Permissible Actions Protocol (PAP)

The Permissible Actions Protocol (PAP) is a set of labels that state what actions a recipient may take on information they receive. Where TLP controls who may see something, PAP controls what you may do with it. Improbus applies PAP alongside TLP on shared intelligence.

PAP pairs with TLP. TLP says who may receive information; PAP says what actions are permitted on it — for example, whether you may act on an indicator in a way an adversary could notice. Neither is an urgency level; for incident urgency see the DFIR Emergency page.

The four action levels

  • PAP:RED
    No visible action. For awareness only. Recipients must not act on the information in any way an adversary could detect.
  • PAP:AMBER
    Passive, internal checks. Recipients may search their own logs and environment for the information, but take no action observable from outside.
  • PAP:GREEN
    Active defence within your constituency. Recipients may block, detect, and hunt, provided it stays inside their organisation and is not publicly attributable.
  • PAP:CLEAR
    No restriction on action. Recipients may act on the information without limitation.

How Improbus applies it

We tag indicators and advisories with a PAP level alongside their TLP label, so it is always clear both who may see an item and what may be done with it. We honour the strictest PAP level on anything you send us, and default to PAP:AMBER when none is marked. PAP travels as a MISP taxonomy tag on machine-readable intelligence.

Summarised in our own words for context. PAP is maintained as a MISP taxonomy and is used widely across the threat-intelligence community; it complements the FIRST TLP standard.
π