Threat Intelligence
Threat intelligence turns evidence about cyber threats into context that defenders can use to decide what to detect, investigate, block, or prioritize. It connects raw observations to an organization's systems, risks, and response.
itDefensive security and security operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — Threat Intelligence
Threat intelligence is evidence about a cyber threat prepared well enough to support a defensive decision. The last five words do most of the work. A malicious IP address is data. Add its source, observation time, confidence, affected assets, related behavior, and a defensible action, and it may finally earn the grander title.
Without that context, reports and feeds accumulate like unlabeled cables in a server room: numerous, plausible, and increasingly difficult to trust. The discipline exists to turn those loose observations into something a detection engineer, incident responder, vulnerability manager, or risk owner can use. Its measure is not how much entered the system. Its measure is which decision changed, who owned the action, and what happened afterward.
The first load-bearing idea is decision first. Begin with a priority question tied to a consumer, scope, and deadline. Then collect evidence, assess it, add local context, choose a bounded action, and gather feedback. Starting with the largest available feed reverses that sequence and lets collection volume appoint itself manager of the work queue, a promotion it has not earned.
The second idea is local relevance. External intelligence can say that an actor used a technique, that infrastructure was observed, or that a technology was targeted. It cannot know whether the necessary telemetry exists, whether an affected asset is exposed, or whether a block would interrupt legitimate work. Confidence describes support for a claim. Impact describes what the claim means here. Combining them produces a tidy number and a muddy decision.
The third idea is behavior over labels. MITRE ATT&CK supplies a shared vocabulary for tactics and techniques, which helps turn reports into detection and hunting questions. It is a map of publicly reported behavior, not proof of attribution and not a certificate of local coverage. Indicators remain useful as pivots and short-lived controls, but they age; behavior often survives a change of infrastructure longer.
STIX and TAXII make exchange consistent. STIX describes cyber threat and observable information. TAXII moves it between systems. Neither decides whether the information is correct, relevant, permitted to share, or safe to enforce. Machine-readable is a transport property, not a character reference. The automation boundary still needs provenance, handling rules, expiry, rollback, and evidence that the control did what it was supposed to do.
There is another cost hiding in the feed catalogue. Every source becomes a maintenance contract for schema changes, duplicates, corrections, confidence scales, and expiry. New indicators can enter through one pipe; a revoked one may need removal from caches, lists, rules, tickets, and blocklists. An empty match count does not resolve the mystery either. It can mean no activity, irrelevant intelligence, missing telemetry, a bad field mapping, or a dead integration.
Read the Intro for the complete working model and limits. Use Slides when the pipeline and decision points need to fit in one view, then keep the Cheatsheet beside an intake or review session. The Practice Reference supplies the record format, and the Exercise makes you apply it to evidence that is useful, incomplete, and inconvenient in exactly the right proportions. Finish with Field Notes before connecting any feed to a control; those are the places where the attractive diagram begins sending invoices.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://www.nist.gov/publications/guide-cyber-threat-information-sharing
Supports
- Cyber threat information as information that helps identify, assess, monitor, and respond to threats
- Indicators, TTPs, defensive actions, incident analysis, sharing goals, sources, scope, rules, communities, and effective use
- https://csrc.nist.gov/topics/security-and-privacy/risk-management/threats/information-sharing
Supports
- Indicators, TTPs, alerts, threat intelligence reports, and tool configurations as cyber threat information
- https://attack.mitre.org/groups/index.html
Supports
- ATT&CK groups as activity clusters tracked under common names
- Group mappings to publicly reported techniques, software, campaigns, and original references
- The limits of group mappings as a subset of behavior available through open-source reporting
