Source & Information Assessment — NATO Admiralty Scale
Every piece of intelligence entering this platform MUST be assessed using the Admiralty Scale. This is non-negotiable. Tag every item with a two-character code (e.g., B2).
Source Reliability
How trustworthy is the source based on its track record?
| Code |
Rating |
Criteria |
| A |
Completely reliable |
No doubt about the source's authenticity, trustworthiness, or competency. History of complete reliability. |
| B |
Usually reliable |
Minor doubt. Source has been reliable in most instances. |
| C |
Fairly reliable |
Doubt about reliability. Source has provided valid information in the past but not consistently. |
| D |
Not usually reliable |
Significant doubt. Source has been unreliable in the past. |
| E |
Unreliable |
Source has a track record of being unreliable, or the information is obtained under duress/deception. |
| F |
Reliability cannot be judged |
No basis for evaluating the source's reliability. New or unknown source. |
Source Reliability Decision Guide
- A: National CERTs, established security vendors (Mandiant, CrowdStrike, Microsoft), peer-reviewed research, direct forensic evidence from your own systems
- B: Reputable threat intelligence providers, well-known security researchers, ISACs, FIRST members
- C: Community threat feeds, open-source intelligence tools with mixed accuracy, semi-verified social media accounts of known researchers
- D: Unverified forum posts, anonymous tips, single-source claims without corroboration
- E: Known disinformation actors, sources with demonstrated fabrication history
- F: First-time sources, automated feeds without historical accuracy data, newly discovered paste sites
Information Credibility
How likely is the information itself to be accurate, regardless of source?
| Code |
Rating |
Criteria |
| 1 |
Confirmed |
Confirmed by other independent sources. Logical, consistent with other information on the subject. |
| 2 |
Probably true |
Not confirmed, but logical and consistent with other information. |
| 3 |
Possibly true |
Not confirmed. Reasonably logical but not fully consistent with other information. |
| 4 |
Doubtful |
Not confirmed. Possible but not logical. No other information on the subject. |
| 5 |
Improbable |
Not confirmed. Not logical. Contradicted by other information on the subject. |
| 6 |
Truth cannot be judged |
No basis for evaluating the information's veracity. |
Information Credibility Decision Guide
- 1: Corroborated by 2+ independent sources; matches observed technical evidence; confirmed by forensic analysis
- 2: From a reliable source; logically consistent with known threat landscape; partially corroborated
- 3: Plausible but from a single source; consistent with general trends but not specifically corroborated
- 4: Unconfirmed claim; contradicts some known information; possible but requires further investigation
- 5: Contradicts well-established intelligence; logically inconsistent; likely disinformation
- 6: Cannot evaluate — insufficient context, entirely new domain, or conflicting assessment criteria
Combined Rating Examples
| Rating |
Example |
| A1 |
Microsoft publishes CVE details with MSRC forensic analysis, confirmed by CISA KEV listing |
| B2 |
CrowdStrike reports new APT campaign TTPs; consistent with own telemetry but not independently confirmed |
| C3 |
Security blogger reports new malware variant with partial technical analysis; plausible but unverified |
| D4 |
Anonymous Telegram channel claims zero-day in popular software; no technical details provided |
| F6 |
First-time automated feed delivers IOCs with no historical accuracy baseline |
How to Apply
- At collection time: Tag every piece of incoming intelligence with its Admiralty rating
- In analysis: Weight evidence by reliability — A1 evidence outweighs D4 evidence
- In products: Include the rating in the Sources & References section
- When ratings change: If new information changes the credibility assessment, update and log the change
Common Mistakes
- Confusing source reliability with information credibility (a reliable source can relay inaccurate information)
- Rating all vendor reports as A1 (vendors can have biases and errors)
- Not reassessing ratings when new corroborating or contradicting information emerges
- Omitting the rating entirely because "it's obvious" — always be explicit
