Threat Intelligence
Threat intelligence turns evidence about cyber threats into context that defenders can use to decide what to detect, investigate, block, or prioritize. It connects raw observations to an organization's systems, risks, and response.
itDefensive security and security operations | OpenSkills.info
Intro
Threat Intelligence
Threat intelligence is evidence-based knowledge about a threat, interpreted so a defender can make a decision. A malicious IP address by itself is an indicator. It becomes intelligence when you know its source, confidence, time window, affected assets, related behavior, and the action it justifies.
The job is not to collect the largest feed. The job is to reduce uncertainty for a specific defensive decision. That decision may be a detection hypothesis, an investigation lead, a block with an expiry, a patch priority, or a leadership risk decision.
The working model
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
