<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Analyst Mind]]></title><description><![CDATA[How analysts think through chaos — critical thinking, threat detection, and AI-augmented defence for security practitioners protecting critical infrastructure to the convergence of cyber and physical security]]></description><link>https://www.theanalystmind.io</link><image><url>https://substackcdn.com/image/fetch/$s_!2h1T!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b9b512c-fbc2-4f4e-bca6-93de9c92d1a9_64x64.png</url><title>The Analyst Mind</title><link>https://www.theanalystmind.io</link></image><generator>Substack</generator><lastBuildDate>Sat, 20 Jun 2026 17:56:53 GMT</lastBuildDate><atom:link href="https://www.theanalystmind.io/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Klaus Wunder]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[theanalystmind@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[theanalystmind@substack.com]]></itunes:email><itunes:name><![CDATA[Klaus Wunder]]></itunes:name></itunes:owner><itunes:author><![CDATA[Klaus Wunder]]></itunes:author><googleplay:owner><![CDATA[theanalystmind@substack.com]]></googleplay:owner><googleplay:email><![CDATA[theanalystmind@substack.com]]></googleplay:email><googleplay:author><![CDATA[Klaus Wunder]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Why Your Best Detection Tool Is Critical Thinking]]></title><description><![CDATA[Every year the stack grows: a new sensor, a new dashboard, a new detection pack, a new box that promises to catch what the last one missed.]]></description><link>https://www.theanalystmind.io/p/why-your-best-detection-tool-is-critical</link><guid isPermaLink="false">https://www.theanalystmind.io/p/why-your-best-detection-tool-is-critical</guid><dc:creator><![CDATA[Klaus Wunder]]></dc:creator><pubDate>Thu, 04 Jun 2026 23:50:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Z8qu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb07585f-576d-429f-bba1-34e39df0ae0b_2400x1440.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Every year the stack grows: a new sensor, a new dashboard, a new detection pack, a new box that promises to catch what the last one missed. The EDR. The SIEM. An NDR. The SOAR platform. The ticketing system. Two or three threat-intel feeds.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LRkI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c0bd24-0f17-4771-b560-98facde3d1f1_2400x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LRkI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c0bd24-0f17-4771-b560-98facde3d1f1_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!LRkI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c0bd24-0f17-4771-b560-98facde3d1f1_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!LRkI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c0bd24-0f17-4771-b560-98facde3d1f1_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!LRkI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c0bd24-0f17-4771-b560-98facde3d1f1_2400x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LRkI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c0bd24-0f17-4771-b560-98facde3d1f1_2400x1440.png" width="1456" height="874" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2c0bd24-0f17-4771-b560-98facde3d1f1_2400x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:170225,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/200660998?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c0bd24-0f17-4771-b560-98facde3d1f1_2400x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LRkI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c0bd24-0f17-4771-b560-98facde3d1f1_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!LRkI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c0bd24-0f17-4771-b560-98facde3d1f1_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!LRkI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c0bd24-0f17-4771-b560-98facde3d1f1_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!LRkI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c0bd24-0f17-4771-b560-98facde3d1f1_2400x1440.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The detections get faster. The dashboards get denser. And every year, analysts still miss things. Not because a tool failed. Because the thinking did.</p><h2>We borrowed the words</h2><p>Look at the language the industry runs on. Almost none of it is ours. War games come from Prussian Kriegsspiel. Triage from Napoleonic battlefield medicine. Kill chain from US Air Force targeting doctrine. OPSEC from a Vietnam-era operation. OSINT, red team, blue team, TTPs. We took the military's operational vocabulary wholesale, and we took some of its frameworks with it: the kill chain, the threat models, the exercises.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-NnL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8faed2d2-bcc6-4885-95b4-0801029679a2_2400x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-NnL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8faed2d2-bcc6-4885-95b4-0801029679a2_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!-NnL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8faed2d2-bcc6-4885-95b4-0801029679a2_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!-NnL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8faed2d2-bcc6-4885-95b4-0801029679a2_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!-NnL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8faed2d2-bcc6-4885-95b4-0801029679a2_2400x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-NnL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8faed2d2-bcc6-4885-95b4-0801029679a2_2400x1440.png" width="1456" height="874" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8faed2d2-bcc6-4885-95b4-0801029679a2_2400x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:163543,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/200660998?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8faed2d2-bcc6-4885-95b4-0801029679a2_2400x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-NnL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8faed2d2-bcc6-4885-95b4-0801029679a2_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!-NnL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8faed2d2-bcc6-4885-95b4-0801029679a2_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!-NnL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8faed2d2-bcc6-4885-95b4-0801029679a2_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!-NnL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8faed2d2-bcc6-4885-95b4-0801029679a2_2400x1440.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There is one thing we did not take. The discipline underneath the words: how their analysts learned to think.</p><p>The intelligence community spent generations on exactly that problem, why smart analysts make bad calls, and what to do about it. They wrote it down. Richards Heuer&#8217;s <em>Psychology of Intelligence Analysis</em> came out of the CIA in 1999. David T. Moore&#8217;s <em>Critical Thinking and Intelligence Analysis</em> came out of the National Defense Intelligence College. Both are public. Both are free.</p><p>We borrowed the words. We did not borrow the discipline. The gap is not in the stack. It is in how we read what the stack shows us.</p><h2>Monday morning</h2><p>It is Monday morning. The queue is full  and it is not getting shorter.</p><p>You open the first alert. EDR-2026-04822. Severity medium. A developer workstation on the engineering subnet, the user signed in, business hours. Three commands in a single burst:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;219787ff-ef76-4ba3-b1d6-8029797e1de1&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">whoami
net group "Domain Admins" /domain
nltest /domain_trusts</code></pre></div><p>Parent process is the interactive shell. No outbound traffic before or after. The EDR verdict is low confidence: recon-like, but probably an admin script or someone poking around.</p><p>You have seen this five times this month. Active session, known user, normal hours, nothing following it. It looks routine. Your cursor is already on the close button.</p><p>Routine false positive at thirty seconds or a missed breach uncovered in thirty days.</p><p>Here is the same alert, walked through one investigation template. Five sections, the telemetry you were about to dismiss.</p><h2>Section 1 - Intake</h2><p>Before you read the alert as a story, you fill in six cells. Five W's and an H, borrowed from journalism and formalized by police and intelligence services.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7nD-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a549c23-9fe9-4afe-8387-8044670dfd9a_2400x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7nD-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a549c23-9fe9-4afe-8387-8044670dfd9a_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!7nD-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a549c23-9fe9-4afe-8387-8044670dfd9a_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!7nD-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a549c23-9fe9-4afe-8387-8044670dfd9a_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!7nD-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a549c23-9fe9-4afe-8387-8044670dfd9a_2400x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7nD-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a549c23-9fe9-4afe-8387-8044670dfd9a_2400x1440.png" width="1456" height="874" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8a549c23-9fe9-4afe-8387-8044670dfd9a_2400x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:126166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/200660998?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a549c23-9fe9-4afe-8387-8044670dfd9a_2400x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7nD-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a549c23-9fe9-4afe-8387-8044670dfd9a_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!7nD-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a549c23-9fe9-4afe-8387-8044670dfd9a_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!7nD-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a549c23-9fe9-4afe-8387-8044670dfd9a_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!7nD-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a549c23-9fe9-4afe-8387-8044670dfd9a_2400x1440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The cell that carries the weight is WHO. Not &#8220;the developer.&#8221; A session originating from the developer&#8217;s workstation. Those are two different things. The first phrasing smuggles in a trusted human and quietly decides which evidence will feel relevant later. The second leaves the question open. That single word is where anchoring loses its grip.</p><p>The rest fall into place once the framing is honest. WHAT is domain reconnaissance, the textbook shape of account and trust enumeration. WHERE is an engineering workstation, a tier that has no business mapping Domain Admins. WHY has no plausible answer for a developer mid-sprint. HOW looks like a human at a keyboard, which is a fact to hold, not a conclusion to trust.</p><h2>Section 2 - Hypotheses</h2><p>The fastest way to confirm what you already believe is to carry a hypothesis. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!g6cg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354f95d7-d532-4e1f-ba01-77fc4cf38038_2400x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!g6cg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354f95d7-d532-4e1f-ba01-77fc4cf38038_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!g6cg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354f95d7-d532-4e1f-ba01-77fc4cf38038_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!g6cg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354f95d7-d532-4e1f-ba01-77fc4cf38038_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!g6cg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354f95d7-d532-4e1f-ba01-77fc4cf38038_2400x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!g6cg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354f95d7-d532-4e1f-ba01-77fc4cf38038_2400x1440.png" width="1456" height="874" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/354f95d7-d532-4e1f-ba01-77fc4cf38038_2400x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:138027,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/200660998?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354f95d7-d532-4e1f-ba01-77fc4cf38038_2400x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!g6cg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354f95d7-d532-4e1f-ba01-77fc4cf38038_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!g6cg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354f95d7-d532-4e1f-ba01-77fc4cf38038_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!g6cg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354f95d7-d532-4e1f-ba01-77fc4cf38038_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!g6cg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354f95d7-d532-4e1f-ba01-77fc4cf38038_2400x1440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is Analysis of Competing Hypotheses, Heuer&#8217;s method. The rule is at least two, better three. H1, a developer with a reason. H2, a real attacker operating through the live session. H3, an authorised red team that is functionally identical to H2 in the telemetry and completely different in the response it demands.</p><p>The third hypothesis is the one most queues never write down, and it is the one that decides whether the next hour is incident response or a phone call. Rank the three by the evidence that would disprove them, not the evidence that would confirm them. One hypothesis is not an investigation. It is a guess with paperwork.</p><h2>Section 3 - Evidence</h2><p>Evidence has two moves, and the order matters. First you assemble. Then you weigh.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bu-k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa98f86c9-fb89-43aa-8677-c7d0f6503e96_2400x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bu-k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa98f86c9-fb89-43aa-8677-c7d0f6503e96_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!bu-k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa98f86c9-fb89-43aa-8677-c7d0f6503e96_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!bu-k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa98f86c9-fb89-43aa-8677-c7d0f6503e96_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!bu-k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa98f86c9-fb89-43aa-8677-c7d0f6503e96_2400x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bu-k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa98f86c9-fb89-43aa-8677-c7d0f6503e96_2400x1440.png" width="1456" height="874" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a98f86c9-fb89-43aa-8677-c7d0f6503e96_2400x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:159445,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/200660998?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa98f86c9-fb89-43aa-8677-c7d0f6503e96_2400x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bu-k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa98f86c9-fb89-43aa-8677-c7d0f6503e96_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!bu-k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa98f86c9-fb89-43aa-8677-c7d0f6503e96_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!bu-k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa98f86c9-fb89-43aa-8677-c7d0f6503e96_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!bu-k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa98f86c9-fb89-43aa-8677-c7d0f6503e96_2400x1440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Assembling means a multi-source timeline in UTC and a typed list of indicators. On this alert the timeline is short and the indicator list is thin. No hashes. No command-and-control. No file written to disk. That emptiness is not nothing. The absence of atomic indicators is itself a finding: this looks like hands on a keyboard, not malware on a host. A sixty-second gap with no outbound traffic is not innocence. Attackers and red teams both pause between recon and the next stage.</p><p>Then you weigh. Every piece of evidence carries a rating.