Skip to main content

Career Education

Summer Sale!

Get any course for £9.99

Threat intelligence is analysed knowledge about existing or emerging cyber threats that helps an organisation make better security decisions. It can explain who may attack, what they are trying to achieve, which systems they target, how they operate and what defenders should do in response.

The raw material may include suspicious internet addresses, malicious file hashes, phishing domains, vulnerability reports, malware behaviour, incident records and observations about threat actors. However, a collection of indicators is not automatically intelligence. It becomes threat intelligence when it is checked, interpreted, placed in context and connected to a decision.

For example, a list of malicious IP addresses is threat data. An assessment explaining that several addresses are part of infrastructure used in attacks against organisations in the same sector—and recommending specific monitoring and blocking actions—is threat intelligence.

It supports strategic planning, security operations, threat hunting, incident response and vulnerability management. This guide explains the intelligence lifecycle, threat feeds and platforms, and how security teams turn information into practical cyber defence.

Threat Data, Threat Information and Threat Intelligence

The terms data, information and intelligence are related, but they are not identical.

Threat data consists of individual observations. Examples include an IP address, domain name, file hash, email sender, malware filename, login time or vulnerability identifier. These items may be useful, but they have little meaning without context.

Threat information organises those observations and describes their relationship. It may show that a group of domains appeared in the same phishing campaign or that a particular malware family communicated with certain infrastructure.

Threat intelligence goes further. It analyses the information to answer questions that matter to a specific audience. It may assess whether the campaign is relevant to the organisation, what the attacker is likely to do next, which controls should be prioritised and how confident the analysts are in their judgement.

This distinction matters because security teams already receive enormous volumes of data. Their problem is rarely a complete lack of indicators. It is deciding which observations are reliable, relevant and urgent enough to justify action.

Why Threat Intelligence Matters

Cyber defenders cannot protect every system against every imaginable attack with equal intensity. Budgets, time and staff are limited, while the threat landscape changes continuously.

Threat intelligence helps an organisation prioritise. A financial institution may need to focus on credential theft, fraud and ransomware groups that target payment systems. A university may be more exposed to account compromise, intellectual-property theft and attacks against open research networks. A manufacturer may care particularly about operational disruption and vulnerable industrial technology.

Intelligence also provides warning before an incident reaches the organisation. If trusted sources report that attackers are exploiting a vulnerability in a product the business uses, the security team can patch, restrict or monitor that system before it is compromised.

During an incident, intelligence helps analysts interpret what they see. A domain found in network logs may be connected to a known malware campaign. A sequence of actions may match tactics associated with a particular intrusion set. This context can shorten investigation time and help responders search for related activity.

At a strategic level, it supports decisions about investment, suppliers and resilience by helping leaders match defences to realistic threats.

The Main Types of Threat Intelligence

Threat intelligence is commonly divided into strategic, operational, tactical and technical categories. The boundaries overlap, but the classification helps match the product to its audience.

Strategic Threat Intelligence

Strategic intelligence provides a high-level view of cyber risk. It is written mainly for boards, senior leaders, risk managers and policy teams.

It may examine changes in attacker motivation, geopolitical developments, sector-wide targeting, supply-chain exposure or the likely effect of new technology. The purpose is not to tell an analyst which IP address to block. It is to support decisions about priorities, investment and risk appetite.

A strategic assessment might explain why ransomware remains a significant sector risk and which resilience improvements deserve funding. It should distinguish facts from analytical judgements and explain confidence clearly.

Operational Threat Intelligence

Operational intelligence examines particular campaigns, incidents or threat actors. It seeks to explain what an adversary is doing, whom they are targeting and how an operation may develop.

It may include campaign timelines, infrastructure, malware, targeting and attacker intent. Incident responders and threat hunters use it to search for related activity, but it can become outdated quickly as attackers change tools and infrastructure.

Tactical Threat Intelligence

Tactical intelligence focuses on adversary behaviour, especially tactics, techniques and procedures, commonly abbreviated as TTPs.

A tactic describes an attacker’s objective, a technique describes how it is achieved, and procedures are the specific ways an actor applies it. This intelligence helps detection engineering and threat hunting because behaviour is often more durable than a single IP address or file hash.

Technical Threat Intelligence

Technical intelligence includes specific indicators associated with malicious activity. Examples include malicious domains, IP addresses, URLs, email addresses, file hashes and certificate details.

