Skip to content

Update data_model.md#3012

Open
alexane-bougeardbebin-sekoia wants to merge 4 commits into
mainfrom
cti-scoring-improvement
Open

Update data_model.md#3012
alexane-bougeardbebin-sekoia wants to merge 4 commits into
mainfrom
cti-scoring-improvement

Conversation

@alexane-bougeardbebin-sekoia

Copy link
Copy Markdown
Contributor

Add details to clarify scoring methodology

Add details to clarify scoring methodology
Removed the previous content and added a new structure for the data model documentation.
@github-actions

github-actions Bot commented May 27, 2026

Copy link
Copy Markdown

Newest code from alexane-bougeardbebin-sekoia has been published to preview environment

🚀 Latest deployment was built on 2026-05-29 15:18:49 (51235c1f3ed6421866eab3bc5751e339d60a6be7).

Comment thread _shared_content/intelligence_center/data_model.md Outdated
Comment thread _shared_content/intelligence_center/data_model.md Outdated
| **C3** | Fairly reliable source, possibly true. Use with caution; seek corroboration. |
| **F6** | Source reliability unknown, truth cannot be judged. Raw, unvalidated data. |

In Sekoia's STIX objects, you can approximate this combined rating by cross-referencing the object's `confidence` field with the `confidence` field on the corresponding source `Identity` in `x_inthreat_sources_refs`.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not sure that's how it works.
Generally speaking, an IOC would have two sources:

  • Sekoia in B2
  • Another in F5
    I think it will have a high confidence level. I don't know how the score is calculated; you'll have to check with T&P.
    In any case, you can keep it general and say: we calculate the confidence score by cross-referencing these sources. We get a score from 1 to 5—where 1 corresponds to A1 and 5 to F/E 5/6 (to be confirmed with T&P). On the platform, we shouldn’t have many IOCs with scores below 3

@alexane-bougeardbebin-sekoia alexane-bougeardbebin-sekoia May 29, 2026

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@ka0ula can you help on this one?

Removed the decision guide section for observables and indicators from the data model.
Replaced a reference to The MITRE Corporation with a reference to PhishTank in the data model.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants