skip to content

Producing Intel

Intel that starts from a named consumer and a decision they owe, not from a feed subscription: what to collect, how to collect it without being seen, and how sure you honestly are.

on this pageshow

explore

questions

12

When researching a suspected C2 domain, what is the difference between passive and active collection?

level: juniorimportance: must knowfreq 64%

answer

  1. who ends up seeing your query
  2. records somebody else already collected
  3. passive DNS, CT logs, WHOIS history
  4. resolving the name is already touching it
  5. his access log is your exposure

basics

~20 s

Passive collection reads records third parties already hold - passive DNS, certificate transparency, WHOIS history, stored scan data - so nothing reaches the adversary. Active collection resolves or connects to his host and writes a footprint into logs he controls.

solid answer

~50 s

Passive collection means asking somebody else what they already recorded: a passive DNS provider's historic name-to-address observations, certificate transparency entries for names on his certificates, registrar and WHOIS history, and a scanning service's stored banner records. None of that sends a packet to the adversary, so his logs stay empty. Active collection is anything that touches infrastructure he runs - resolving the name (the query lands on his authoritative nameserver), a TLS handshake, an HTTP request, a port scan, or asking a URL scanner to fetch the link, which makes a third party touch it on your behalf at a moment correlated with your discovery. The operating rule is: exhaust passive first, decide consciously before going active, and go active only from infrastructure that does not identify your organisation - never from the office network.

go deeper

for a junior

Be ready to name three passive sources and three active acts, and to say what each active act writes into the adversary's log. Knowing that resolving a name already counts as touching it is the point being tested.

for a middle

Explain the mechanics: which server actually receives your query in each case, what a passive DNS or certificate transparency record does and does not prove, and how tooling silently converts a passive intent into an active lookup.

for a senior

Show the decision rule. Say what the active step buys, what continued quiet observation is worth, and from what infrastructure you would touch the host at all - then be explicit that going active is a choice someone owns, not a reflex.

for a principal

Own the capability question: whether the team gets a non-attributable research path and a research tenant at all, what it costs, and what you forbid outright while it does not exist.

## The question behind the question When you find a domain or address you believe belongs to an intruder's command-and-control infrastructure, every step you take next either leaves a trace the operator can read or it does not. Tradecraft is the discipline of knowing which is which *before* you click, because the operator's response to being looked at is to rotate infrastructure, go quiet, or accelerate - and all three cost you more than the answer you were about to get. ## Passive: reading what somebody else already collected Passive sources are databases built by third parties from their own vantage points. Querying them reaches the provider, never the adversary. - **Passive DNS.** Sensors and recursive resolvers record the answers they observe and a provider aggregates them. A passive DNS record tells you that *some sensor observed this name resolving to this address at this time*. That is all it tells you. It does not prove the name resolves there now, and coverage is partial - an absence of records is not evidence the name was never used. - **Certificate transparency.** Publicly trusted certificate authorities log the certificates they issue to append-only public logs. A CT entry proves *a certificate containing that name was issued and logged*, not that any host serves it. Names on a shared certificate, an unusual issuance cadence, or a distinctive subject often reveal siblings of the host you started from. A self-signed certificate leaves no CT record at all, so absence proves nothing. - **Registrar and WHOIS history.** Registration and expiry dates, registrar, and nameserver changes over time. Most contact fields are redacted for privacy on many top-level domains, but historic snapshots and nameserver reuse are still strong pivots. - **Stored scan and banner data.** Internet-wide scanning services keep historic records of what a host answered with. Reading a stored record is passive; pressing that same service's *rescan* button is not - it fires a fresh scan at the host on your behalf. ## Active: anything that touches his infrastructure - **Resolving the name.** If the adversary runs the authoritative nameserver for the domain, a recursive lookup delivers a query to *his* server. He sees the resolver that asked, and some resolvers attach an EDNS Client Subnet field carrying a truncated prefix of the client's network. - **Connecting.** A TLS handshake, an HTTP request, a browser visit, a port probe - all of these write a source address, a timestamp and often a distinctive user agent into a log he owns. - **Submitting a URL to a scanner.** You did not touch it, but the service fetches it, and the fetch is timed to your discovery. If the link carried a per-victim token, the fetch also tells him which victim reported it. The trap is that plenty of tooling blurs the line: an intel platform's enrichment button may perform a live lookup, and a browser will helpfully resolve and prefetch a link you only meant to read. ## Why the operator's log is a real threat Corporate address space is attributable. Registry records map a netblock to an autonomous system and an organisation, so a single request from the office egress can tell a watchful operator *which company* is investigating him. A one-analyst team with no separate research egress and no research tenant has, in practice, only one non-attributable option: do not touch it. ## The decision rule 1. Exhaust passive sources and record what you found, including timestamps. 2. Ask what the active step would add that passive cannot give you. 3. Weigh that against the value of continuing to observe the infrastructure quietly. 4. If you still need it, go active from infrastructure that does not identify your organisation, and treat the visit as a decision with a named owner - not as a reflex. Going active is sometimes exactly right: once containment is imminent, or the intel need outweighs further observation, the burn is a price you choose to pay. What is never right is paying it by accident from a workstation.