These indicators can support alerting, enrichment or blocking, but they may expire quickly. They are most useful when accompanied by a source, timestamp, campaign context, confidence level and intended use.

What Information Does Threat Intelligence Contain?

A threat intelligence product may contain several kinds of information, depending on its purpose.

Indicators of compromise are observations that may suggest malicious activity, such as a known malware hash or command-and-control domain. Indicators of attack focus more on behaviour that suggests an attack is developing, even before a confirmed compromise is found.

Intelligence may describe threat actors, their motivation, targeting and behaviour, although attribution should be expressed carefully. Campaign information connects related activity such as phishing themes, infrastructure, malware and techniques.

Vulnerability intelligence adds context to published weaknesses. Rather than treating every vulnerability with the same severity score as equally urgent, analysts examine whether exploitation is occurring, whether the vulnerable system is exposed and how valuable it would be to an attacker.

Useful intelligence also recommends actions such as detection queries, patching priorities or account reviews. Without a clear link to a decision, a report may be interesting but not operationally valuable.

Where Threat Intelligence Comes From

Threat intelligence draws on internal and external sources. The strongest programmes combine both.

Internal sources include security logs, endpoint alerts, email reports, incident records, vulnerability scans, help-desk tickets and observations from threat hunting. This information is directly relevant because it reflects the organisation’s own systems and users.

External sources include vendor reports, government advisories, security research, public databases and trusted communities. Commercial services may add curated feeds, infrastructure analysis and specialist support. Every source should still be assessed for relevance, accuracy and motive. Sharing groups can also reveal that an apparently isolated incident forms part of a wider campaign.

Suppliers and managed security providers may also contribute intelligence. Governance should define sharing rules and responsibility for action.

What Are Threat Intelligence Feeds?

Threat intelligence feeds are streams of threat-related data delivered regularly or in near real time. They may contain malicious domains, IP addresses, URLs, file hashes, vulnerability information or other indicators.

Feeds can be free, community-based, government-provided or commercial. Some focus on one area, such as phishing websites or malware infrastructure, while others combine many threat categories.

A feed may contain duplicate, stale or poorly explained indicators. Security teams should check how entries are collected and validated, whether timestamps and confidence are included, and whether the content is relevant to their sector and technology.

Feeds should be tested before automatic blocking because false positives can interrupt legitimate services. A feed used for alert enrichment may be suitable even when its indicators are not reliable enough to justify immediate blocking.

What Is a Threat Intelligence Platform?

A threat intelligence platform, often called a TIP, is a system used to collect, organise, enrich, analyse and distribute threat intelligence.

The platform may receive commercial feeds, open sources, internal investigations and partner reports. It normalises formats, removes duplicates, enriches indicators and connects related actors, campaigns and infrastructure.

It can then distribute selected intelligence to security information and event management systems, endpoint tools, email controls, firewalls and orchestration platforms so analysts receive useful context during investigations.

A TIP may also support analyst collaboration, confidence scoring, intelligence reports and searches across historical observations. It reduces the need to check numerous disconnected sources manually.

However, a platform does not create good intelligence by itself. Technology manages scale, but source quality, clear requirements and human judgement remain essential.

Threat Intelligence Platforms, SIEM and SOAR

Threat intelligence platforms are sometimes confused with other security operations tools.

A security information and event management system, or SIEM, collects and analyses organisational security logs, while threat intelligence enriches its alerts with external context.

Security orchestration, automation and response, or SOAR, connects security tools and automates workflows such as enrichment, case creation or endpoint isolation.

A TIP primarily manages intelligence content and relationships. A SIEM primarily analyses events generated within the organisation. SOAR coordinates actions between different systems.

Modern products may overlap, so the important issue is whether information moves efficiently from collection to analysis and defensive action.

The Threat Intelligence Lifecycle

Threat intelligence is normally managed as a cycle. The exact number and names of the stages vary, but a practical lifecycle includes direction, collection, processing, analysis, dissemination and feedback.

1. Direction and Requirements

The process begins by identifying what decision the intelligence must support.

A vague requirement such as “tell us about cyber threats” is too broad. A useful one might ask whether a new vulnerability is being exploited or which actors target the organisation’s sector.

Requirements should reflect critical assets, audience, deadline and required confidence so analysts do not collect information without purpose.

For example, a vulnerability team may require an assessment within hours, while a strategic board report may examine trends over several months. Defining the audience early affects the language, technical depth and delivery method.

