Threat Intelligence
Threat intelligence that becomes useful only after it has earned trust. Candidate indicators are proposed from confirmed findings, explicitly validated, and shared with provenance — and they can be contested or revoked when the evidence changes.
Born private. Carries the indicator, its epistemic, and confidence clamped to the backing finding — never the finding text or case content.
A reviewer checked the evidence and activated it. Still private until shared — activation is not publication.
Consumable by detection. Carries the indicator and an opaque reference to its source — the case file stays behind.
Stops influencing detection while the challenge is resolved. Cleared challenges return it to Active; sustained ones end in Revoked.
Illustrative example — the lifecycle every indicator travels; statuses and transitions are simplified.
A finding is not automatically intelligence.
Only a confirmed finding can propose a candidate indicator — and the proposal inherits the finding's epistemic level and carries no more confidence than the finding behind it. An analyst then explicitly reviews the evidence before anything becomes active. Detection never promotes itself.
What a proposal carries
An indicator is not the investigation.
A shared indicator carries what detection needs — the subject, its type, confidence, epistemic level, and an opaque reference to where it came from. It does not carry the case: no finding text, no notes, no decisions, no evidence bodies. Provenance travels with every indicator, so a consumer can always ask what earned it a place in the feed.
Intelligence that cannot change is a liability.
New evidence can challenge a shared indicator. A contested indicator stops influencing detection while the challenge is resolved — cleared challenges return it to active, sustained ones end in revocation, and revoked stays revoked. The history is preserved either way: a changed mind is a new row, never a rewrite.
What challenge looks like
- Contradicting evidence arrives — a destination first flagged as hostile is later verified as a legitimate service.
- The indicator is contested — it stops influencing detection while analysts resolve the conflict.
- Resolution is recorded — cleared (back to active) or revoked (terminal), with the reason preserved.
Inference never silently becomes fact.
Every indicator keeps the epistemic label it was proposed with. Observed stays observed; inferred stays inferred until a human confirms otherwise. And shared intelligence stays open to challenge — new evidence can contest or revoke it at any time.
12.4M USDC transferred from treasury_1 at 2026-08-04T14:32:04Z.
Deterministic. Never argued away.
Funds hop treasury_1 → 8qLm…2kDe → CEX deposit.
Reproducible, stamped with method and version.
CEX deposit address matches a verified exchange entity in the registry.
Only used when the link can be shown, not assumed.
The address set is likely operated by a single actor.
Never overrides facts. Never persisted unconfirmed.
VikingIntel distinguishes these levels in every finding. An inferred conclusion is labeled inferred — it is never presented as a verified fact, and it never overrides deterministic evidence. Correlation is not ownership proof: shared funding makes wallets worth reviewing, not persons identified.
When evidence is missing, exhausted, or ambiguous, the answer is unknown — stated plainly, never papered over with a guess. Unlabeled means unchecked; truncated means truncated.
Share what you have proven.
Propose indicators from your confirmed findings and build intelligence your whole team can trust.
No credit card required · Free forever