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nMLO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd8dfdf5-c371-46d3-ac64-f7f22e9e692f_2400x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nMLO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd8dfdf5-c371-46d3-ac64-f7f22e9e692f_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!nMLO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd8dfdf5-c371-46d3-ac64-f7f22e9e692f_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!nMLO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd8dfdf5-c371-46d3-ac64-f7f22e9e692f_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!nMLO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd8dfdf5-c371-46d3-ac64-f7f22e9e692f_2400x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nMLO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd8dfdf5-c371-46d3-ac64-f7f22e9e692f_2400x1440.png" width="1456" height="874" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cd8dfdf5-c371-46d3-ac64-f7f22e9e692f_2400x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:130123,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/200660998?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd8dfdf5-c371-46d3-ac64-f7f22e9e692f_2400x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nMLO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd8dfdf5-c371-46d3-ac64-f7f22e9e692f_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!nMLO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd8dfdf5-c371-46d3-ac64-f7f22e9e692f_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!nMLO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd8dfdf5-c371-46d3-ac64-f7f22e9e692f_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!nMLO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd8dfdf5-c371-46d3-ac64-f7f22e9e692f_2400x1440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Admiralty Code is a NATO standard, two characters: a letter for how reliable the source is and a number for how credible the information is. Most analysts have never seen it, and it is the cleanest defence against confirmation bias I know.</p><p>Rate the case. The user says they did not run those commands. That is a fairly reliable person making an unverified claim about one specific session: C3, not A1. The session telemetry shows the account logged in, which says the session is open, not that the human is at the keyboard: B2. The network silence is definitive log data supporting a doubtful inference: A4. Three pieces of evidence, and not one of them rates above C3 toward the benign story. The hypothesis you wanted to pick is not earning its weight. The point of the rating is that it makes you say so out loud.</p><h2>Section 4 - Adversarial Review</h2><p>The brain that built the bias cannot detect it alone. So you attack your own analysis before someone else does.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N2ld!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65fbb0c-1fd0-4265-9300-c8c91e3c5513_2400x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N2ld!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65fbb0c-1fd0-4265-9300-c8c91e3c5513_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!N2ld!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65fbb0c-1fd0-4265-9300-c8c91e3c5513_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!N2ld!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65fbb0c-1fd0-4265-9300-c8c91e3c5513_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!N2ld!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65fbb0c-1fd0-4265-9300-c8c91e3c5513_2400x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N2ld!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65fbb0c-1fd0-4265-9300-c8c91e3c5513_2400x1440.png" width="1456" height="874" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b65fbb0c-1fd0-4265-9300-c8c91e3c5513_2400x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:127671,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/200660998?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65fbb0c-1fd0-4265-9300-c8c91e3c5513_2400x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N2ld!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65fbb0c-1fd0-4265-9300-c8c91e3c5513_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!N2ld!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65fbb0c-1fd0-4265-9300-c8c91e3c5513_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!N2ld!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65fbb0c-1fd0-4265-9300-c8c91e3c5513_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!N2ld!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65fbb0c-1fd0-4265-9300-c8c91e3c5513_2400x1440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Start with the bias checklist: keep the actor&#8217;s name out of the ticket until evidence supports it, check the base rate for your environment, ask what you would conclude without the tool. Then put the story in front of a devil&#8217;s advocate, someone whose only job is to break it. That can be a team member, an LLM, or you after a short break with fresh eyes.</p><p>One move decides this case. Deconfliction rules out friendly fire. A single question to the security manager: is anyone authorized running offensive testing in this environment right now. The answer sorts an incident from a learning conversation, and skipping it is how teams either burn response ressources on their own red team or close on a real intruder. The pre-mortem comes last, a final stress-test: assume the analysis was wrong and write what you missed before you commit.</p><h2>Section 5 - Decision</h2><p>Analysis that does not move is a diary entry. The decision is a loop, not a checkbox.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qbEM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e8d4cb-ff15-4848-93cf-91ff15f75397_2400x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qbEM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e8d4cb-ff15-4848-93cf-91ff15f75397_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!qbEM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e8d4cb-ff15-4848-93cf-91ff15f75397_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!qbEM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e8d4cb-ff15-4848-93cf-91ff15f75397_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!qbEM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e8d4cb-ff15-4848-93cf-91ff15f75397_2400x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qbEM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e8d4cb-ff15-4848-93cf-91ff15f75397_2400x1440.png" width="1456" height="874" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c3e8d4cb-ff15-4848-93cf-91ff15f75397_2400x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:126632,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/200660998?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e8d4cb-ff15-4848-93cf-91ff15f75397_2400x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qbEM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e8d4cb-ff15-4848-93cf-91ff15f75397_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!qbEM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e8d4cb-ff15-4848-93cf-91ff15f75397_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!qbEM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e8d4cb-ff15-4848-93cf-91ff15f75397_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!qbEM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e8d4cb-ff15-4848-93cf-91ff15f75397_2400x1440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>John Boyd built the OODA loop for fighter pilots deciding under fire. Observe pulls the full process tree and prior host activity. Orient places it against the three hypotheses: H2 and H3 both hold, H1 does not. Decide is not "close." It is escalate to a hunt and run deconfliction in parallel. Act executes both. Then the loop turns, because the act produced new data: the hunt finds two more workstations running the same recon pattern inside forty-eight hours. One event was an anomaly. Three is a campaign.</p><h2>The reveal</h2><p>Deconfliction comes back. There was an authorized, no-notice red team running that month. Initial access was a spearphish to a finance employee two weeks earlier. The developer workstation was the third stop in their lateral movement and they were heading for the Tier Zero tier.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!H99e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e9f828-5143-4aba-8fb8-e938c03f1052_2400x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!H99e!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e9f828-5143-4aba-8fb8-e938c03f1052_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!H99e!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e9f828-5143-4aba-8fb8-e938c03f1052_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!H99e!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e9f828-5143-4aba-8fb8-e938c03f1052_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!H99e!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e9f828-5143-4aba-8fb8-e938c03f1052_2400x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!H99e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e9f828-5143-4aba-8fb8-e938c03f1052_2400x1440.png" width="1456" height="874" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b5e9f828-5143-4aba-8fb8-e938c03f1052_2400x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:151827,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/200660998?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e9f828-5143-4aba-8fb8-e938c03f1052_2400x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!H99e!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e9f828-5143-4aba-8fb8-e938c03f1052_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!H99e!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e9f828-5143-4aba-8fb8-e938c03f1052_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!H99e!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e9f828-5143-4aba-8fb8-e938c03f1052_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!H99e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e9f828-5143-4aba-8fb8-e938c03f1052_2400x1440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Same telemetry as a real attacker, same urgency and same TTPs. </p><p>Different attribution: </p><p>Closed as a false positive, this is a missed breach. The red team writes a friendly debrief. A real adversary deploys ransomware to your environment.</p><p>Same analyst, Same tooling but different discipline. Eight minutes from the alert you could have closed to an escalation. The only thing that changed was the order of your thinking.</p><h2>The full walk is one page</h2><p>Five sections, one artifact. The filled template is the handover: the next analyst inherits your reasoning, not just your verdict.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z8qu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb07585f-576d-429f-bba1-34e39df0ae0b_2400x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z8qu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb07585f-576d-429f-bba1-34e39df0ae0b_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!Z8qu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb07585f-576d-429f-bba1-34e39df0ae0b_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!Z8qu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb07585f-576d-429f-bba1-34e39df0ae0b_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!Z8qu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb07585f-576d-429f-bba1-34e39df0ae0b_2400x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z8qu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb07585f-576d-429f-bba1-34e39df0ae0b_2400x1440.png" width="1456" height="874" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eb07585f-576d-429f-bba1-34e39df0ae0b_2400x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:149018,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/200660998?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb07585f-576d-429f-bba1-34e39df0ae0b_2400x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z8qu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb07585f-576d-429f-bba1-34e39df0ae0b_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!Z8qu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb07585f-576d-429f-bba1-34e39df0ae0b_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!Z8qu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb07585f-576d-429f-bba1-34e39df0ae0b_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!Z8qu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb07585f-576d-429f-bba1-34e39df0ae0b_2400x1440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Triage is not investigation</h2><p>Everything above is an investigation. Most of your day may not.</p><p>When the queue is full and you have minutes per alert, you are triaging, not investigating. Triage is the decision of which alerts earn the full template and which do not. It is a different job, and it has its own version of the discipline.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JSca!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5a38183-967f-40d7-9009-67c4fc8e5896_2400x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JSca!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5a38183-967f-40d7-9009-67c4fc8e5896_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!JSca!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5a38183-967f-40d7-9009-67c4fc8e5896_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!JSca!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5a38183-967f-40d7-9009-67c4fc8e5896_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!JSca!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5a38183-967f-40d7-9009-67c4fc8e5896_2400x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JSca!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5a38183-967f-40d7-9009-67c4fc8e5896_2400x1440.png" width="1456" height="874" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c5a38183-967f-40d7-9009-67c4fc8e5896_2400x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:105989,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/200660998?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5a38183-967f-40d7-9009-67c4fc8e5896_2400x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JSca!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5a38183-967f-40d7-9009-67c4fc8e5896_2400x1440.png 424w, https://substackcdn.com/image/fetch/$s_!JSca!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5a38183-967f-40d7-9009-67c4fc8e5896_2400x1440.png 848w, https://substackcdn.com/image/fetch/$s_!JSca!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5a38183-967f-40d7-9009-67c4fc8e5896_2400x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!JSca!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5a38183-967f-40d7-9009-67c4fc8e5896_2400x1440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Three questions. What is my primary hypothesis right now. How would I rate my strongest piece of evidence on Admiralty. What single thing would change my mind. A couple minutes per alert, run on the queue, not on a single case. Not every alert is a case. Triage is how you find the one that is.</p><h2>The work is already done</h2><p>The intelligence community already figured out why good analysts make bad calls. They wrote it up and gave it away.</p><p>If you have followed this series, you have been collecting the pieces. The four biases. The two systems. The W + H questions. Each post was one tool. This is the piece where they live together in a single page you can run on a real shift.</p><p>We do not have to redo it. We borrowed the words. Now borrow the discipline.</p><h2>What is on the horizon</h2><p>The next version of this problem is already coming. AI writes the first-draft triage now, fluent and confident and sometimes wrong, the job is shifting from producing the analysis to judging the machine's analysis. An LLM verdict starts unverified, the same as any other source. The discipline that rates a person's claim is the discipline that rates the model's.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.theanalystmind.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.theanalystmind.io/subscribe?"><span>Subscribe now</span></a></p><p></p><h2>Appendix: The Investigation Template</h2><p>Copy this into your notes app, your ticketing system, or a markdown file. It is a living document. Fill it as the investigation moves.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;markdown&quot;,&quot;nodeId&quot;:&quot;7696c583-60c6-4715-a1e1-e4bd088810dc&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-markdown"># Investigation Template

