Skip to content
Paul Marinos
Menu

Threat Intelligence

Turning raw signal into decisions people act on.

Most threat intelligence fails at the last mile. The collection is fine, the analysis is defensible, and then it lands in a PDF that nobody reads and nothing changes. This pillar is about the last mile: making a finding legible, quantifying how sure you are, and handing it to someone in a form they can act on.

The working definition here is narrow on purpose. Threat intelligence is the analysis and communication of adversary knowledge. Operationalizing that knowledge into running detections is a different discipline — that lives in Detection Engineering & SecOps.

An organization’s defensive capacity is bounded by what it decides to do, not by what it knows. The bottleneck is almost never the feed. It’s that the analysis arrived without a confidence statement, without a base rate, or without a “so what” — so the reader substituted their own priors and moved on.

  • Penetration Testing & Red Teaming: adversary emulation validates the techniques intel says matter. Pentest findings become intel inputs.
  • Detection Engineering: intel supplies the detection backlog; detection supplies the telemetry that becomes intel.
  • GRC: risk prioritization (§1.4) is the same math a risk register needs, done honestly.
  • AppSec: exploit-in-the-wild signal is what should be driving the vulnerability queue, not CVSS alone.
  • AI & Automation: summarization and enrichment pipelines are where this pillar scales — and where hallucinated intel does real damage.
  • IAM: identity is the most common initial-access path in the reporting, which makes it the most common thing intel should be arguing about.
  • Cloud & Infrastructure Security: posture tooling produces findings by the thousand. §1.4 prioritization is the difference between a queue and a wall.
  • Incident Response & Digital Forensics: investigation output is intelligence. Malware analysis yields indicators and behaviours, and confidence language matters most when it is written under time pressure.
  • Data Security & Privacy Engineering: exfiltration is the objective in most reporting, which makes data flow the thing worth prioritizing around.
Subsection Focus
Report Writing Tactical/operational/strategic formats, BLUF, ICD 203 confidence language, Admiralty source grading, templates
Statistics & Data Analytics Base rates, time-series for detection trends, cohort and survival analysis for remediation, sampling bias
Data Visualization Chart selection by question type, visualizing uncertainty, SOC vs. executive dashboards, anti-patterns
Risk Prioritization CVSS vs. EPSS vs. SSVC, KEV, asset criticality weighting, FAIR and loss exceedance
Effective Communication Writing for engineer/director/board, translating findings to business impact, briefing formats
Collection & Sourcing OSINT tradecraft, feed evaluation, internal telemetry as a source, STIX/TAXII and MISP

Graph View