STANDARDS & PROTOCOLS

Evidence & Mapping Methodology

A transparent standard for converting complex legal proceedings and government advisories into structured, verifiable cybersecurity intelligence.

Key Facts

  • Every technique mapping requires an exact quotation and page or paragraph locator from a primary source document.
  • Zero reliance on anonymous sources, vendor marketing claims, or speculative threat intelligence.
  • Three-stage pipeline verification: deterministic rules, offline model proposal, and mandatory human review.
  • Complete legal lifecycle tracking from initial grand jury indictment through plea agreements and final sentencing.

1. The Primary Source Standard

The Cyberattack Case Library maintains a strict rule: we cite only primary legal documents, sworn affidavits, grand jury indictments, court dockets, official CISA advisories, SEC Form 8-K Item 1.05 disclosures, and OFAC sanctions notices.

Commercial threat intelligence reports frequently rely on proprietary telemetry that cannot be independently audited by the public. In contrast, documents filed in United States federal courts are subject to evidentiary standards, cross-examination, and perjury penalties. By anchoring our database to official records, every technique attribution can be verified by students, researchers, and defense counsel.

2. Evidentiary Excerpts and Locators

Every technique mapped to an incident in this library must carry two mandatory proof fields:

  • Verbatim Evidence Excerpt: The exact sentence or passage from the primary document describing the adversary action.
  • Document Locator: The specific page number, paragraph number, or docket entry number (for example, "Indictment p. 14, ¶ 32" or "Affidavit ¶ 19").

Technique mappings that lack an exact locator or direct evidentiary quote are not admitted into the library.

3. Verification Pipeline and Human Review

Candidate mappings progress through a three-stage verification pipeline:

STAGE 1: RULES

Deterministic Extraction

Keyword, regex, and syntactic pattern matching scans document text for tool names, CVE identifiers, and specific offensive behaviors.

STAGE 2: PROPOSAL

Offline Model Proposal

Local offline models running on private hardware propose candidates from complex narrative passages, extracting exact quotes without external network transmission.

STAGE 3: REVIEW

Human Verification

Analysts review candidates using our CLI audit tool. Only mappings explicitly marked as reviewed appear in standard views and MITRE ATT&CK Navigator layers.

4. Legal Case Lifecycles

Legal cases evolve over years. Our database derives legal statuses deterministically from docket events:

  • Alleged: Grand jury indictment or complaint filed; defendants have not appeared or entered pleas.
  • Charged / Arrested: Defendants taken into custody or initial appearances completed.
  • Pleaded: Formal guilty plea entered under a Rule 11 plea agreement.
  • Convicted: Jury verdict of guilty or bench trial verdict.
  • Sentenced: Final judgment entered with statutory prison term and restitution orders.
  • Fugitive: Defendants remain outside extradition jurisdiction with active Interpol Red Notices or federal arrest warrants.