*Companion artefact to "Why Your Best Detection Tool Is Critical Thinking"*

---

## Case Header

- **TLP Classification:** [ ] RED  [ ] AMBER+STRICT  [ ] AMBER  [ ] GREEN  [ ] CLEAR
- **Case ID:**
- **Analyst:**
- **Opened (UTC):**
- **Status:** [ ] Open  [ ] Escalated  [ ] Closed

---

## Timeline (UTC, Multi-Source)

| Timestamp (UTC) | Source | Event Description |
|------------------|--------|-------------------|
| YYYY-MM-DD HH:MM | | |
| YYYY-MM-DD HH:MM | | |
| YYYY-MM-DD HH:MM | | |
| YYYY-MM-DD HH:MM | | |

&gt; Mark timezone differences explicitly. Look for gaps. Hours with no log data indicate often missing evidence, not absence of activity.

---

## Section 1 - Intake (5W+H)

*Goal: structured first read of the alert before pattern-matching kicks in.*

| Question | Response |
|----------|----------|
| **WHO**  | Victim(s), suspected actor(s), beneficiaries |
| **WHAT** | Exactly what happened, in one sentence |
| **WHEN** | First observed AND earliest indicator (UTC) |
| **WHERE**| Systems, networks, geography |
| **WHY**  | Likely motive: ransom, espionage, sabotage, profit |
| **HOW**  | Initial access vector and kill-chain stage so far |

---

## Section 2 - Hypotheses (ACH + TTPs)

*Goal: force at least two hypotheses. One hypothesis is not an investigation.*

### Hypothesis 1 (Primary)
- **Description:**
- **Confidence:** [ ] HIGH (70-100%)  [ ] MEDIUM (40-70%)  [ ] LOW (1-40%)
- **TTPs to hunt for:**
- **Disproving evidence would be:**

### Hypothesis 2 (Alternative)
- **Description:**
- **Confidence:** [ ] HIGH  [ ] MEDIUM  [ ] LOW
- **TTPs to hunt for:**
- **Disproving evidence would be:**

### Hypothesis 3 (Optional: Insider / Red Team / Supply Chain / Benign)
- **Description:**
- **Confidence:** [ ] HIGH  [ ] MEDIUM  [ ] LOW
- **TTPs to hunt for:**
- **Disproving evidence would be:**

&gt; Rank hypotheses by which has the most disconfirming evidence, not the most confirming evidence. Heuer, Analysis of Competing Hypotheses.

---

## Section 3 - Evidence (Admiralty Scored)

*Goal: every piece of evidence carries a credibility rating. Unrated evidence gets a free pass it has not earned.*

| Type | Indicator | Admiralty | TTPs | Notes |
|------|-----------|-----------|------|-------|
| Hash | | | | |
| IP | | | | |
| Domain | | | | |
| URL | | | | |
| File Path | | | | |
| Other | | | | |

**Admiralty Code reference:**
- **Source reliability (A-F):** A = Completely reliable, B = Usually reliable, C = Fairly reliable, D = Not usually reliable, E = Unreliable, F = Cannot be judged
- **Information credibility (1-6):** 1 = Confirmed by other sources, 2 = Probably true, 3 = Possibly true, 4 = Doubtful, 5 = Improbable, 6 = Cannot be judged

&gt; Example: B2 = Usually reliable source, probably true. LLM output on framed indicators starts at F6 until verified by independent evidence.

---

## Section 4 - Adversarial Review

*Goal: actively try to break your own analysis before someone else does.*

### Bias Checklist

- [ ] **Anchoring defence:** Actor / malware name banned from ticket until evidence supports it
- [ ] **Tool verdicts manually verified:** What would I conclude without the tool?
- [ ] **Base-rate check:** Is this common in OUR environment?
- [ ] **Null hypothesis considered:** Could this be benign?

### Devil's Advocate

&gt; Someone whose only job is to break the primary hypothesis. Not for approval, for disagreement. It can be a team member, an LLM, or yourself after a short break.

**Who or what challenged it:**

### Information Gaps

- [ ] Missing log sources?
- [ ] Unchecked systems?
- [ ] Unverified IOCs?
- [ ] Memory not captured?
- [ ] **What single piece of evidence would change your primary hypothesis?**
- [ ] Other:

### Pre-mortem

&gt; Imagine it is six months from now and this analysis was wrong. What did we miss? Write the postmortem before the incident.

**Response:**

---

## Section 5 - Decision (OODA)

*Goal: turn analysis into action and feed the result back into analysis. The loop runs until the case closes.*

| Phase | Question | Response |
|---|---|---|
| **OBSERVE** | What raw data is in front of you right now? | |
| **ORIENT** | What does it mean given your context and current hypotheses? | |
| **DECIDE** | Contain, escalate, investigate further, close? | |
| **ACT** | What did you execute, with what authority, with what outcome? | |

&gt; Every action produces new data. Feed it back to OBSERVE. The loop runs continuously until the case is closed and handed over.

### Under-pressure version (5-minute triage)

When you do not have time for the full template, you are triaging, not investigating. The OODA loop collapses to three questions:

1. **What is my primary hypothesis right now?**
2. **How would I rate the strongest evidence on Admiralty?**
3. **What single thing would change my mind?**

Decide. Act. Loop.

---

## Overall Case Confidence

**Confidence in hypothesis:** [ ] HIGH (70-100%)  [ ] MEDIUM (40-70%)  [ ] LOW (1-40%)

**Justification (2-3 sentences):**
- What evidence supports this confidence level?
- What evidence still has gaps?
- Which assumption, if wrong, would drop your confidence by one level?

