The BLUF principle — lead any intelligence product with its single most important judgment or implication, before background or detail. This is the structural core of analytic writing in the style manual.
Recommended product structure
| Section | Purpose |
|---|---|
| Title | Precise, informative (actor/campaign/date) |
| Classification / TLP | Handling, top of every page |
| BLUF / Key Judgements | 1–3 sentences: what happened, why it matters, recommended action |
| Key Findings | Supporting judgements, each with confidence |
| Analysis / Substantiation | Logical flow; separate facts from judgements |
| Implications & Outlook | "So what" + forward look, estimative language |
| Recommendations / Detection | Actionable next steps, IOCs, TTPs, defences |
| Appendices | Technical detail — IOCs, YARA/Sigma, MITRE ATT&CK, sources |
Core rules
- Length: if the answer fits in two pages, don't write five. Executives read BLUF + Key Findings; operators read the appendices.
- Confidence: every major judgment carries explicit confidence.
- Facts vs judgement: clearly separate reported information from analyst assessment (e.g. "reported that…" vs "we assess…").
- Attribution: calibrate language ("consistent with…", "we assess with [confidence] that…"); never "definitely the work of X".
The manual also encodes broader analytic standards (ICD 203-derived): be objective, describe source quality, express uncertainties, incorporate analysis of alternatives for attribution/intent.
Related
- Estimative Language — the confidence vocabulary used in BLUF
- Structured Analytic Techniques — produce well-tested judgments before writing
- Admiralty Rating — source-level grading feeds the confidence in key findings
Note: This is your own draft style manual (v0.1). The wiki indexes it rather than replacing it — keep the source of truth in
Intel/Intel Writing Style Guide/.