Skip to content
Paul Marinos
Menu

Threat Intelligence

Turning raw signal into decisions people act on.

Most threat intelligence fails at the last mile. The collection is fine, the analysis is defensible, and then it lands in a PDF that nobody reads and nothing changes. This pillar is about the last mile: making a finding legible, quantifying how sure you are, and handing it to someone in a form they can act on — plus the analytic step in the middle that decides whether the finding was ever worth carrying.

The working definition here is narrow on purpose. Threat intelligence is the analysis and communication of adversary knowledge. Operationalizing that knowledge into running detections is a different discipline — that lives in Detection Engineering & SecOps.

An organization’s defensive capacity is bounded by what it decides to do, not by what it knows. The bottleneck is almost never the feed. It’s that the analysis arrived without a confidence statement, without a base rate, or without a “so what” — so the reader substituted their own priors and moved on.

  • → Penetration Testing & Red Teaming: adversary emulation validates the techniques intel says matter. Pentest findings become intel inputs.
  • → Detection Engineering: intel supplies the detection backlog; detection supplies the telemetry that becomes intel.
  • → GRC: risk prioritization (§1.4) is the same math a risk register needs, done honestly.
  • → AppSec: exploit-in-the-wild signal is what should be driving the vulnerability queue, not CVSS alone.
  • → AI & Automation: summarization and enrichment pipelines are where this pillar scales — and where hallucinated intel does real damage.
  • → IAM: identity is the most common initial-access path in the reporting, which makes it the most common thing intel should be arguing about.
  • → Cloud & Infrastructure Security: posture tooling produces findings by the thousand. §1.4 prioritization is the difference between a queue and a wall.
  • → Incident Response & Digital Forensics: investigation output is intelligence. Malware analysis yields indicators and behaviors, and confidence language matters most when it is written under time pressure.
  • → Data Security & Privacy Engineering: exfiltration is the objective in most reporting, which makes data flow the thing worth prioritizing around.
Subsection Focus
Report Writing Tactical/operational/strategic formats, BLUF, ICD 203 confidence language, Admiralty source grading, templates
Statistics & Data Analytics Base rates, time-series for detection trends, cohort and survival analysis for remediation, sampling bias
Data Visualization Chart selection by question type, visualizing uncertainty, SOC vs. executive dashboards, anti-patterns
Risk Prioritization The four-input model, FAIR and loss exceedance, and a page each on CVSS, EPSS & KEV and SSVC
Effective Communication Writing for engineer/director/board, translating findings to business impact, briefing formats
Collection & Sourcing OSINT tradecraft, feed evaluation, internal telemetry as a source, STIX/TAXII and MISP
Analytic Methods & Attribution Diamond Model and kill chain, ACH and key assumptions, activity clustering, the levels of attribution, actor naming
The Intelligence Lifecycle The six-phase loop and where it breaks in practice, with a page each on F3EAD, Processing & Enrichment and Feedback & Product Health
Intelligence Requirements PIRs as answerable questions, EEI decomposition, the RFI workflow, collection planning as gap analysis, tagging and review
Sharing & Community TLP 2.0 as written, the ISAC/CERT/trust-group ecosystem, tearlines and sanitization, what contributing back buys
Running a CTI Program Consumers as the charter, the three tiers as product lines, team shapes, CTI-CMM and build order, procurement, metrics
Threat Actor Profiling & Tracking Which actors matter to you, the profile as a living product, tracking TTP change over time, and the emulation and detection consumers the library feeds

Graph View

Spotted an error on this page? Report it.