write-the-intel-brief
Compare original and translation side by side
🇺🇸
Original
English🇨🇳
Translation
ChineseWrite the intel brief
撰写情报简报
The report is the only part of the investigation anyone else sees, so it is the
only part that can be wrong in public. The failure that destroys credibility
isn't a missed source — it's a sentence that reads as fact and is actually an
inference. "The account is operated from Lisbon" versus "posting times cluster
in UTC+0/+1, consistent with Iberian working hours." One survives cross-
examination.
调查中只有报告部分会被其他人看到,因此这也是唯一可能在公开场合出现错误的部分。摧毁可信度的失误并非遗漏来源——而是将推断表述为事实的句子。比如“该账户由里斯本运营”与“发帖时间集中在UTC+0/+1时区,符合伊比利亚半岛工作时间”,后者能经得起交叉质询。
Step 1 — Sort every claim into observation, inference, or assessment
步骤1 — 将每项声明归类为观察、推断或评估
Three categories, never blurred, ideally visually distinct in the text.
- Observation — what you saw, with source and timestamp. "The registry record retrieved 2024-03-11 lists A. Kestrel as director."
- Inference — a logical step from observations, with the step shown. "The same registrant email appears on both domains, so they were registered by one party."
- Assessment — your analytic judgement, carrying probability and confidence. "We assess it is likely the two companies are commonly controlled."
Any sentence where you cannot say which category it belongs to is a sentence
that has smuggled a conclusion into the evidence. Rewrite it. Verbs betray the
category: is, lists, shows for observation; indicates, implies for
inference; we assess, we judge for assessment. Watch out for "appears to be",
which pretends to be observation and is inference.
Done when every claim is tagged and no inference is written in the
grammatical form of an observation.
分为三类,绝不能混淆,文本中最好在视觉上区分开。
- 观察 — 你所看到的内容,附带来源和时间戳。例如“2024-03-11获取的注册记录显示A. Kestrel为董事。”
- 推断 — 基于观察得出的逻辑推导,需明确展示推导过程。例如“两个域名使用相同的注册邮箱,因此它们由同一主体注册。”
- 评估 — 你的分析判断,包含概率和可信度。例如“我们评估这两家公司很可能由同一方控制。”
任何无法归为上述某一类的句子,都是将结论偷偷混入证据的句子,需要重写。动词会暴露类别:是、显示、列出用于观察;表明、暗示用于推断;我们评估、我们判断用于评估。注意“似乎是”这类表述,它伪装成观察,但实际是推断。
完成标准:每项声明都已标记类别,没有推断被写成观察的语法形式。
Step 2 — Attach source, timestamp, and an archived copy to every claim
步骤2 — 为每项声明附加来源、时间戳和存档副本
A claim with no source does not go in the report. Not in a footnote, not
"multiple sources" — the specific one, per claim.
Each source needs: the URL or the tool and its exact query; the UTC date-time
you retrieved it; the source-reliability grade (see ); and
an archive reference. Live URLs rot, and hostile subjects delete. Archive
everything you cite, at the moment you cite it, using —
cite the snapshot alongside the live URL, and keep a local copy too, since
public archives can themselves be removed on request.
investigate-anythingread-deleted-pagesFor anything that might become evidence, add chain of custody: who collected
it, when, with what tool and version, and a cryptographic hash of the stored
file ( on Linux, on macOS). Record the hash
in the report, keep the original untouched, and work on copies. A screenshot
with no hash, no timestamp and no capture method is worth very little; the
underlying HTML, headers, and image files are worth more.
sha256sum fileshasum -a 256 fileDone when every retained claim has source, retrieval timestamp, grade, and
archive reference, and evidentiary items also have hashes.
