Machine speed sharing of threat intelligence and IOCs is helpful for defense but the context for that intelligence is often lost, making it near impossible to translate the information to actions. By having a standardized definition of confidence as to whether or not an IOC is actively malicious that can be reviewed by the community, we can gain insight into response and improve our overall ability to take action.