1---2name: source-assessment3description: Use when rating a source with the NATO Admiralty Scale, the user asks "is this reliable?" / "rate this source", or the tradecraft pipeline calls for source assessment before publishing. Reliability A-F, credibility 1-6.4---56# Source & Information Assessment — NATO Admiralty Scale78Every piece of intelligence entering this platform MUST be assessed using the Admiralty Scale. This is non-negotiable. Tag every item with a two-character code (e.g., B2).910## Source Reliability1112How trustworthy is the **source** based on its track record?1314| Code | Rating | Criteria |15|------|--------|----------|16| **A** | Completely reliable | No doubt about the source's authenticity, trustworthiness, or competency. History of complete reliability. |17| **B** | Usually reliable | Minor doubt. Source has been reliable in most instances. |18| **C** | Fairly reliable | Doubt about reliability. Source has provided valid information in the past but not consistently. |19| **D** | Not usually reliable | Significant doubt. Source has been unreliable in the past. |20| **E** | Unreliable | Source has a track record of being unreliable, or the information is obtained under duress/deception. |21| **F** | Reliability cannot be judged | No basis for evaluating the source's reliability. New or unknown source. |2223### Source Reliability Decision Guide2425- **A**: National CERTs, established security vendors (Mandiant, CrowdStrike, Microsoft), peer-reviewed research, direct forensic evidence from your own systems26- **B**: Reputable threat intelligence providers, well-known security researchers, ISACs, FIRST members27- **C**: Community threat feeds, open-source intelligence tools with mixed accuracy, semi-verified social media accounts of known researchers28- **D**: Unverified forum posts, anonymous tips, single-source claims without corroboration29- **E**: Known disinformation actors, sources with demonstrated fabrication history30- **F**: First-time sources, automated feeds without historical accuracy data, newly discovered paste sites3132## Information Credibility3334How likely is the **information itself** to be accurate, regardless of source?3536| Code | Rating | Criteria |37|------|--------|----------|38| **1** | Confirmed | Confirmed by other independent sources. Logical, consistent with other information on the subject. |39| **2** | Probably true | Not confirmed, but logical and consistent with other information. |40| **3** | Possibly true | Not confirmed. Reasonably logical but not fully consistent with other information. |41| **4** | Doubtful | Not confirmed. Possible but not logical. No other information on the subject. |42| **5** | Improbable | Not confirmed. Not logical. Contradicted by other information on the subject. |43| **6** | Truth cannot be judged | No basis for evaluating the information's veracity. |4445### Information Credibility Decision Guide4647- **1**: Corroborated by 2+ independent sources; matches observed technical evidence; confirmed by forensic analysis48- **2**: From a reliable source; logically consistent with known threat landscape; partially corroborated49- **3**: Plausible but from a single source; consistent with general trends but not specifically corroborated50- **4**: Unconfirmed claim; contradicts some known information; possible but requires further investigation51- **5**: Contradicts well-established intelligence; logically inconsistent; likely disinformation52- **6**: Cannot evaluate — insufficient context, entirely new domain, or conflicting assessment criteria5354## Combined Rating Examples5556| Rating | Example |57|--------|---------|58| **A1** | Microsoft publishes CVE details with MSRC forensic analysis, confirmed by CISA KEV listing |59| **B2** | CrowdStrike reports new APT campaign TTPs; consistent with own telemetry but not independently confirmed |60| **C3** | Security blogger reports new malware variant with partial technical analysis; plausible but unverified |61| **D4** | Anonymous Telegram channel claims zero-day in popular software; no technical details provided |62| **F6** | First-time automated feed delivers IOCs with no historical accuracy baseline |6364## How to Apply65661. **At collection time**: Tag every piece of incoming intelligence with its Admiralty rating672. **In analysis**: Weight evidence by reliability — A1 evidence outweighs D4 evidence683. **In products**: Include the rating in the Sources & References section694. **When ratings change**: If new information changes the credibility assessment, update and log the change7071## Common Mistakes7273- Confusing source reliability with information credibility (a reliable source can relay inaccurate information)74- Rating all vendor reports as A1 (vendors can have biases and errors)75- Not reassessing ratings when new corroborating or contradicting information emerges76- Omitting the rating entirely because "it's obvious" — always be explicit