无来源的声明不得纳入报告。不能仅用脚注标注,也不能模糊写“多个来源”——需为每项声明指定具体来源。
每个来源需包含:URL或工具及精确查询语句;你获取该来源的UTC日期时间;来源可信度等级(详见);以及存档引用。在线URL会失效,目标对象也会删除内容。因此,在引用任何内容时,都需使用进行存档——同时引用实时URL和快照链接,还要保留本地副本,因为公共存档也可能因请求被移除。
investigate-anythingread-deleted-pages对于可能成为证据的内容,需添加监管链信息:收集人、收集时间、使用的工具及版本,以及存储文件的加密哈希值(Linux系统用,macOS系统用)。在报告中记录哈希值,保留原始文件不动,仅使用副本工作。没有哈希值、时间戳和捕获方法的截图几乎毫无价值;而底层HTML、请求头和图像文件的价值更高。
sha256sum fileshasum -a 256 file完成标准:所有保留的声明都附带来源、获取时间戳、等级和存档引用,证据类内容还需包含哈希值。
Step 3 — Lead with the judgements
步骤3 — 以判断结论开篇
Assume the reader stops after the first half page — because they will. BLUF:
the answer to the objective question first, in plain language, with its
probability and confidence. Then the two or three judgements that carry the
decision. Background, method and detail come after, for the reader who needs to
audit you.
A key judgement is one sentence, one judgement, with its estimative term, its
confidence, and the reason compressed to a clause. If a judgement needs a
paragraph of setup to make sense, it isn't a judgement yet.
Done when the objective question is answered in the first paragraph, and
the answer would still be defensible if nothing else were read.
假设读者只会读前半页——实际情况往往如此。采用BLUF原则:先用直白语言回答核心问题,同时说明概率和可信度。接着列出两三个影响决策的关键判断。背景、方法和细节放在后面,供需要审核的读者查阅。
关键判断需是单句单结论,包含评估术语、可信度,以及压缩为从句的理由。如果某个判断需要一段铺垫才能让人理解,那它还不能算是合格的判断。
完成标准:核心问题在第一段得到解答,即使不阅读后续内容,该答案也具备可辩护性。
Step 4 — Use the probability ladder, and only it
步骤4 — 使用统一的概率层级,且仅限该层级
"Possibly" everywhere is how a report says nothing at length. Standardise on one
ordered set of terms and use them consistently:
almost certainly · highly likely · likely · roughly even chance · unlikely ·
highly unlikely · remote
Rules that make it work: never use a term outside the ladder; never mix in a
numeric percentage in the same sentence as a word, since readers anchor on the
number; never use "possible" as an estimate, because everything not excluded is
possible; and print the ladder in the report so the reader maps words to ranges
the same way you did. Full table with ranges, the near-synonyms to avoid, and
worked rewrites: reference/estimative-language.md.
Probability and confidence are different axes. Probability is how likely the
judgement is to be true. Confidence is how good the evidence underneath it is —
source quality, corroboration, and the presence of gaps or plausible deception.
You can legitimately write "highly likely, low confidence": the evidence points
strongly one way but rests on a single unverifiable source. That sentence is
honest and useful. Collapsing the two into one word is not.
Done when every assessment carries one ladder term and a stated confidence
level, with the reason for the confidence given.
通篇使用“可能”会让报告冗长却言之无物。需统一使用一套有序术语并保持一致性:
几乎肯定 · 极有可能 · 有可能 · 大致五五开 · 不太可能 · 极不可能 · 可能性极低
确保有效的规则:绝不使用层级外的术语;同一句子中绝不混用文字表述和数字百分比,因为读者会锚定数字;绝不将“可能”作为评估结果,因为所有未被排除的情况都是“可能”的;在报告中附上概率层级表,让读者和你对术语对应的范围理解一致。包含范围、需避免的近义表述及改写示例的完整表格:reference/estimative-language.md。
概率和可信度是两个不同维度。概率指判断为真的可能性,可信度指支撑判断的证据质量——包括来源可靠性、佐证情况、是否存在信息缺口或合理的欺骗可能性。你完全可以写出“极有可能,低可信度”这样的表述:证据明确指向某一结论,但仅基于单一无法验证的来源。这句话诚实且有用,而将两者合并为一个词则不可取。
完成标准:每项评估都包含一个层级术语和明确的可信度等级,并说明可信度的理由。
Step 5 — Write the negative findings
步骤5 — 记录负面调查结果
Juniors delete these because they feel like failure. They are frequently the
most useful content in the report: they are what stops the next analyst
repeating the work, and in due diligence and pre-employment contexts the
absence of adverse findings is the deliverable.