  • Is a WHOIS lookup passive?
    The WHOIS or RDAP query itself goes to the registry or registrar, not to the adversary, so it is passive. The care needed is with tooling: many WHOIS wrappers also resolve the name, fetch the site, or offer a live-scan button, and any of those turns the same click into an active touch.
  • Does a passive DNS record tell you whether the domain resolves right now?
    No. It tells you that a sensor observed that resolution at some point, and coverage is partial. The record can be months stale, and the absence of a record only means no contributing sensor saw it. To know current state you must resolve it, which is an active step with a footprint.
  • When is going active the right call?
    When passive sources are exhausted, the answer materially changes a decision, and the value of continued quiet observation is already gone - typically because containment is imminent or the adversary knows he is discovered. Even then, do it from infrastructure that does not identify your organisation, and record that someone chose to accept the exposure.

Passive collection is reading the public land registry about a house. Active collection is walking up and trying the door - it answers a different question, and the person inside knows you were there.

saying these in an interview costs you the question

  • Thinks a passive DNS query reaches the adversary's nameserver
  • Calls a browser visit to the C2 host harmless because nothing was downloaded
  • Assumes every adversary TLS host appears in certificate transparency
  • Treats an intel platform's enrichment button as always passive
  • Believes the office VPN makes corporate egress unattributable

context

open as a page

What must a priority intelligence requirement name that 'keep an eye on infostealer activity' does not?

level: juniorimportance: must knowfreq 68%

basics

~20 s

A priority intelligence requirement names a consumer, the decision they owe by a date, and what would count as an answer. 'Keep an eye on infostealer activity' names none of those, so nobody acts on it and it never closes.

open as a page

Why can uploading a suspected implant to a public multi-scanner service burn your investigation?

level: middleimportance: must knowfreq 71%

basics

~20 s

An uploaded sample becomes visible to the platform's subscribers, and operators watch for their own tooling appearing there. The upload announces that the implant is discovered, and a targeted file often identifies the victim through embedded names, addresses or per-victim tokens.

open as a page

At 07:00 your CEO forwards a leak-site post naming a company like yours — how do you assess it?

level: seniorimportance: must knowfreq 55%

basics

~20 s

A leak-site listing proves someone published a claim, not that data was taken. Check the exact legal entity, then reseller and supplier lists, identity-provider sign-ins and SaaS audit trails. Answer with a likelihood, a confidence and a stated falsifier.

open as a page

In an Admiralty Code rating like B2, what do the letter and the number each grade?

level: juniorimportance: should knowfreq 45%

basics

~20 s

The letter grades the source's track record (A completely reliable, down to F cannot be judged). The number grades that one report's credibility (1 confirmed by other sources, down to 6 cannot be judged). They are graded independently.

open as a page

How do you turn a priority intelligence requirement into a collection plan when an MSSP runs part of your SOC?

level: middleimportance: should knowfreq 44%

basics

~20 s

Decompose the requirement into answerable sub-questions, then give each one a source, a named collector, a cadence and a definition of answered. With an MSSP, every line has to say who collects it - you or them - and lines nobody can collect are recorded as collection gaps.

open as a page

How do you detect circular reporting across three vendor write-ups of one campaign?

level: middleimportance: should knowfreq 42%

basics

~20 s

Trace every report back to a first-hand observation. Compare indicator lists, screenshots, dates and repeated errors; check publication order and citations. If all three descend from one original write-up, you hold one source, not three, and corroboration was never earned.

open as a page

An analyst browsed a live C2 panel from the office network and the cluster went dark within the hour - what have you lost?

level: seniorimportance: should knowfreq 44%

basics

~20 s

You have likely lost quiet observation of that infrastructure and told the operator which company is investigating him, because corporate address space is attributable. Rotation timed to the visit is strong evidence he noticed, not proof.

open as a page

A standing intelligence requirement has returned nothing in two years - how do you decide whether to retire it?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Silence is ambiguous, so first establish whether anything was ever tasked and whether the source could have reported it. Retire only when the decision behind the requirement is gone or the targeting rationale never held - and record what would reopen it.

open as a page

An assessment reads "likely, with low confidence" — is that a contradiction?

level: middleimportance: nice to knowfreq 36%

basics

~20 s

No. Likelihood is how probable the analyst thinks the claim is; confidence is how good the sourcing and reasoning behind that estimate are. Likely with low confidence means the estimate leans yes but little new information would move it.

open as a page

Your intelligence consumer says 'just send me anything relevant' - how do you get real requirements out of that?

level: principalimportance: nice to knowfreq 29%

basics

~20 s

Work backwards from the decisions on that person's calendar, draft a small ranked set of requirements naming each decision and its date, and make them cut it down. Priority comes from their competing decisions, not from analyst interest.

open as a page