Standard Operating Procedures
SOP-001: Daily Intelligence Triage
Frequency: Daily Owner: Orchestrator
- Review overnight intelligence feeds and alerts
- Check active PIRs — any new information relevant to Critical/High PIRs?
- Triage new indicators:
- Discard noise (known benign, low confidence, duplicate)
- Fast-track critical indicators (active exploitation, direct relevance)
- Queue remaining for standard processing
- Dispatch OSINT researcher for any trending threats relevant to PIRs
- Update relevant knowledge cells with new significant intelligence
- Produce daily intelligence brief if significant developments occurred
SOP-002: IOC Processing
Trigger: New IOC list received (from internal detection, external sharing, or OSINT collection) Owner: IOC Processor
- Parse and classify all indicators
- Validate format (reject malformed)
- Deduplicate against existing active IOC collections
- Enrich via enrichment workflow (dispatch tool agents)
- Apply source assessment to enrichment results
- Synthesise verdict (malicious/suspicious/benign/unknown)
- Store in
data/iocs/active/ - If actionable: request detection rule creation from detection engineer
- If significant: flag to orchestrator for flash report consideration
- Export in relevant formats if sharing is appropriate
SOP-003: Flash Report Creation
Trigger: Time-critical intelligence requiring immediate stakeholder action Owner: Orchestrator → Analyst → Report Writer → Quality Reviewer
- Orchestrator identifies time-critical situation
- Dispatch analyst for rapid assessment (30-minute time box)
- Dispatch report writer with flash report template
- Quality reviewer performs expedited review (critical checks only):
- TLP correct?
- Key finding supported?
- IOCs validated?
- Actions clear?
- Disseminate via appropriate TLP channel
- Link to relevant PIRs
- Schedule follow-up analysis if warranted
Expedited review: For flash reports, quality review focuses on CRITICAL issues only. MAJOR and MINOR issues are noted but don't block publication. Speed matters.
SOP-004: Threat Actor Profile Update
Trigger: Significant new intelligence about a tracked threat actor Owner: Orchestrator → Analyst
- Identify which knowledge cell applies
- Load the knowledge cell
- Dispatch analyst to review new intelligence against existing cell
- Analyst determines:
- What is genuinely new?
- What confirms existing knowledge?
- What contradicts existing knowledge?
- Update knowledge cell:
- Add new campaign entries
- Update TTP tables
- Revise executive summary if landscape changed
- Add to Sources & References
- Log change in Change Log
- If significant change: flag for stakeholder communication
SOP-005: Stakeholder Briefing
Trigger: Quarterly or ad-hoc stakeholder request Owner: Orchestrator → Analyst → Report Writer
- Review active PIRs for the stakeholder
- Gather satisfaction history since last briefing
- Dispatch analyst to prepare briefing content:
- Key developments since last briefing
- PIR satisfaction status
- Emerging threats relevant to stakeholder
- Recommended PIR adjustments
- Dispatch report writer to produce briefing document
- Tailor format to stakeholder (per stakeholder-management skill)
- Quality review
- Deliver via appropriate channel
- Collect feedback
- Update PIRs based on feedback
SOP-006: Quarterly PIR Review
Frequency: Quarterly Owner: Orchestrator
- List all active PIRs
- For each PIR:
- Review satisfaction history
- Check stakeholder is still active/relevant
- Assess if priority should change
- Determine if scope needs adjustment
- Decide: maintain / modify / retire
- Archive retired PIRs
- Create new PIRs based on stakeholder feedback and emerging threats
- Update collection plans for modified PIRs
- Document review outcomes
SOP-007: Knowledge Cell Maintenance
Frequency: Monthly review, continuous updates Owner: Orchestrator
- List all knowledge cells
- For each cell:
- Check
last_updated— flag any not updated in 60+ days - Review intelligence gaps — any now answerable?
- Check if active campaigns have concluded → move to historical
- Verify executive summary reflects current landscape
- Check
- For stale cells: dispatch OSINT researcher for current intelligence
- For cells with resolved gaps: update gap list
- Consider: are new cells needed for emerging threats?