State what you looked for, where you looked, and what you did not find —
distinguishing "checked, absent" from "could not check". "No sanctions or
enforcement listings for the subject in the OFAC, UK, and EU consolidated lists,
checked 2024-03-11" is a finding. "No adverse media found" without naming the
sources searched, the languages, and the date range is not a finding, it is a
shrug. Record rejected leads and candidates too, with the reason for rejection.
Done when searched-and-empty, could-not-check, and rejected-candidate items
are each written up with scope and dates.
初级分析师会删除这些内容,因为他们觉得这是失败的表现。但这些内容往往是报告中最有用的部分:它能避免后续分析师重复劳动,在尽职调查和入职背调场景中,未发现负面信息本身就是交付成果。
需说明你查找了什么、在哪里查找的,以及未找到的结果——区分“已核查,无相关内容”和“无法核查”。例如“2024-03-11核查OFAC、英国及欧盟综合名单,未发现目标对象的制裁或执法记录”是有效调查结果。而仅写“未发现负面媒体报道”却未说明搜索的来源、语言和日期范围,不能算作调查结果,只是敷衍。还需记录被否决的线索和候选对象,以及否决理由。
完成标准:已核查无结果、无法核查、被否决候选对象的内容均已按范围和日期整理记录。
Step 6 — Document method and gaps
步骤6 — 记录方法和信息缺口
Reproducibility is what separates an intelligence product from an opinion.
Record the tools with versions, the exact queries and dorks, the databases and
their coverage dates, the languages searched, and anything that shaped the
result: rate limiting, geo-restricted content, paywalls, a persona's access
level, deleted material recovered only from archives.
Gaps go in the body, not buried at the end: what could not be established, why
(no public registry in that jurisdiction, platform requires authentication,
records are sealed), and what would close it — a records request, a subpoena, a
site visit. Naming the closed source is a service to whoever reads it.
Done when another analyst could re-run the collection from the report alone
and get the same result, and every unanswered objective question has a named
reason and a route.
可重复性是情报产品与主观意见的区别所在。需记录使用的工具及版本、精确的查询语句和搜索语法、数据库及其覆盖日期、搜索的语言,以及任何影响结果的因素:限流、地域限制内容、付费墙、角色访问权限、仅从存档中恢复的删除内容。
信息缺口需放在正文中,而非埋在文末:说明无法确认的内容、原因(该辖区无公开注册信息、平台需要认证、记录被封存),以及填补缺口的途径——申请记录、传票、实地走访。指明需要非公开来源的信息,对读者来说是有用的提示。
完成标准:其他分析师仅通过报告就能重复收集过程并得到相同结果,每个未解答的核心问题都有明确原因和解决途径。
Step 7 — Minimise, redact, and format for the audience
步骤7 — 精简、编辑并匹配受众格式
Collect broadly, publish narrowly. Remove everything not needed for the
objective — especially data about uninvolved third parties who appeared in the
collection: family members, neighbours, co-residents at an address, bystanders
in photographs, unrelated people sharing the subject's name. Redact rather than
delete where the item explains a reasoning step, and say what was redacted and
why, so the redaction itself is auditable. Never publish full national-ID
numbers, payment card numbers, credentials, or plaintext passwords from breach
data; reference them by type and partial value. Keep the unredacted case file
separately, encrypted, under the retention limit in
../../ETHICS.md.