---

**Analyst:** ___________________  **Date:** ___________________  **Case ID:** ___________________

&gt; The filled template IS the handover. The next analyst inherits your thinking, not just your conclusions. Write it so they can pick up the case without asking you a question.</code></pre></div>]]></content:encoded></item><item><title><![CDATA[Two Systems]]></title><description><![CDATA[One Shift]]></description><link>https://www.theanalystmind.io/p/two-systems</link><guid isPermaLink="false">https://www.theanalystmind.io/p/two-systems</guid><dc:creator><![CDATA[Klaus Wunder]]></dc:creator><pubDate>Mon, 18 May 2026 02:09:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!32UT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fea6196-73c4-411d-a325-3734d01dd814_1200x780.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>It is the end of a long shift.</h2><p>Thirty alerts are already closed. The dashboard is calm. You can see the finish line. The handover meeting is twenty minutes away, and for the first time today, the queue is almost empty.</p><p>One last incident pops.</p><p>You open it. It looks routine. The kind of alert you have seen a hundred times. Same pattern, same source, same shape. You scan the evidence, run two quick checks, and close it. Clean.</p><p>You hand over. The incoming analyst sees a green dashboard. You log off, and for the first time in eight hours, your shoulders drop.</p><p>It feels good.</p><h2>The Unease</h2><p>Three hours later, you are eating dinner, and the thought arrives uninvited.</p><div class="pullquote"><p><em>Did I miss something?</em></p></div><p>You cannot name what. There is no smoking gun in your memory, no specific detail your mind is flagging. Just a low background hum of unease, sitting under everything else, refusing to leave.</p><p>You try to dismiss it. The ticket was routine. You have closed a hundred like it. The dashboard was green.</p><p>The hum gets louder overnight.</p><p>The next morning, before your first coffee, you pull the ticket up again. You read it properly this time, line by line, not pattern-matching, not skimming. And whether or not you find anything you missed, one thing is now clear.</p><p>You closed a ticket yesterday on a verdict you had never actually tested.</p><h2>Two Systems</h2><p>What happened in those two moments, the close at the end of shift and the unease three hours later, is the cleanest possible illustration of a framework Daniel Kahneman won a Nobel Prize for naming. In his book <em>Thinking, Fast and Slow</em>, he describes two distinct systems running inside every human mind.</p><p>System 1 is fast. It is automatic. It recognises patterns, completes sentences, drives your car on a road you know. It is low-effort and almost always on. It is how you closed the ticket in ninety seconds at the end of shift.</p><p>System 2 is slow. It is deliberate. It is the system you use to multiply two three-digit numbers, to read a sentence with care, to reconstruct a chain of reasoning. It is high-effort, and you cannot run it for long without depleting yourself. It is the system that arrived three hours later, after dinner, when the noise of the day had subsided and your mind finally had the bandwidth to revisit what your fast brain had already disposed of.</p><p>System 2 did not arrive too slowly because something was wrong with you. It arrived too slowly because the SOC, by design, runs on System 1.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!32UT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fea6196-73c4-411d-a325-3734d01dd814_1200x780.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!32UT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fea6196-73c4-411d-a325-3734d01dd814_1200x780.png 424w, https://substackcdn.com/image/fetch/$s_!32UT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fea6196-73c4-411d-a325-3734d01dd814_1200x780.png 848w, https://substackcdn.com/image/fetch/$s_!32UT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fea6196-73c4-411d-a325-3734d01dd814_1200x780.png 1272w, https://substackcdn.com/image/fetch/$s_!32UT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fea6196-73c4-411d-a325-3734d01dd814_1200x780.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!32UT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fea6196-73c4-411d-a325-3734d01dd814_1200x780.png" width="728" height="473.2" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5fea6196-73c4-411d-a325-3734d01dd814_1200x780.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:780,&quot;width&quot;:1200,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:488521,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/197902906?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fea6196-73c4-411d-a325-3734d01dd814_1200x780.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!32UT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fea6196-73c4-411d-a325-3734d01dd814_1200x780.png 424w, https://substackcdn.com/image/fetch/$s_!32UT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fea6196-73c4-411d-a325-3734d01dd814_1200x780.png 848w, https://substackcdn.com/image/fetch/$s_!32UT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fea6196-73c4-411d-a325-3734d01dd814_1200x780.png 1272w, https://substackcdn.com/image/fetch/$s_!32UT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fea6196-73c4-411d-a325-3734d01dd814_1200x780.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h2>System 1 Is Not the Problem</h2><p>This is the first thing to get right, because the rest of the article depends on it.</p><p>System 1 is not the enemy. It is the only reason you can do this job. If you ran every alert through full deliberate reasoning, you would close four tickets a shift instead of forty. You would burn out by month three. The analysts who have lasted in this work for ten or twenty years are not the ones who suppress their fast brain. They are the ones who have trained it on enough cases that its pattern-matching is sharp.</p><p>The problem is not that you used System 1 at the end of shift. The problem is that nothing in the room told you that this particular ticket was one where you needed to switch. Not the tooling. Not the workflow. Not the dashboard going green.</p><p>That is the analyst&#8217;s job. Not to run on System 2 always. That is impossible. Not to abandon System 1. That is suicidal at SOC volumes. The job is to read the evidence in front of you, <em>including the evidence of your own thinking</em>, and recognise when the fast version of the answer is going to be wrong.</p><p>The clearest signal that System 2 needs to take over is the one we covered in the last post. The moment you notice you are running into a bias, your fast brain is producing exactly the kind of cheap answer it evolved to produce, and you are about to commit to it. Confirmation pulls you toward the easy hypothesis. Anchoring fixes your reading to the alert label. Availability nudges you toward last week&#8217;s case. Automation hands you a verdict you never checked. Each one is a flag. Each one is the switch.</p><h2>Five Triggers That Should Force the Switch</h2><p>You will not catch every System 1 close in real time. Nobody does. But there are five conditions where you can install a small, repeatable habit of pausing before you commit.</p><p><strong>One. You notice you are matching the pattern, not reading the evidence.</strong> This is the bias signal. The moment you find yourself thinking <em>I have seen this before</em> before you have actually looked at the data, you are on confirmation-and-anchoring autopilot. Stop and read the ticket as if you have never seen it.</p><p><strong>Two. End of shift, or cognitive depletion.</strong> The scenario at the top of this article is not rare. It is the most common single failure mode in SOC work. Your last five tickets of a long shift deserve more scrutiny than your first five, not less. The dopamine of a clean dashboard is not evidence.</p><p><strong>Three. An inherited verdict.</strong> A handover, a peer, or a previous shift hands you a conclusion. <em>Looks like a false positive.We already cleared this.</em> Your System 1 will accept the verdict and start working downstream of it. Rebuild the reasoning from raw evidence, or you are not investigating. You are inheriting.</p><p><strong>Four. Conflicting evidence inside the same ticket.</strong> When two data points disagree and your brain quietly resolves the conflict in favour of the more familiar one, that resolution is System 1 erasing inconvenient information. Surface the conflict explicitly. Write it down. Do not let it dissolve.</p><p><strong>Five. A tool or AI verdict that feels right too easily.</strong> Automation bias is System 1 outsourced. When a SIEM rule, an EDR verdict, or an LLM-generated summary lines up with your first instinct, you are receiving two System 1 outputs reinforcing each other. That is not corroboration. That is correlated error. Ask what you would have decided if the tool had said nothing.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!T3B_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F467e12ac-6623-4881-87e0-b3f9fd21c5a1_1200x780.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!T3B_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F467e12ac-6623-4881-87e0-b3f9fd21c5a1_1200x780.png 424w, https://substackcdn.com/image/fetch/$s_!T3B_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F467e12ac-6623-4881-87e0-b3f9fd21c5a1_1200x780.png 848w, https://substackcdn.com/image/fetch/$s_!T3B_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F467e12ac-6623-4881-87e0-b3f9fd21c5a1_1200x780.png 1272w, https://substackcdn.com/image/fetch/$s_!T3B_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F467e12ac-6623-4881-87e0-b3f9fd21c5a1_1200x780.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!T3B_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F467e12ac-6623-4881-87e0-b3f9fd21c5a1_1200x780.png" width="1200" height="780" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/467e12ac-6623-4881-87e0-b3f9fd21c5a1_1200x780.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:780,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:518725,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/197902906?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F467e12ac-6623-4881-87e0-b3f9fd21c5a1_1200x780.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!T3B_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F467e12ac-6623-4881-87e0-b3f9fd21c5a1_1200x780.png 424w, https://substackcdn.com/image/fetch/$s_!T3B_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F467e12ac-6623-4881-87e0-b3f9fd21c5a1_1200x780.png 848w, https://substackcdn.com/image/fetch/$s_!T3B_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F467e12ac-6623-4881-87e0-b3f9fd21c5a1_1200x780.png 1272w, https://substackcdn.com/image/fetch/$s_!T3B_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F467e12ac-6623-4881-87e0-b3f9fd21c5a1_1200x780.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Why the Unease Worked. Signal and Noise.</h2><p>Now back to the dinner-table moment.</p><p>The unease three hours later was not magic. It was not intuition in the mystical sense. It was a signal.</p><p>Somewhere in the ticket you closed, there was a detail that did not fit the pattern your fast brain matched it to. System 1 noticed it. System 1 notices almost everything. But it did not flag it loudly enough to interrupt the close. During the shift, that signal was buried under the noise of thirty other alerts, the rhythm of the queue, and the dopamine of a clean handover.</p><p>After the shift, the noise floor dropped. The other thirty tickets were gone. The queue was someone else&#8217;s problem. And the signal that had been buried all afternoon finally rose above the noise.</p><p>This is the same signal-versus-noise problem you already understand from detection engineering, applied now to your own cognition. The goal of System 2 is not to manufacture suspicion. It is to lower the noise floor of your own thinking enough that the real signal, the detail that did not fit, has a chance to be heard <em>before</em> the close, not three hours after it.</p><p>The five triggers are how you do that without burning yourself out trying to be slow all the time. They are not a discipline of constant vigilance. They are a small set of conditions in which you have agreed, in advance, that the fast version of the answer is not good enough.</p><h2>What Comes Next</h2><p>If this post has done its job, the next time you reach the end of a long shift and one last ticket lands, you will hear a different question in your head. Not <em>can I close this and go home</em>, but <em>which system is about to close this ticket, and is it the right one for the job</em>.