2. Collection

The team gathers information relevant to the requirement. Sources may include internal telemetry, incident reports, public research, commercial feeds, trusted partners and security communities.

Collection should be planned because every source has cost, coverage and reliability limitations. Collecting everything can overwhelm analysts without improving decisions.

Legal, privacy and contractual restrictions may also limit how information can be used or shared.

3. Processing

Processing prepares raw information through formatting, deduplication, translation, timestamp correction and indicator extraction.

It also helps reconcile different names and confidence levels. Several suppliers may use different names for the same malware or actor, while the same indicator may appear repeatedly across separate feeds.

Automation handles repetitive work efficiently, but important enrichment still requires validation. A database lookup or automated score can be wrong, outdated or missing relevant context.

4. Analysis and Production

Analysts interpret the processed information and produce judgements.

They identify patterns, test alternative explanations and assess organisational relevance. The output may be an alert, technical report, detection package or strategic assessment.

Good analysis explains what happened, why it matters, what may happen next and what action should be considered, while acknowledging uncertainty.

A strong product separates observed facts from assessment. It should not present an assumed attacker identity or predicted outcome as certain when the available evidence supports only a cautious judgement.

5. Dissemination

The intelligence is delivered to the people or systems that can use it.

A board may receive a concise risk assessment, analysts may receive TTPs and detection guidance, and vulnerability teams may receive prioritised weaknesses.

Timing matters. A concise warning delivered in time is often more valuable than a perfect report delivered too late. Sensitive information must also follow appropriate handling and sharing rules.

6. Feedback

The audience explains whether the intelligence was useful, accurate and delivered in the right form.

Feedback reveals whether a product was too technical, general or late and may create new requirements. Without it, analysts may continue producing reports that do not change decisions.

How Threat Analysts Assess Information

Threat analysis requires structured judgement. Analysts should consider the source’s reliability, the information’s credibility and whether independent evidence supports it.

A trusted source can still be wrong, while a new source may provide accurate information requiring verification. Analysts also assess timeliness and relevance.

An old indicator may help a historical investigation but no longer justify blocking. Similarly, an accurate report about attacks against technology the organisation does not use may not require urgent action.

Confidence statements help audiences understand uncertainty. High confidence does not mean absolute certainty; it means the judgement is strongly supported by the available evidence. Lower confidence indicates important gaps or credible alternative explanations.

Analysts should also guard against confirmation bias through peer review and documented assumptions. Once a team suspects a particular actor, it can become too easy to interpret every new observation as supporting that theory.

How MITRE ATT&CK Supports Threat Intelligence

MITRE ATT&CK is a knowledge base that organises observed adversary behaviour into tactics and techniques. It provides a common language for discussing how attackers operate.

Analysts can map reports and incidents to ATT&CK techniques, compare activity described under different names and review detection coverage.

If intelligence indicates that relevant attackers frequently use a particular technique, defenders can check whether their logs, endpoint tools and analytics would reveal it.

Threat hunters can then search for durable behaviour across endpoints and networks instead of relying only on temporary domains or hashes.

ATT&CK is a framework for organising observations, not proof of attribution. Many actors use the same techniques, so a technique match should not be treated as evidence that one specific group is responsible.

STIX and TAXII in Threat Intelligence Sharing

Threat intelligence needs consistent formats if organisations and security products are to exchange it efficiently.

Structured Threat Information Expression, or STIX, is a standard language and format for representing cyber threat and observable information. It can describe indicators, threat actors, campaigns, attack patterns, malware and relationships between them.

Trusted Automated Exchange of Intelligence Information, or TAXII, is a protocol for communicating cyber threat information between systems.

In simple terms, STIX structures the intelligence and TAXII helps move it. They support machine-readable sharing, but correct formatting does not guarantee that an indicator is current, relevant or accurate.

Standards reduce manual conversion and make integration easier. Governance, confidence scoring and analyst validation are still required.

How Security Operations Use Threat Intelligence

Security operations centres use threat intelligence to enrich alerts, build detection rules, guide threat hunting and understand incident scope.

When an endpoint contacts an unfamiliar domain, intelligence can show whether the address has been associated with phishing, malware or another campaign. This allows the analyst to prioritise the alert and search for connected activity.

Detection engineers can translate knowledge of attacker behaviour into analytics covering suspicious processes, account activity and network patterns.

