Threat Intelligence
Turning raw signal into decisions people act on.
Most threat intelligence fails at the last mile. The collection is fine, the analysis is defensible, and then it lands in a PDF that nobody reads and nothing changes. This pillar is about the last mile: making a finding legible, quantifying how sure you are, and handing it to someone in a form they can act on — plus the analytic step in the middle that decides whether the finding was ever worth carrying.
The working definition here is narrow on purpose. Threat intelligence is the analysis and communication of adversary knowledge. Operationalizing that knowledge into running detections is a different discipline — that lives in Detection Engineering & SecOps.
Why it matters
Section titled “Why it matters”An organization’s defensive capacity is bounded by what it decides to do, not by what it knows. The bottleneck is almost never the feed. It’s that the analysis arrived without a confidence statement, without a base rate, or without a “so what” — so the reader substituted their own priors and moved on.
How this connects
Section titled “How this connects”- → Penetration Testing & Red Teaming: adversary emulation validates the techniques intel says matter. Pentest findings become intel inputs.
- → Detection Engineering: intel supplies the detection backlog; detection supplies the telemetry that becomes intel.
- → GRC: risk prioritization (§1.4) is the same math a risk register needs, done honestly.
- → AppSec: exploit-in-the-wild signal is what should be driving the vulnerability queue, not CVSS alone.
- → AI & Automation: summarization and enrichment pipelines are where this pillar scales — and where hallucinated intel does real damage.
- → IAM: identity is the most common initial-access path in the reporting, which makes it the most common thing intel should be arguing about.
- → Cloud & Infrastructure Security: posture tooling produces findings by the thousand. §1.4 prioritization is the difference between a queue and a wall.
- → Incident Response & Digital Forensics: investigation output is intelligence. Malware analysis yields indicators and behaviors, and confidence language matters most when it is written under time pressure.
- → Data Security & Privacy Engineering: exfiltration is the objective in most reporting, which makes data flow the thing worth prioritizing around.
What’s here
Section titled “What’s here”| Subsection | Focus |
|---|---|
| Report Writing | Tactical/operational/strategic formats, BLUF, ICD 203 confidence language, Admiralty source grading, templates |
| Statistics & Data Analytics | Base rates, time-series for detection trends, cohort and survival analysis for remediation, sampling bias |
| Data Visualization | Chart selection by question type, visualizing uncertainty, SOC vs. executive dashboards, anti-patterns |
| Risk Prioritization | The four-input model, FAIR and loss exceedance, and a page each on CVSS, EPSS & KEV and SSVC |
| Effective Communication | Writing for engineer/director/board, translating findings to business impact, briefing formats |
| Collection & Sourcing | OSINT tradecraft, feed evaluation, internal telemetry as a source, STIX/TAXII and MISP |
| Analytic Methods & Attribution | Diamond Model and kill chain, ACH and key assumptions, activity clustering, the levels of attribution, actor naming |
| The Intelligence Lifecycle | The six-phase loop and where it breaks in practice, with a page each on F3EAD, Processing & Enrichment and Feedback & Product Health |
| Intelligence Requirements | PIRs as answerable questions, EEI decomposition, the RFI workflow, collection planning as gap analysis, tagging and review |
| Sharing & Community | TLP 2.0 as written, the ISAC/CERT/trust-group ecosystem, tearlines and sanitization, what contributing back buys |
| Running a CTI Program | Consumers as the charter, the three tiers as product lines, team shapes, CTI-CMM and build order, procurement, metrics |
| Threat Actor Profiling & Tracking | Which actors matter to you, the profile as a living product, tracking TTP change over time, and the emulation and detection consumers the library feeds |
Graph View
Spotted an error on this page? Report it.