</p><p>This piece is part of the Analyst Framework series on The Analyst Mind. The series builds the cognitive toolkit a SOC analyst actually needs, one principle at a time. The biases that distort fast thinking. The questions that structure an investigation. The competing hypotheses that test your reasoning. The deliberate pause that catches what you almost missed. The moments where AI augmentation quietly becomes correlated error. Stay tuned.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.theanalystmind.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Analyst Mind! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Hypotheses]]></title><description><![CDATA[The Theories You Are Actually Testing]]></description><link>https://www.theanalystmind.io/p/hypotheses</link><guid isPermaLink="false">https://www.theanalystmind.io/p/hypotheses</guid><dc:creator><![CDATA[Klaus Wunder]]></dc:creator><pubDate>Fri, 01 May 2026 20:28:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!5H-S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88ee77-f213-4c41-8d65-33aea930245c_1200x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>You are two hours into an investigation.</p><p>You have pulled authentication logs. You have pulled endpoint telemetry. You have checked the user directory, cross-referenced the asset database, queried the firewall. Your notes field is full. Your tabs are full. Your coffee is cold.</p><p>And if someone asked you right now - what do you think happened? - you would struggle to answer.</p><p>That is the moment most analysts mistake for investigation. It is not. It is browsing.</p><h3><strong>Evidence Without a Theory Is Just Data</strong></h3><p>Here is the uncomfortable truth about most SOC work. Analysts believe their job is to find evidence. To pull logs. To correlate indicators. To chase down the unusual thing until it resolves into something nameable.</p><p>That is not the job.</p><p>The job is to build and kill theories. The evidence only matters in relation to the theories it supports or contradicts. Without a hypothesis, you are not investigating, you are scrolling through data hoping the answer will surface itself. It rarely does. And when it does, you cannot explain why.</p><p>If you cannot state what you think happened in a single clear sentence, you are not investigating yet. You are preparing to investigate.</p><h3><strong>The First Hypothesis Is a Trap</strong></h3><p>So you force yourself to state a theory. </p><p><em>&#8220;The account was compromised via stolen credentials from a phishing email earlier this week.&#8221;</em></p><p>Now you have a hypothesis. And the moment you have one, something dangerous happens.</p><p>Your brain starts working for it, not against it. Every log line that fits the theory becomes &#8220;evidence.&#8221; Every log line that doesn&#8217;t fit becomes &#8220;noise.&#8221; You start searching for confirmation, and confirmation is cheap. If you only have one theory, every piece of matching data feels like progress. But you are no longer investigating. You are assembling a case for a verdict you have already reached.</p><p>This is the pattern the first post in this series named as confirmation bias. It hits every analyst, every day. The only reliable countermeasure is structural: refuse to work with a single hypothesis.</p><p><strong>If you have one theory, you do not have an investigation. You have a confirmation exercise with extra steps.</strong></p><h3><strong>The Minimum Is Two</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5H-S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88ee77-f213-4c41-8d65-33aea930245c_1200x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5H-S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88ee77-f213-4c41-8d65-33aea930245c_1200x420.png 424w, https://substackcdn.com/image/fetch/$s_!5H-S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88ee77-f213-4c41-8d65-33aea930245c_1200x420.png 848w, https://substackcdn.com/image/fetch/$s_!5H-S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88ee77-f213-4c41-8d65-33aea930245c_1200x420.png 1272w, https://substackcdn.com/image/fetch/$s_!5H-S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88ee77-f213-4c41-8d65-33aea930245c_1200x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5H-S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88ee77-f213-4c41-8d65-33aea930245c_1200x420.png" width="1200" height="420" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8d88ee77-f213-4c41-8d65-33aea930245c_1200x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:356685,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/196135267?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88ee77-f213-4c41-8d65-33aea930245c_1200x420.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5H-S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88ee77-f213-4c41-8d65-33aea930245c_1200x420.png 424w, https://substackcdn.com/image/fetch/$s_!5H-S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88ee77-f213-4c41-8d65-33aea930245c_1200x420.png 848w, https://substackcdn.com/image/fetch/$s_!5H-S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88ee77-f213-4c41-8d65-33aea930245c_1200x420.png 1272w, https://substackcdn.com/image/fetch/$s_!5H-S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88ee77-f213-4c41-8d65-33aea930245c_1200x420.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The rule is simple. You need at least two competing hypotheses before you touch the evidence again.</p><p>For any suspicious authentication alert, the starting pair might be:</p><ul><li><p>Hypothesis A: The account is compromised. Credentials were stolen and are being used by an external actor.</p></li><li><p>Hypothesis B: The account is legitimate. The unusual pattern has a benign explanation &#8212; VPN routing, a new device, travel the user forgot to mention.</p></li></ul><p>That is not enough. You push for a third.</p><ul><li><p>Hypothesis C: Misconfiguration. A recent change to the authentication system is producing false signals.</p></li></ul><p>And if you are serious, a fourth.</p><ul><li><p>Hypothesis D: Insider activity. The user themselves is doing something they should not, using their own valid credentials.</p></li></ul><p>Each hypothesis changes what evidence is meaningful. Under Hypothesis A, the absence of VPN logs is damning. Under Hypothesis B, the absence of VPN logs is trivial, maybe the user is on their home network. The same data carries different weight depending on which theory you are testing.</p><p>This is the reason Analysis of Competing Hypotheses from intelligence tradecraft works. It forces you to look for the absence of expected evidence, not just the presence of confirming evidence. The hypothesis with the least contradicting evidence is the strongest. Not the one with the most confirming evidence. Confirmation is cheap. Disconfirmation is diagnostic.</p><h3><strong>Where the Augmented Analyst Wins</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FY86!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F134c3485-eb8f-48f3-8976-1a7e76c969a9_1200x380.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FY86!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F134c3485-eb8f-48f3-8976-1a7e76c969a9_1200x380.png 424w, https://substackcdn.com/image/fetch/$s_!FY86!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F134c3485-eb8f-48f3-8976-1a7e76c969a9_1200x380.png 848w, https://substackcdn.com/image/fetch/$s_!FY86!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F134c3485-eb8f-48f3-8976-1a7e76c969a9_1200x380.png 1272w, https://substackcdn.com/image/fetch/$s_!FY86!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F134c3485-eb8f-48f3-8976-1a7e76c969a9_1200x380.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FY86!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F134c3485-eb8f-48f3-8976-1a7e76c969a9_1200x380.png" width="1200" height="380" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/134c3485-eb8f-48f3-8976-1a7e76c969a9_1200x380.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:380,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:354074,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/196135267?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F134c3485-eb8f-48f3-8976-1a7e76c969a9_1200x380.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FY86!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F134c3485-eb8f-48f3-8976-1a7e76c969a9_1200x380.png 424w, https://substackcdn.com/image/fetch/$s_!FY86!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F134c3485-eb8f-48f3-8976-1a7e76c969a9_1200x380.png 848w, https://substackcdn.com/image/fetch/$s_!FY86!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F134c3485-eb8f-48f3-8976-1a7e76c969a9_1200x380.png 1272w, https://substackcdn.com/image/fetch/$s_!FY86!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F134c3485-eb8f-48f3-8976-1a7e76c969a9_1200x380.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is the place in modern SOC work where AI earns its keep, if the analyst knows how to use it.</p><p>A well-prompted language model can do two things with hypotheses that no enrichment pipeline can do.</p><p><strong>1. It can pre-fill the hypothesis space.</strong> You describe the observed behaviour and ask for five plausible explanations. The model returns a list. Some are obvious. Some are things you would have reached on your own. And sometimes, not always, but often enough to matter, one or two are paths you would not have considered. Not because you lack experience, but because you are thinking inside the constraints of your current case. The model is not. That breadth is the value.</p><p><strong>2. It can challenge the hypothesis you already hold.</strong> You hand it your theory and ask: what evidence would prove this wrong? What alternative explanations fit the same facts? Where does this reasoning break down? Used this way, the model is a structured devil&#8217;s advocate &#8212; the role intelligence analysts have assigned to senior reviewers for decades, now available in real time.</p><p>Neither of these is a replacement for analyst judgment. Both are amplifiers.</p><p>The augmented analyst is not an analyst who defers to the model. The augmented analyst is one who uses the model to stress-test their own thinking and who still owns every conclusion. The AI expands the hypothesis space. The analyst decides which hypotheses are worth pursuing, which evidence actually supports them, and what the answer means for the business, the environment, and the decision at hand.</p><p>There is a trap here, and it is worth naming. If you prompt an LLM with your existing theory and ask it to help you build the case, it will - willingly and convincingly. The model is a compliance machine unless you deliberately instruct it otherwise. It will generate supporting reasoning, surface matching indicators, construct a coherent narrative. Every one of those outputs feels like progress. None of it is investigation. It is confirmation bias with machine-grade production values.</p><p>The discipline is to always ask the model the second question. Not just &#8220;does this theory hold?&#8221; but &#8220;what would make this theory wrong?&#8221; If you only ask the first, you are not using AI as a thinking partner. You are using it as a yes-machine.</p><p><strong>Hypotheses Are Living Documents</strong></p><p>Treat your hypotheses the way a scientist treats them: as things that must be written down, compared against evidence, and updated as the investigation develops.</p><p>Not held in your head.</p><p>The moment your hypotheses live only in your head, two things happen. First, you lose track of which ones you have actually considered and which ones felt obvious enough to skip. Second, you quietly revise your theory as new evidence comes in without noticing you are doing it. A phenomenon behavioural scientists call hindsight bias, and it is lethal to investigation quality.</p><p>Writing them down forces honesty. A hypothesis you wrote at 14:05 that no longer matches the evidence at 15:30 is a hypothesis you killed. That kill is useful. It tells you what you learned. An unwritten hypothesis that silently morphed to fit the new evidence teaches you nothing, because you were never testing it in the first place.</p><p>Your investigation notes should answer three questions at any moment:</p><ul><li><p>What hypotheses am I currently considering?</p></li><li><p>What evidence supports or contradicts each one?</p></li><li><p>What would I need to see to rule any of them in or out?