Then match the format to the reader:
| Audience | Shape |
|---|---|
| Client or executive | One-page BLUF, judgements with probability and confidence, business implication, no tool names in the body |
| Incident responder | Judgements plus a machine-usable indicator table (selectors, first/last seen, confidence) and the raw artefacts |
| Legal or regulatory | Observation-only body, inferences separated and labelled, chain of custody and hashes per exhibit, method appendix, nothing redacted without a log |
| Internal handover | The graph from |
Template with all sections, and the evidentiary variant:
reference/report-template.md.
Done when the report contains no third-party data the objective doesn't
need, and the format matches the named audience.
广泛收集,精准发布。删除所有与核心目标无关的内容——尤其是收集过程中出现的无关第三方数据:家庭成员、邻居、同一地址的其他居住者、照片中的路人、与目标同名的无关人员。若某内容能解释推理过程,则进行编辑而非删除,并说明编辑的内容和原因,确保编辑本身可被审核。绝不能发布完整的身份证号、银行卡号、凭证或泄露数据中的明文密码;仅按类型和部分值进行引用。未编辑的案件文件需单独加密保存,保留期限遵循../../ETHICS.md中的规定。
然后根据受众调整格式:
| 受众 | 格式 |
|---|---|
| 客户或高管 | 一页BLUF简报,带概率和可信度的判断结论、业务影响,正文中不提及工具名称 |
| 事件响应人员 | 判断结论加上机器可识别的指标表(选择器、首次/末次出现时间、可信度)及原始 artefacts |
| 法务或监管机构 | 正文仅包含观察内容,推断内容单独标注,每份证据附带监管链和哈希值,方法附录,无记录的情况下不得编辑内容 |
| 内部交接 | |
包含所有章节的模板及证据变体:reference/report-template.md。
完成标准:报告中无核心目标不需要的第三方数据,格式与指定受众匹配。
Where this goes wrong
常见失误
- Inference laundering. An inference stated on page 2, repeated as background on page 5, cited as established on page 8. Watch for your own claims re-entering as facts.
- Confidence inflation from volume. Forty low-grade items feel like a lot. Grade quality, not count; check for circular reporting before any corroboration claim.
- The hedge that means nothing. "It cannot be ruled out that" is true of everything. Either estimate it or drop it.
- Screenshots as evidence. Trivially forged and easily misread. Cite the archived original; use a screenshot only as an illustration next to it.
- Report written from memory. Reconstructing sources afterwards produces citations to pages that no longer say what you remember. Cite as you collect.
- The wrong-person catastrophe. Everything above is fine and the subject is the wrong human being. Restate the discriminators in the report and show which evidence ties the findings to that individual specifically.
- Distribution. Once sent, it is copied forever. Mark handling, name the recipients, and assume onward sharing.
- 推断洗白:第2页表述的推断,在第5页作为背景重复,第8页被引用为既定事实。注意自己的声明是否被当作事实再次使用。
- 因数量膨胀可信度:40个低质量内容看似很多,但需评估质量而非数量;在声称佐证之前,检查是否存在循环报告。
- 无意义的模糊表述:“无法排除……的可能性”适用于所有情况,要么给出评估,要么删除该表述。
- 将截图作为证据:截图极易伪造且易被误读。引用存档的原始内容;仅将截图作为原始内容旁的插图使用。
- 凭记忆撰写报告:事后重建来源会导致引用的页面内容与记忆不符。收集时就同步引用来源。
- 认错对象的灾难:上述所有步骤都正确,但目标对象是错误的人。在报告中重新说明识别依据,并展示哪些证据将调查结果与该特定个人关联。
- 分发问题:报告一旦发出,就会被永久复制。标注处理要求、收件人姓名,并假设内容会被转发分享。
Confidence grading
可信度分级
- High confidence — multiple independently collected sources, at least one authoritative primary record, consistent, no plausible deception, no material gap.