If a detected tool is linked with credential theft, incident responders can prioritise password resets, session revocation and identity monitoring even before fraud or lateral movement becomes visible.

Vulnerability teams can use evidence of active exploitation and attacker interest to decide which weaknesses require immediate remediation rather than relying only on numerical severity.

Threat Intelligence vs Threat Hunting

Threat intelligence and threat hunting support one another, but they are not the same activity.

Threat intelligence collects and analyses knowledge about adversaries, campaigns, vulnerabilities and indicators. Threat hunting is the proactive search for signs of malicious activity that existing alerts may have missed.

Intelligence can provide the starting hypothesis for a hunt. For example, analysts may learn that attackers targeting their sector commonly abuse a particular remote-access method. Hunters can then search internal endpoint, identity and network data for evidence of that behaviour.

The hunt may produce new intelligence in return. Analysts could discover a previously unknown domain, a variation in the technique or a different targeting pattern. That information can be validated, added to the intelligence repository and shared with appropriate partners.

Threat hunting should not become a search for every indicator mentioned in every report. It needs a clear hypothesis, suitable telemetry and a connection to the organisation’s risk. Otherwise, the team may spend large amounts of time searching for activity that is technically interesting but unlikely to affect the business.

Indicators vs Attacker Behaviour

Indicators such as domains, IP addresses and file hashes are easy for security tools to match, but they often have a short useful life. Attackers can move to a new server, register another domain or change a file enough to create a different hash.

Behavioural intelligence is usually harder for an adversary to replace. A group may continue using similar methods for credential access, persistence or lateral movement because changing its entire operating model requires more effort.

This does not mean technical indicators are unimportant. They can provide fast confirmation during an active campaign and support immediate containment. The strongest approach combines them with TTPs, internal telemetry and contextual analysis.

For example, blocking one malicious domain may stop a known connection. A detection that also identifies the underlying process and account behaviour can reveal related activity even after the attacker changes infrastructure.

This balance helps security teams avoid two extremes: relying on short-lived blocklists or producing broad behavioural reports that cannot be translated into practical monitoring.

A Practical Threat Intelligence Example

Consider a company that receives a report about a phishing campaign targeting its sector.

The report includes sender addresses, domains and attachment hashes. Analysts validate the indicators and compare the phishing theme with internal reports. They discover a related invoice lure and an endpoint connection to one of the domains.

The team prepares detection queries, removes matching messages from other inboxes, blocks confirmed malicious destinations and reviews the affected account.

Management receives a short assessment of the campaign and actions taken. External data has become organisation-specific intelligence rather than an unfiltered domain list.

The company can then feed the investigation results back into its intelligence process. New internal observations may help identify further messages, infrastructure or defensive improvements.

Common Problems with Threat Intelligence

One common problem is indicator overload. Security teams subscribe to many feeds and receive millions of entries without enough context to judge them. The result is noisy alerts rather than better security.

Stale indicators may later belong to legitimate services, while poorly expressed confidence can make uncertain attribution sound definitive.

Programmes also fail when no team owns the recommended action or when vendor visibility is mistaken for the whole threat landscape.

Threat intelligence sources do not all observe the same networks, regions or victims. One provider’s report may be accurate within its visibility but incomplete as a description of the wider threat.

Volume is not value. The key question is whether intelligence improved a decision, detection or response.

Building a Threat Intelligence Programme

A useful programme begins with requirements rather than technology.

Identify the organisation’s critical services, data, suppliers and likely adversaries. Speak with security operations, vulnerability management, incident response, risk teams and senior leaders to understand their decisions.

Choose a small number of relevant sources before buying many feeds or a large platform. Define a repeatable lifecycle and assign owners for resulting actions.

Start with practical use cases such as alert enrichment, monitoring internet-facing systems or vulnerability prioritisation.

Record confidence, timestamps and sharing restrictions. Review expired indicators and remove controls that no longer have a valid basis.

As the programme matures, add automation where it saves analyst time without hiding necessary judgement.

Threat Intelligence for Small Organisations

A small organisation may not need a dedicated platform or full-time analyst.

It can follow trusted government advisories, supplier alerts and sector communities, concentrating on products and risks it actually faces.

A named person or provider should review warnings and decide whether action is required. Intelligence has little value when reports arrive in a shared mailbox that nobody checks.