</p></li></ul><p>If your notes do not answer those three questions, you are not building an investigation. You are building a timeline of your own attention.</p><p><strong>Your Hypothesis Depends on Your Assumptions</strong></p><p>Before you get too attached to any theory, pause on one question: what am I assuming about the data that this hypothesis depends on?</p><p>Your theory might be &#8220;the account was compromised at 14:32.&#8221; But if the timestamps you are reasoning from are in the wrong timezone, you are testing the wrong hypothesis entirely. A 14:32 UTC event interpreted as local time shifts the entire narrative. Suddenly the &#8220;suspicious login after hours&#8221; is a routine login during business hours. Your whole case collapses - not because the analysis was flawed, but because the assumption underneath it was.</p><p>This is the opening into the next post in this series. Hypotheses live or die by the timeline they are tested against. And timelines are harder to build than most analysts realise. That is where we go next.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5fhA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd962c9ec-ec3b-4b22-a64c-7dee674c141c_1200x280.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5fhA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd962c9ec-ec3b-4b22-a64c-7dee674c141c_1200x280.png 424w, https://substackcdn.com/image/fetch/$s_!5fhA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd962c9ec-ec3b-4b22-a64c-7dee674c141c_1200x280.png 848w, https://substackcdn.com/image/fetch/$s_!5fhA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd962c9ec-ec3b-4b22-a64c-7dee674c141c_1200x280.png 1272w, https://substackcdn.com/image/fetch/$s_!5fhA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd962c9ec-ec3b-4b22-a64c-7dee674c141c_1200x280.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5fhA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd962c9ec-ec3b-4b22-a64c-7dee674c141c_1200x280.png" width="1200" height="280" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d962c9ec-ec3b-4b22-a64c-7dee674c141c_1200x280.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:280,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:242652,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/196135267?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd962c9ec-ec3b-4b22-a64c-7dee674c141c_1200x280.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5fhA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd962c9ec-ec3b-4b22-a64c-7dee674c141c_1200x280.png 424w, https://substackcdn.com/image/fetch/$s_!5fhA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd962c9ec-ec3b-4b22-a64c-7dee674c141c_1200x280.png 848w, https://substackcdn.com/image/fetch/$s_!5fhA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd962c9ec-ec3b-4b22-a64c-7dee674c141c_1200x280.png 1272w, https://substackcdn.com/image/fetch/$s_!5fhA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd962c9ec-ec3b-4b22-a64c-7dee674c141c_1200x280.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>The Starting Move</strong></p><p>Starting tomorrow, make this the first thing you do after the W+H baseline is in place: write down at least two competing hypotheses in plain language. No jargon. No actor names. Just what you think might have happened, in sentences a peer could challenge.</p><p>If you cannot write two, you do not know enough to investigate yet. That is useful information. Go gather more context.</p><p>If you write two and one of them feels obviously correct before you examine the evidence, that is the hypothesis you should interrogate hardest. Not because it is wrong, but because &#8220;obviously correct&#8221; is the sound confirmation bias makes when it is working.</p><p>The evidence is not the investigation. The theories are the investigation. The evidence is how you choose between them.</p>]]></content:encoded></item><item><title><![CDATA[The 5W+H Questions]]></title><description><![CDATA[Structuring Your Thinking From Minute One]]></description><link>https://www.theanalystmind.io/p/the-5wh-questions</link><guid isPermaLink="false">https://www.theanalystmind.io/p/the-5wh-questions</guid><dc:creator><![CDATA[Klaus Wunder]]></dc:creator><pubDate>Sun, 29 Mar 2026 20:23:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hqiL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b05679-afec-4408-858b-ccb596f4a887_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>You are sixty seconds into an investigation. The alert fired. The ticket is open. The clock is running.</p><p>Most analysts do the same thing: they dive, straight into the logs, straight into the tool stack, straight into whatever data is closest. No structure. No sequence. Just motion.</p><p>Motion feels productive. It is not the same as progress.</p><p>The problem is not speed. The problem is that without a framework for what to ask first, the investigation is shaped by whatever data happens to land in front of you. The first log entry anchors your thinking. The first IOC becomes the theory. And from there, you are not investigating, you are confirming.</p><p>If you read the first post in this series, you recognise that pattern. Anchoring bias meets confirmation bias, sixty seconds in, before the analyst even knows it is happening.</p><p>There is a countermeasure. It is old. It is simple. It works:</p><h2>Six Questions, One Framework</h2><p>Who. What. When. Where. Why. How.</p><p>The 5W+H framework has been used in journalism, military intelligence, and law enforcement for decades. It is not clever. It is not novel. That is the point. Its value is that it forces completeness before it allows depth.</p><p>When you open an investigation with the 5W+H questions, you are not solving yet. You are mapping. You are building the landscape of the problem before you pick a direction to walk.</p><ul><li><p><strong>Who</strong> is affected? Who triggered the alert? Who owns the asset? Who else might be involved?</p></li><li><p><strong>What</strong> happened? What did the detection actually fire on? What is the observable behaviour, stripped of the tool&#8217;s interpretation?</p></li><li><p><strong>When</strong> did it start? When was it detected? Is there a gap between those two? What was happening in that gap?</p></li><li><p><strong>Where</strong> in the environment? Which system, which network segment, which cloud tenant? Where does this asset sit in your architecture, and what can it reach?</p></li><li><p><strong>Why</strong> does this matter? Why would an attacker target this? Why now? Or why might this be benign?</p></li><li><p><strong>How</strong> did it happen? How did the activity occur technically? How was access gained, or how was the process initiated?</p></li></ul><p>None of these questions are hard. All of them are missed &#8212; routinely &#8212; when analysts skip straight to hypothesis.</p><h2>The Blank Page Problem</h2><p>Here is where it gets practical.</p><p>One of the biggest friction points in investigation work is the blank page. A ticket opens. The analyst stares at an empty notes field and a pile of raw telemetry. Where do you even start?</p><p>This is where automation earns its place, not as a replacement for the analyst, but as a pre-fill for the obvious.</p><p>A well-configured SOAR playbook, enrichment pipeline, or even an LLM integration can answer a significant portion of the 5W+H  questions before the analyst touches the case. The factual, contextual baseline: Who is this user? What is their role? What asset is this? Where does it sit in the network? When did the alert fire, and what is the detection logic behind it? What does the raw event look like?</p><p>That pre-fill is valuable. It eliminates the blank page. It gives the analyst a starting point that is structured, not random. Instead of diving into logs with no direction, the analyst opens a case and sees a partially completed 5W+H matrix, a map with some terrain already sketched in.</p><p>This is the kind of work automation was built for. Gathering context. Correlating identifiers. Pulling asset data and user profiles. Fast, repeatable, boring. Exactly the tasks that should not consume analyst time.</p><p>But here is the part that matters more than the efficiency gain.</p><h2>The Answers Are Not Settled</h2><p>The pre-filled 5W+H is a starting point. It is not the investigation. Every line is a premise to question, not a fact to accept.</p><p>The moment you treat the automated answers as settled, you have swapped one blind spot for another, a page so complete it stops you from asking the questions that matter.</p><p>Think about what happens. Automation says the &#8220;Who&#8221; is a specific user. The analyst accepts that and moves on. But what if the account was compromised? Then the &#8220;Who&#8221; is not the user &#8212; it is an attacker using stolen credentials. The initial answer was technically correct (this is the account) and operationally misleading (this is not the person).</p><p>The &#8220;What&#8221; might say &#8220;suspicious login from unusual location.&#8221; That is the alert summary. But the actual &#8220;What&#8221; might be the third step in a multi-stage intrusion that started days earlier. The alert is not the event &#8212; it is the symptom that finally crossed a detection threshold.</p><p>Military intelligence analysts are trained to challenge their own assessments as rigorously as they build them. The 5W+H framework operates the same way. Each question is asked at least twice: once to establish the baseline, and again as the investigation develops to test whether the baseline still holds.</p><p>This is where you earn your value. Not in gathering the initial facts, automation handles that. In asking the second-order questions that automation cannot reach.</p><p><strong>Who</strong> &#8212; beyond the account name, who actually performed this action? Is there evidence of shared credentials, compromised tokens, delegated access?</p><p><strong>What</strong> &#8212; beyond the alert description, what is the full sequence of activity? What happened before and after the detection? What did the attacker do that the detection did <em>not</em> catch?</p><p><strong>Why</strong> &#8212; beyond &#8220;it looked suspicious,&#8221; why would an attacker choose this path? What is the strategic value of this asset, this account, this timing? Or, what benign explanation accounts for all the evidence, not just most of it?</p><p>These are judgment questions. They require context that no enrichment pipeline carries: knowledge of the business, understanding of the environment&#8217;s normal patterns, awareness of what happened last week and what is planned for next week. The analyst brings this. The tool does not.</p><h2>A Bias Check Built Into the Structure</h2><p>There is a second benefit to the 5W+H framework that goes beyond investigation efficiency.</p><p>The structure itself is a bias countermeasure.</p><p>When you force yourself to answer all six questions &#8212; not just the ones that feel relevant &#8212; you are resisting the pull of confirmation bias. Your hypothesis might explain the What and the How beautifully. But can it explain the When? Does the timing actually make sense? And the Where, does the affected system fit the theory, or did you quietly ignore that the activity originated from a segment that contradicts your hypothesis?</p><p>The 5W+H questions create a completeness check. They make the gaps visible. And gaps &#8212; missing answers, questions you cannot explain &#8212; are often more diagnostic than the data you have.</p><p>The questions you cannot answer tell you more than the ones you can.</p><p>This is why the framework matters even for experienced analysts who think they do not need a checklist. Especially for experienced analysts. Experience builds pattern recognition, but it also builds assumptions. The 5W+H framework forces those assumptions into the open where they can be examined.</p><p>Combine this with a habit from earlier in this series. The deliberate pause: that moment before closure where you stop confirming and start challenging. Before you close the case, revisit each 5W+H. Has the answer changed since the investigation started? If your final &#8220;Who&#8221; is the same as your initial &#8220;Who&#8221;, are you confident because you verified it, or because you never questioned it?</p><h2>The Handoff Model</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hqiL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b05679-afec-4408-858b-ccb596f4a887_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hqiL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b05679-afec-4408-858b-ccb596f4a887_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!hqiL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b05679-afec-4408-858b-ccb596f4a887_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!hqiL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b05679-afec-4408-858b-ccb596f4a887_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!hqiL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b05679-afec-4408-858b-ccb596f4a887_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hqiL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b05679-afec-4408-858b-ccb596f4a887_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/29b05679-afec-4408-858b-ccb596f4a887_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:547729,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/192454779?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b05679-afec-4408-858b-ccb596f4a887_1200x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hqiL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b05679-afec-4408-858b-ccb596f4a887_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!hqiL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b05679-afec-4408-858b-ccb596f4a887_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!hqiL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b05679-afec-4408-858b-ccb596f4a887_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!hqiL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b05679-afec-4408-858b-ccb596f4a887_1200x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So the practical model looks like this:</p><p><strong>Layer 1 Automation</strong>: Pre-fill the 5W+H matrix with factual, contextual data. User identity, asset information, alert metadata, geolocation, network context, related recent alerts. Fast. Structured. Consistent across every case.</p><p><strong>Layer 2 Analyst baseline review</strong>: Read the pre-fill. Your first question is not &#8220;does this look right?&#8221; Your first question is: <strong>what assumptions are embedded in these answers?</strong> What does the automation not know? What is missing? Flag anything that feels incomplete and flag anything that feels too clean.</p><p><strong>Layer 3 Analyst deep investigation</strong>: Pursue the second-order W questions. Test whether the initial answers survive scrutiny. Build competing explanations. Look for what the automation could not see: intent, context, strategic meaning, absence of expected evidence.</p><p><strong>Layer 4 Bias check</strong>: Before closing, walk the full 5W+H one final time. Compare your final answers to the initial pre-fill. Where they differ, you learned something. Where they match, verify that you actually confirmed them, rather than simply never challenged them.</p><p>This is not a workflow diagram for a SOAR platform. It is a thinking model. The automation handles the context gathering so the analyst can focus on the cognition. That is the division of labour that actually works.</p><h2>What Comes Next</h2><p>The 5W+H framework gives you a structure for the first minutes. But an investigation is more than its opening. In the next post, we will tie everything together &#8212; the bias countermeasures, the reasoning chain, the 5W+H questions &#8212; into a full investigation template. A single, practical document that carries you from alert to closure with structured thinking at every stage.</p><p>The tools will change. The thinking compounds.</p>]]></content:encoded></item><item><title><![CDATA[Blind Spots in the SOC: Four Cognitive Biases That Make Analysts Miss What Matters]]></title><description><![CDATA[Why smart analysts reach wrong conclusions, and how to catch yourself]]></description><link>https://www.theanalystmind.io/p/blind-spots-in-the-soc-four-cognitive</link><guid isPermaLink="false">https://www.theanalystmind.io/p/blind-spots-in-the-soc-four-cognitive</guid><dc:creator><![CDATA[Klaus Wunder]]></dc:creator><pubDate>Mon, 09 Mar 2026 18:38:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rRxi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3538259-caa6-4510-a8b5-e2e77e79d562_1200x780.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2><strong>Your brain is working against you.</strong></h2><p>Not because you are a bad analyst. Not because you lack training or tools. But because you are human, and human brains take shortcuts. Those shortcuts kept our ancestors alive when a rustling bush might be a predator. In a SOC during an active incident, those same shortcuts make you miss things.</p><p>Cognitive biases are not personal flaws. They are features of how the human brain processes information under time pressure, uncertainty, and cognitive load. In cybersecurity, we rarely talk about this. We talk about tools, detections, frameworks, and playbooks. But we almost never talk about the human operating all of it.</p><p>This is part one of a series. Todays focus: The four biases I see hit SOC analysts the hardest, with real-world examples and practical ways to counter each one.</p><p></p><h2><strong>Confirmation Bias: Seeing What You Expect to See</strong></h2><p>You are investigating a suspicious authentication alert. Early in the triage, you find one indicator matching a known APT group. Your brain locks in: this is APT activity.</p><p>From that moment, everything you see gets filtered through that lens. Log entries that support the theory. Evidence. Log entries that contradict it. Noise, probably unrelated. You stop looking for alternative explanations because you already have one that fits.</p><p>The problem is that &#8220;fits&#8221; is not the same as &#8220;correct.&#8221; While you were building your APT case, you missed the data exfiltration that started three days before the alert fired. You missed it because you were not looking for it. You were looking for confirmation.</p><p>This is confirmation bias. The tendency to search for, interpret, and remember information that supports what you already believe, while ignoring or dismissing what contradicts it.</p><p><strong>How to counter it:</strong> Before closing any case, ask yourself one question: &#8220;What evidence would prove me wrong, and have I looked for it?&#8221; If you cannot answer that, your investigation is not finished. In my training sessions, I teach the Analysis of Competing Hypotheses method. You must generate at least two competing explanations before settling on one. If you only have one theory, you do not have an investigation. You have a confirmation exercise.</p><h2><strong>Anchoring Bias: The First Data Point Wins</strong></h2><p>The SIEM flags an alert as &#8220;Critical.&#8221; You open the ticket, and before you have looked at a single log, your brain has already decided this is serious. That severity label has become your anchor.</p><p>Now everything you investigate gets measured against that anchor. Lower-severity alerts in the same timeframe? They seem less important by comparison. You deprioritize them. But the real initial access was buried in one of those lower-severity alerts three entries earlier. You missed it because the first thing you saw shaped everything that followed.</p><p>Anchoring bias is the tendency to rely too heavily on the first piece of information you encounter. That first data point, whether it is a severity score, an alert title, a colleague&#8217;s opinion, or the first IOC you find, it disproportionately influences every judgment that follows.</p><p><strong>How to counter it:</strong> Always ask: &#8220;What if my first data point is wrong?&#8221; Start from the raw evidence, not from labels or scores. When investigating an alert chain, deliberately examine the full sequence rather than focusing on whichever alert triggered first. One technique I use in training: ban actor names and malware names from ticket titles. The moment you write &#8220;APT29 Investigation&#8221; at the top of your ticket, every analyst who touches it is anchored before they read a single log line.</p><h2><strong>Availability Bias: Recent Experience Distorts Your Judgment</strong></h2><p>Your team spent last week responding to a ransomware incident. It was painful, visible, and everyone remembers it. This week, an alert fires showing unusual file encryption activity on a server. Your gut says ransomware. It feels obvious.</p><p>But &#8220;feels obvious&#8221; is not analysis. What you are actually experiencing is availability bias, that is the tendency to judge the likelihood of something based on how easily examples come to mind, rather than on actual base rates.</p><p>Because ransomware is fresh in your memory, your brain overestimates the probability that this new alert is also ransomware. Meanwhile, the actual cause &#8212; a backup process using encryption that was recently reconfigured &#8212; gets overlooked because you are preconditioned. </p><p>This works in the other direction too. A high-profile APT campaign hits the news, and suddenly every lateral movement alert in your environment feels like nation-state activity. The base rate for nation-state attacks against your organization has not changed. But your perception of the risk has.</p><p><strong>How to counter it:</strong> Check base rates. What does the monitoring in your environment actually show? Use historical data, not recent memory. When you catch yourself thinking &#8220;this looks just like last week,&#8221; pause and ask: &#8220;How common is this attack type in our environment, based on data, not based on what I remember?&#8221;</p><h2>Automation Bias: Trusting the Tool Over Your Own Judgment</h2><p>The EDR scans the endpoint. "No malware detected." The SOAR enrichment comes back clean. The risk score says "Low."</p><p>You see all of this. Something about the alert still feels off &#8212; maybe the timing, maybe the process chain. But the tools say it is clean. So you close the ticket and move on.</p><p>That is automation bias. Not the tool auto-closing the ticket without you seeing it. You closing the ticket because the tool told you it was fine, even though your instinct said otherwise.</p><p>The analyst is still in the loop. The analyst still makes the decision. But the decision is shaped by the tool&#8217;s verdict rather than by independent analysis. The tool becomes the authority, and the analyst becomes the one who clicks &#8220;close.&#8221;</p><p>This bias is going to get worse as LLMs enter the analyst workflow. An AI-generated investigation summary sounds confident and well-structured even when it is wrong. If you do not have the skills to critically evaluate that output, you have a bigger problem than alert fatigue.</p><p><strong>How to counter it:</strong> Trust but verify. Build a habit of spot-checking automated verdicts. When a tool gives you a clean bill of health, ask yourself: &#8220;What would I decide if the tool did not exist?&#8221; If you cannot answer that, you are not augmenting your analysis with automation ,  you are replacing your analysis with automation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rRxi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3538259-caa6-4510-a8b5-e2e77e79d562_1200x780.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rRxi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3538259-caa6-4510-a8b5-e2e77e79d562_1200x780.png 424w, https://substackcdn.com/image/fetch/$s_!rRxi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3538259-caa6-4510-a8b5-e2e77e79d562_1200x780.png 848w, https://substackcdn.com/image/fetch/$s_!rRxi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3538259-caa6-4510-a8b5-e2e77e79d562_1200x780.png 1272w, https://substackcdn.com/image/fetch/$s_!rRxi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3538259-caa6-4510-a8b5-e2e77e79d562_1200x780.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rRxi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3538259-caa6-4510-a8b5-e2e77e79d562_1200x780.png" width="1200" height="780" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d3538259-caa6-4510-a8b5-e2e77e79d562_1200x780.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:780,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:545986,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.theanalystmind.io/i/190399606?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3538259-caa6-4510-a8b5-e2e77e79d562_1200x780.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rRxi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3538259-caa6-4510-a8b5-e2e77e79d562_1200x780.png 424w, https://substackcdn.com/image/fetch/$s_!rRxi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3538259-caa6-4510-a8b5-e2e77e79d562_1200x780.png 848w, https://substackcdn.com/image/fetch/$s_!rRxi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3538259-caa6-4510-a8b5-e2e77e79d562_1200x780.png 1272w, https://substackcdn.com/image/fetch/$s_!rRxi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3538259-caa6-4510-a8b5-e2e77e79d562_1200x780.