- Moderate confidence — credible sourcing with partial corroboration, or a gap that does not touch the core judgement.
- Low confidence — single source, unverifiable sourcing, significant gaps, or a live possibility of manipulation. Still publishable — say why it is low and what would raise it.
State the confidence next to the judgement, not in a preamble the reader skips.
- 高可信度 — 多个独立收集的来源,至少包含一份权威原始记录,内容一致,无合理欺骗可能性,无重大信息缺口。
- 中等可信度 — 可信来源且有部分佐证,或存在不影响核心判断的信息缺口。
- 低可信度 — 单一来源、无法验证的来源、重大信息缺口,或存在被操纵的可能性。仍可发布,但需说明低可信度的原因及提升可信度的方法。
需在判断结论旁标注可信度,而非放在读者会跳过的前言中。
Worked example
示例
Objective: does the supplier share control with a barred entity?
BLUF: "It is likely (moderate confidence) that Nordvale Trading and the
barred entity share beneficial control."
Observation: both filings name the same accountancy firm; both domains resolve
to a registrant email (retrieved 2024-03-11,
archived). Inference: a shared registrant email indicates one registering party.
Assessment: likely common control — moderate, not high, because the beneficial
owner is undisclosed in that jurisdiction and a nominee arrangement remains
untested.
admin@ke-holdings.exampleNegative finding included: the shared home address reported by three
people-search sites was traced to one broker feed carrying an identical
misspelling; recorded as circular and excluded. Redacted: two co-residents at
that address, unrelated to the objective. Gap named: UBO register is
non-public; a formal request would close it.
目标:供应商是否与被封禁实体共享控制权?
BLUF:“有可能(中等可信度)Nordvale Trading与被封禁实体共享实际控制权。”
观察:两份备案文件均提及同一家会计师事务所;两个域名的注册邮箱均为(2024-03-11获取,已存档)。推断:共享注册邮箱表明由同一主体注册。评估:很可能存在共同控制权——可信度为中等而非高,因为该辖区未披露实际所有人,代理安排尚未验证。
admin@ke-holdings.example包含的负面调查结果:三个人员搜索网站报告的共享家庭地址可追溯至同一经纪商数据源,且存在相同拼写错误;已记录为循环信息并排除。编辑内容:该地址的两名无关居住者,与核心目标无关。指明的信息缺口:实际所有人登记册不公开;正式申请可填补该缺口。
Pivots
衔接
The report is the terminal product; it consumes rather than produces selectors.
Take the entity map from , the archived copies from
, and the scope statement from .
Unresolved indicators go back to the workflow that produces them.
graph-the-networkread-deleted-pagesinvestigate-anything报告是最终产品,它消耗而非生成选择器。使用生成的实体图、获取的存档副本,以及生成的范围声明。未解决的指标需返回至生成它们的工作流。
graph-the-networkread-deleted-pagesinvestigate-anythingLegal notes
法律提示
An OSINT report about a living person is personal data in its own right, and the
subject may have access rights to it in some jurisdictions — write every line as
if the subject will read it, because they may be entitled to. Reports likely to
be used in proceedings need the evidentiary format from Step 7 and unbroken
custody; a report assembled loosely and reformatted later cannot recover
custody it never had. Breach-derived material carries its own handling
constraints — see — and quoting credentials into a
report can itself be unlawful processing.
what-leaked-about-you关于自然人的OSINT报告本身属于个人数据,在某些司法辖区,报告对象可能有权访问报告——因此每一行都要假设报告对象会阅读,因为他们可能有权这么做。可能用于诉讼的报告需采用步骤7中的证据格式,并保持完整的监管链;松散汇编后重新格式化的报告无法恢复其从未拥有的监管链。泄露数据衍生的内容有其自身的处理限制——详见——在报告中引用凭证本身可能构成非法处理。
what-leaked-about-you