Threat Intelligence
Threat intelligence turns evidence about cyber threats into context that defenders can use to decide what to detect, investigate, block, or prioritize. It connects raw observations to an organization's systems, risks, and response.
itDefensive security and security operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Intro
Threat Intelligence
Threat intelligence is evidence-based knowledge about a threat, interpreted so a defender can make a decision. A malicious IP address by itself is an indicator. It becomes intelligence when you know its source, confidence, time window, affected assets, related behavior, and the action it justifies.
The job is not to collect the largest feed. The job is to reduce uncertainty for a specific defensive decision. That decision may be a detection hypothesis, an investigation lead, a block with an expiry, a patch priority, or a leadership risk decision.
The working model
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://www.nist.gov/publications/guide-cyber-threat-information-sharing
Supports
- Cyber threat information as information that helps identify, assess, monitor, and respond to threats
- Indicators, TTPs, defensive actions, incident analysis, sharing goals, sources, scope, rules, communities, and effective use
- https://csrc.nist.gov/topics/security-and-privacy/risk-management/threats/information-sharing
Supports
- Indicators, TTPs, alerts, threat intelligence reports, and tool configurations as cyber threat information
- https://attack.mitre.org/groups/index.html
Supports
- ATT&CK groups as activity clusters tracked under common names
- Group mappings to publicly reported techniques, software, campaigns, and original references
- The limits of group mappings as a subset of behavior available through open-source reporting
- https://docs.oasis-open.org/cti/stix/v2.1/stix-v2.1.html
Supports
- STIX as a language and serialization format for cyber threat and observable information
- STIX for consistent machine-readable exchange and a Bundle as a container for STIX objects
- https://docs.oasis-open.org/cti/taxii/v2.1/os/taxii-v2.1-os.html
Supports
- TAXII as an application-layer protocol and REST API for cyber threat information exchange
- Collections as producer-hosted CTI requested by consumers
- https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/automated-indicator-sharing-ais/how-share-cyber-threat-information-through-ais
Supports
- AIS use of STIX and TAXII to exchange indicators and defensive measures
- AIS source anonymity by default during transmission and submission guidance
- https://github.com/hslatman/awesome-threat-intelligence
Supports
- Discovery of MISP, OpenCTI, Sigma, and YARA as threat-intelligence ecosystem resources