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>What&#8217;s Next</strong></h2><p>These four biases are not the full picture. They are the ones I see most often in SOC environments. Knowing they exist is the first step. But awareness alone does not fix the problem,  you need practical tools to fight them in real time.</p><p>In the next article, I will cover the W questions that structure your thinking from the first minute of an investigation. Continuing we build the full investigation template that ties it all together.</p><p>Remember: <strong>Biases are not something you fix once. They are something you manage every day.</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.theanalystmind.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.theanalystmind.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[What cybersecurity can learn from military intelligence and the CIA]]></title><description><![CDATA[Critical thinking frameworks that every analyst should know]]></description><link>https://www.theanalystmind.io/p/what-cybersecurity-can-learn-from</link><guid isPermaLink="false">https://www.theanalystmind.io/p/what-cybersecurity-can-learn-from</guid><dc:creator><![CDATA[Klaus Wunder]]></dc:creator><pubDate>Fri, 27 Feb 2026 17:36:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2h1T!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b9b512c-fbc2-4f4e-bca6-93de9c92d1a9_64x64.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Cybersecurity has always borrowed from the military. Lockheed Martin&#8217;s Cyber Kill Chain. MITRE ATT&amp;CK, rooted in intelligence analysis methodology. Red teaming itself comes from military war gaming. The language we use every day like threat actors, campaigns, reconnaissance, exfiltration, that is military language.</p><p>We took their offensive frameworks. We took their defensive models. We took their vocabulary.</p><p>But I realized we skipped the one thing that makes all of it work: how they train their analysts to think.</p><p>Two weeks ago I posted five critical thinking habits for security analysts on LinkedIn. The response surprised me, not just the engagement, but the conversations it started. Team leads sharing what they struggle to teach. Analysts admitting they&#8217;d never been trained to think, only to follow playbooks. Career changers asking where to even begin. </p><p>It confirmed something I&#8217;ve believed for a long time: cybersecurity has a thinking problem, not a tools problem.</p><p>So I want to go deeper. Not just five habits, but the actual frameworks behind them,  where they come from, why they work, and how you can apply them starting today.</p><p><strong>The intelligence community figured this out decades ago</strong></p><p>Here&#8217;s something most security professionals don&#8217;t know: the military and intelligence community have been formally training analysts in critical thinking for over 30 years. They had to. When a wrong assessment can cost lives, you can&#8217;t afford analysts who only follow procedures.</p><p>The CIA published &#8220;Psychology of Intelligence Analysis&#8221;, a book specifically about the cognitive biases that cause analysts to reach wrong conclusions. Not technical biases. Human biases. Confirmation bias. Anchoring. Mirror imaging. The same traps that cause a SOC analyst to close a ticket too fast, because the evidence looks like something they&#8217;ve seen before.</p><p>David T. Moore, writing for the National Defense Intelligence College, published &#8220;Critical Thinking and Intelligence Analysis&#8221; which laid out a core principle: analysts must simultaneously build a logical reasoning chain AND objectively challenge their own logic. Not one or the other. Both at the same time.</p><p>This isn&#8217;t abstract philosophy. This is operational tradecraft. And it translates directly to cybersecurity.</p><p><strong>Applying this in the SOC</strong></p><p>Let me make this concrete. You get an alert: a user account is authenticating from two geographic locations within an impossible travel timeframe. </p><p>An analyst following a playbook checks the VPN logs, confirms whether the user has a travel ticket, and either escalates or closes.</p><p>An analyst using critical thinking does something different: </p><p>Purpose: what am I actually trying to determine? Not &#8220;is this a true positive&#8221; but &#8220;is this account compromised?&#8221;</p><p><strong>Assumptions</strong>: I&#8217;m assuming the geolocation data is accurate. I&#8217;m assuming the user only has one device. Am I sure about both?</p><p><strong>Information</strong>: what data do I have? What data am I missing? Are there other signals I should correlate &#8212; endpoint telemetry, email activity, privilege changes?</p><p><strong>Inferences</strong>: if this account IS compromised, what would the attacker do next? What evidence would I expect to see? If it ISN&#8217;T compromised, what benign explanations exist and what evidence supports them?</p><p><strong>Point of view</strong>: am I looking at this only from a defensive perspective? If I were the attacker, would this alert even be the real concern, or would it be a distraction?</p><p>This is the difference between an alert handler and an analyst.</p><p><strong>Why this matters more now than ever</strong></p><p>LLMs are becoming part of the analyst workflow. They&#8217;re impressive tools. But they are pattern-matching engines that generate the most probable answer, not necessarily the correct one. They sound authoritative even when they&#8217;re wrong.</p><p>If you don&#8217;t have the critical thinking skills to evaluate an LLM&#8217;s output with the same rigor you&#8217;d evaluate a suspicious process execution, you have a problem. AI amplifies the analyst, but only if the analyst has the judgment to question its conclusions.</p><p>The intelligence community understood this about their analysts decades ago. Cybersecurity is only now catching up.</p><p><strong>Where to start</strong></p><p>You don&#8217;t need a certification or a master&#8217;s degree to start thinking more critically. But if you want structured paths, the best part is that these foundational texts are available for free.</p><p>But the real starting point is simpler than any book:</p><p>The next time you investigate an alert, PAUSE. Ask yourself what you&#8217;re assuming. Consider the opposite of your first conclusion. Explain your reasoning out loud. Check whether your thinking would hold up if someone challenged every step.</p><div class="preformatted-block" data-component-name="PreformattedTextBlockToDOM"><label class="hide-text" contenteditable="false">Text within this block will maintain its original spacing when published</label><pre class="text">That pause &#8212; that moment of deliberate, structured thinking &#8212; is what separates good analysts from the ones who catch what everyone else missed.</pre></div><p>Tools change every year. Thinking compounds forever.</p><p><strong>Further reading:</strong></p><ul><li><p>Psychology of Intelligence Analysis &#8212; Richards J. Heuer Jr., CIA (free PDF):<a href="https://www.cia.gov/resources/csi/static/Pyschology-of-Intelligence-Analysis.pdf">https://www.cia.gov/resources/csi/static/Pyschology-of-Intelligence-Analysis.pdf</a></p></li><li><p>Critical Thinking and Intelligence Analysis &#8212; David T. Moore, National Defense Intelligence College (free PDF):<a href="https://apps.dtic.mil/sti/tr/pdf/ADA481702.pdf">https://apps.dtic.mil/sti/tr/pdf/ADA481702.pdf</a></p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.theanalystmind.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Analyst Mind! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Why I Started The Analyst Mind]]></title><description><![CDATA[I&#8217;ve spent nearly two decades in cybersecurity.]]></description><link>https://www.theanalystmind.io/p/why-i-started-the-analyst-mind</link><guid isPermaLink="false">https://www.theanalystmind.io/p/why-i-started-the-analyst-mind</guid><dc:creator><![CDATA[Klaus Wunder]]></dc:creator><pubDate>Fri, 20 Feb 2026 23:35:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!tx0q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbb1786d-2646-4cff-b35c-17224c8731a3_2697x1320.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tx0q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbb1786d-2646-4cff-b35c-17224c8731a3_2697x1320.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tx0q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbb1786d-2646-4cff-b35c-17224c8731a3_2697x1320.heic 424w, https://substackcdn.com/image/fetch/$s_!tx0q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbb1786d-2646-4cff-b35c-17224c8731a3_2697x1320.heic 848w, https://substackcdn.com/image/fetch/$s_!tx0q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbb1786d-2646-4cff-b35c-17224c8731a3_2697x1320.heic 1272w, https://substackcdn.com/image/fetch/$s_!tx0q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbb1786d-2646-4cff-b35c-17224c8731a3_2697x1320.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tx0q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbb1786d-2646-4cff-b35c-17224c8731a3_2697x1320.heic" width="1456" height="713" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fbb1786d-2646-4cff-b35c-17224c8731a3_2697x1320.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:713,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:736743,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://theanalystmind.substack.com/i/188670526?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbb1786d-2646-4cff-b35c-17224c8731a3_2697x1320.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tx0q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbb1786d-2646-4cff-b35c-17224c8731a3_2697x1320.heic 424w, https://substackcdn.com/image/fetch/$s_!tx0q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbb1786d-2646-4cff-b35c-17224c8731a3_2697x1320.heic 848w, https://substackcdn.com/image/fetch/$s_!tx0q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbb1786d-2646-4cff-b35c-17224c8731a3_2697x1320.heic 1272w, https://substackcdn.com/image/fetch/$s_!tx0q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbb1786d-2646-4cff-b35c-17224c8731a3_2697x1320.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I&#8217;ve spent nearly two decades in cybersecurity. Hands on networks before the cloud existed. Protecting systems where a breach doesn&#8217;t just cost data, it costs safety.</p><p>In that time, I&#8217;ve trained analysts and teams across red team, blue team, and everything in between. And one pattern keeps showing up.</p><p>The people who perform best &#8212; in exercises, during incidents, when troubleshooting at 3am &#8212; aren&#8217;t the ones with the longest cert list or the latest tools. They&#8217;re the ones who think differently.</p><p>They question before they escalate. They sit with discomfort instead of closing the ticket. They understand the why, not just the what.</p><p>That&#8217;s what this newsletter is about.</p><p>The Analyst Mind is where I share what I&#8217;ve learned from years of training, incident response, detection engineering, troubleshooting, and building secure infrastructure &#8212; not as a tool guide, but as a thinking guide. Whether you&#8217;re a SOC analyst, a sysadmin, a network engineer, or somewhere in between, the mindset is what makes the difference.</p><p>What you can expect here:</p><p>Deeper dives into the topics I post about on LinkedIn &#8212; critical thinking, offensive skills for defenders, AI in security operations, threat hunting, and incident preparedness.</p><p>Frameworks and mental models that make you better at your craft &#8212; not because you memorize more, but because you reason better.</p><p>Behind-the-scenes lessons from real training exercises, tabletop scenarios, and operational troubleshooting &#8212; what worked, what failed, and why.</p><p>My honest take on where this industry is heading &#8212; especially as AI reshapes how we work.</p><p>I started this because I believe our industry doesn&#8217;t have a tools problem. It has a thinking problem. And the people who solve that &#8212; whether they sit in a SOC, a server room, or a red team engagement &#8212; will be the ones who define the next era of security.</p><p>If that resonates, subscribe. I publish every two weeks, and I keep it practical.</p><p>Welcome to The Analyst Mind.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.theanalystmind.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Analyst Mind - by Klaus! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>