openskills.info
Open Course

Threat Intelligence

Threat intelligence turns evidence about cyber threats into context that defenders can use to decide what to detect, investigate, block, or prioritize. It connects raw observations to an organization's systems, risks, and response.

itDefensive security and security operations

Don't Panic — Threat Intelligence

Threat intelligence is evidence about a cyber threat prepared well enough to support a defensive decision. The last five words do most of the work. A malicious IP address is data. Add its source, observation time, confidence, affected assets, related behavior, and a defensible action, and it may finally earn the grander title.

Without that context, reports and feeds accumulate like unlabeled cables in a server room: numerous, plausible, and increasingly difficult to trust. The discipline exists to turn those loose observations into something a detection engineer, incident responder, vulnerability manager, or risk owner can use. Its measure is not how much entered the system. Its measure is which decision changed, who owned the action, and what happened afterward.

The first load-bearing idea is decision first. Begin with a priority question tied to a consumer, scope, and deadline. Then collect evidence, assess it, add local context, choose a bounded action, and gather feedback. Starting with the largest available feed reverses that sequence and lets collection volume appoint itself manager of the work queue, a promotion it has not earned.

The second idea is local relevance. External intelligence can say that an actor used a technique, that infrastructure was observed, or that a technology was targeted. It cannot know whether the necessary telemetry exists, whether an affected asset is exposed, or whether a block would interrupt legitimate work. Confidence describes support for a claim. Impact describes what the claim means here. Combining them produces a tidy number and a muddy decision.

The third idea is behavior over labels. MITRE ATT&CK supplies a shared vocabulary for tactics and techniques, which helps turn reports into detection and hunting questions. It is a map of publicly reported behavior, not proof of attribution and not a certificate of local coverage. Indicators remain useful as pivots and short-lived controls, but they age; behavior often survives a change of infrastructure longer.

STIX and TAXII make exchange consistent. STIX describes cyber threat and observable information. TAXII moves it between systems. Neither decides whether the information is correct, relevant, permitted to share, or safe to enforce. Machine-readable is a transport property, not a character reference. The automation boundary still needs provenance, handling rules, expiry, rollback, and evidence that the control did what it was supposed to do.

There is another cost hiding in the feed catalogue. Every source becomes a maintenance contract for schema changes, duplicates, corrections, confidence scales, and expiry. New indicators can enter through one pipe; a revoked one may need removal from caches, lists, rules, tickets, and blocklists. An empty match count does not resolve the mystery either. It can mean no activity, irrelevant intelligence, missing telemetry, a bad field mapping, or a dead integration.

Read the Intro for the complete working model and limits. Use Slides when the pipeline and decision points need to fit in one view, then keep the Cheatsheet beside an intake or review session. The Practice Reference supplies the record format, and the Exercise makes you apply it to evidence that is useful, incomplete, and inconvenient in exactly the right proportions. Finish with Field Notes before connecting any feed to a control; those are the places where the attractive diagram begins sending invoices.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources