ctianalyst.com

Structured analytic techniques

ACH is not a spreadsheet ritual. It is a discipline for finding the evidence that would prove you wrong, which is the only kind that carries much information.

Structured analytic techniques exist because human judgement fails in predictable ways under uncertainty. Richards Heuer's Psychology of Intelligence Analysis is the foundational text, and its central argument is uncomfortable: analysts rarely fail from lack of data. They fail from processing it through an unexamined mental model.

Analysis of Competing Hypotheses

ACH is the technique most often asked about. The core insight: evidence consistent with your favoured hypothesis is nearly worthless, because it is usually consistent with several others too. What discriminates is evidence that is inconsistent with a hypothesis. So you work by elimination, not accumulation.

  1. Enumerate hypotheses — including ones you find unlikely. Do this before looking hard at the evidence, and get someone else to add to the list.
  2. List the evidence and, critically, the relevant absences. What should be there if a hypothesis were true?
  3. Build the matrix — hypotheses across, evidence down. For each cell mark whether the evidence is consistent, inconsistent, or not applicable.
  4. Refine — drop evidence with no diagnostic value (consistent with everything), and sharpen hypotheses that overlap.
  5. Rank by inconsistency, not by supporting weight. The hypothesis with the fewest inconsistencies is the tentative lead.
  6. Test sensitivity — which single item, if wrong, collapses the conclusion? That item deserves the most scrutiny.
  7. Report conclusions with alternatives, not just the winner.
  8. Identify future indicators that would shift the ranking, and go collect against them.

A worked CTI example

Ransomware deployed in your environment; the affiliate model means tooling tells you less than it seems to. Hypotheses: (H1) a financially motivated affiliate acting opportunistically; (H2) a targeted intrusion by the same actor with prior access; (H3) destructive activity disguised as ransomware; (H4) an insider.

Evidence "ransomware binary from a known family" is consistent with all four — it has no diagnostic value and should be set aside. Evidence "no exfiltration observed despite a functioning C2 channel for six days" is inconsistent with H1's normal double-extortion pattern and starts to discriminate. Evidence "initial access via credentials valid before the compromise window" bears on H4. That is how the matrix earns its keep.

Key assumptions check

Cheaper than ACH and often more useful. List every assumption your assessment depends on, then ask of each: how confident am I, what would happen to the conclusion if it were false, and could I actually test it?

In CTI the recurring unexamined assumptions are worth memorising: that your telemetry covers the relevant surface; that the adversary's goal is the obvious one; that public reporting about a group is current; that an indicator is still controlled by the actor; and that the first intrusion you found is the first that happened.

Other techniques worth naming

  • Devil's advocacy / red teaming — someone is tasked to argue the opposite case in good faith. Effective specifically because it is assigned rather than volunteered.
  • Quality of information check — a structured pass over sourcing before analysis begins. Pairs directly with source grading.
  • Indicators and warning — define in advance the observables that would signal a shift, so you notice a change rather than rationalising it.
  • Premortem — assume the assessment turned out wrong and reason backwards to how. Fast, and unusually good at surfacing groupthink.

The biases these counter

BiasHow it shows up in CTI
Confirmation biasCollecting until the favoured attribution is supported, then stopping
AnchoringThe first group name mentioned shapes every later interpretation
AvailabilityOver-weighting the actor you read about this week
Mirror imagingAssuming the adversary values what you value, or is as competent as you would be
SatisficingAccepting the first hypothesis that fits rather than testing alternatives
Interview reality check

Nobody expects a full ACH matrix during an incident. What interviewers listen for is whether you generate alternatives unprompted and say what would falsify your lead hypothesis. If you name one explanation and defend it, you have failed the round regardless of whether the explanation was correct.

Practise structured analysis questions.

Next step

Run a mock interview on this material. You get the question, a graded response against a vetted rubric, and the probing follow-up an interviewer would ask next.

Related reading