One bulletin says a crew targeting city halls "uses scheduled tasks and signed binaries for persistence." Another gives a single SHA-256. How should the analyst classify those two pieces?
Select an answer to reveal the explanation.
Short Explanation
How they work is the playbook; the hash is the jersey number on one jersey. Scheduled tasks plus signed binaries are tactical TTPs, while a SHA-256 is a technical IoC that dies when they recompile — do not swap those labels.
Full Explanation
Tactical intelligence describes TTPs — how the adversary operates, such as scheduled tasks and signed binaries. Technical intelligence is indicator-level, such as a specific hash. Neither item is strategic board context, and ES annotations do not fire notables by themselves. Civic Defense Analysts should keep the split so detections can aim at durable behaviors while threat lists handle perishable IoCs.