Small organisations can also learn from their own incidents. Repeated phishing themes, suspicious login locations and frequently targeted accounts provide internal intelligence that can improve controls and awareness training.

Measuring the Value of Threat Intelligence

Threat intelligence should be measured by outcomes rather than collection volume.

Useful measures may include how often intelligence led to a new detection, improved an investigation or accelerated remediation. Teams can track whether important warnings reached the correct audience in time and whether indicators produced excessive false positives.

Other measures include time saved during alert enrichment or incident scoping and whether expired indicators are removed promptly.

Quantitative measures should be supported by examples showing how intelligence changed a real decision. Fewer relevant assessments may be more valuable than hundreds of unread reports.

Privacy, Legal and Sharing Considerations

Threat intelligence may contain sensitive information, including account details, internal system names, incident records and observations about individuals or organisations.

Collection and sharing must follow applicable law, contracts and organisational policy. Teams should minimise personal data, control access and respect sharing conditions.

Attribution requires particular care because unsupported public claims can create legal and reputational harm.

The aim is to improve cyber defence without unnecessarily exposing victims, investigations or confidential business details.

The Role of Automation and AI

Automation can collect feeds, remove duplicates, enrich indicators and distribute selected intelligence to security tools.

Artificial intelligence may assist with report summaries, relationship analysis and prioritisation of large datasets. This can reduce repetitive work and allow analysts to spend more time interpreting threats.

However, automation can also repeat errors at scale. A wrong indicator sent directly to blocking controls may interrupt legitimate services, while generated analysis may hide uncertainty or create unsupported conclusions.

Human review remains essential for attribution, strategic judgements and other high-impact decisions. Automation should improve the speed and consistency of the intelligence lifecycle without removing accountability.

Frequently Asked Questions

What is threat intelligence?

Threat intelligence is analysed and contextualised knowledge about cyber threats that supports security decisions. It explains what the threat means, why it is relevant and what action may be appropriate.

What are threat intelligence feeds?

Threat intelligence feeds are regularly delivered streams of indicators or threat data, such as malicious domains, IP addresses, file hashes and vulnerability information.

What is a threat intelligence platform?

A threat intelligence platform collects, organises, enriches and distributes intelligence from multiple sources. It can integrate with security operations and defensive tools.

What is the difference between threat data and threat intelligence?

Threat data is a raw observation. Threat intelligence adds analysis, context, relevance and a connection to a decision or action.

What are indicators of compromise?

Indicators of compromise are observations that may show malicious activity, such as a known malware hash, phishing domain or unauthorised system change.

What are TTPs?

TTPs are tactics, techniques and procedures. They describe attackers’ objectives, methods and specific ways of carrying out activity.

How does threat intelligence help a SOC?

It enriches alerts, supports threat hunting, informs detection rules, improves incident response and helps analysts prioritise suspicious activity.

Is threat intelligence only for large organisations?

No. Small organisations can use government alerts, sector communities, supplier reports and their own incident data without operating a dedicated platform.

Can threat intelligence stop cyber attacks automatically?

Selected indicators can support automated blocking, but intelligence should be validated and matched to risk. False or stale information can disrupt legitimate services.

What makes threat intelligence actionable?

It is timely, reliable, relevant to the organisation and clear about what decision or defensive action it supports.

Conclusion

Threat intelligence turns raw cyber threat data into knowledge that helps people and security systems make better decisions.

It may describe malicious infrastructure, vulnerabilities, threat actors, campaigns or attacker TTPs. Its value comes from analysis and context, not merely from collecting large lists of indicators.

Strategic intelligence supports leadership and investment decisions. Operational and tactical intelligence help analysts understand campaigns and adversary behaviour, while technical intelligence supports rapid detection and blocking.

Threat intelligence feeds provide useful data, and threat intelligence platforms help organise, enrich and distribute it. Frameworks and standards such as MITRE ATT&CK, STIX and TAXII make analysis and sharing more consistent.

The intelligence lifecycle begins with a clear requirement and continues through collection, processing, analysis, dissemination and feedback. Each stage should serve a defined audience and decision.

Strong threat intelligence does not attempt to predict every attack with certainty. It reduces uncertainty enough for defenders to prioritise, detect and respond more effectively.

When connected to security operations, vulnerability management, incident response and business risk, threat intelligence becomes a practical part of cyber defence rather than another stream of information.

Leave a Reply

Your email address will not be published. Required fields are marked *