- https://docs.oasis-open.org/cti/stix/v2.1/stix-v2.1.html
Supports
- STIX as a language and serialization format for cyber threat and observable information
- STIX for consistent machine-readable exchange and a Bundle as a container for STIX objects
- https://docs.oasis-open.org/cti/taxii/v2.1/os/taxii-v2.1-os.html
Supports
- TAXII as an application-layer protocol and REST API for cyber threat information exchange
- Collections as producer-hosted CTI requested by consumers
- https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/automated-indicator-sharing-ais/how-share-cyber-threat-information-through-ais
Supports
- AIS use of STIX and TAXII to exchange indicators and defensive measures
- AIS source anonymity by default during transmission and submission guidance
- https://github.com/hslatman/awesome-threat-intelligence
Supports
- Discovery of MISP, OpenCTI, Sigma, and YARA as threat-intelligence ecosystem resources
- https://attack.mitre.org/techniques/T1190/
Supports
- Exploit Public-Facing Application as an ATT&CK initial-access technique used by the synthetic exercise
- https://www.first.org/newsroom/releases/20220805
Supports
- TLP established by NISCC in 1999
- FIRST release of TLP 2.0 on 2022-08-05 after industry consultation
- https://www.lockheedmartin.com/content/dam/lockheed-martin/rms/documents/cyber/LM-White-Paper-Intel-Driven-Defense.pdf
Supports
- Publication of the 2011 Cyber Kill Chain paper
- Linking intrusion phases, indicators, defensive courses of action, campaigns, and intelligence feedback
- https://www.misp-project.org/who/
Supports
- CyDefSIG project start around May 2011
- Initial goal of replacing IOC sharing through email and PDF with machine-processable data
- https://www.mitre.org/news-insights/publication/standardizing-cyber-threat-intelligence-information-structured-threat
Supports
- MITRE publication describing the STIX language effort in January 2012
- https://taxii.mitre.org/about/documents/Introduction_to_TAXII_White_Paper_November_2012.pdf
Supports
- November 2012 TAXII white paper and exchange model
- https://stix.mitre.org/language/version1.0/
Supports
- STIX 1.0 official release on 2013-04-08
- Released components for structured cyber threat information
- https://apps.dtic.mil/dtic/tr/fulltext/u2/a586960.pdf
Supports
- July 2013 publication of the Diamond Model of Intrusion Analysis
- Adversary, capability, infrastructure, and victim as the model's core event features
- https://attack.mitre.org/docs/ATTACK_Design_and_Philosophy_March_2020.pdf
Supports
- First ATT&CK model created in September 2013
- Public release in May 2015 with 96 techniques
- https://www.oasis-open.org/2015/05/20/call-for-participation-oasis-cyber-threat-intelligence-cti-technical-committee/
Supports
- Formation and June 2015 first meeting of the OASIS CTI Technical Committee
- Committee scope to standardize and continue STIX, TAXII, and CybOX
- https://www.first.org/conference/2020/releases
Supports
- FIRST announcement of consolidated TLP 1.0 on 2016-08-31
- https://www.oasis-open.org/2017/10/27/stix-v2-0-and-taxii-v2-0-are-now-oasis-committee-specifications/
Supports
- Publication of STIX 2.0 and TAXII 2.0 as OASIS Committee Specifications on 2017-10-27
- https://www.oasis-open.org/2021/06/23/stix-v2-1-and-taxii-v2-1-oasis-standards-are-published/
Supports
- Approval of STIX 2.1 and TAXII 2.1 as OASIS Standards on 2021-06-10
- https://www.misp-project.org/features/
Supports
- MISP sharing, storage, correlation, sightings, reporting, distribution, and STIX interoperability
- MISP open-source licensing and deployment options
- https://filigran.io/platform/opencti/
Supports
- OpenCTI STIX-based knowledge graph, connectors, streams, and SecOps integration
- Community, enterprise, and hosted editions
- https://github.com/OpenCTI-Platform/opencti/blob/master/LICENSE
Supports
- Apache-licensed Community Edition and separately licensed Enterprise Edition
- https://knowledge.threatconnect.com/docs/threatconnect-platform
Supports
- ThreatConnect support for threat intelligence operations, security operations, cyber risk, and orchestration
- https://www.anomali.com/products/threatstream
Supports
- ThreatStream collection, normalization, deduplication, scoring, enrichment, and operationalization workflow
- https://helpcenter.threatq.com/ThreatQ_Platform/ThreatQ_Platform.htm
Supports
- ThreatQ centralized intelligence library, adaptive workbench, scoring, enrichment, prioritization, and exchange
- https://www.recordedfuture.com/platform
Supports
- Recorded Future actor, infrastructure, vulnerability, risk, and integration capabilities
- https://cloud.google.com/security/products/threat-intelligence
Supports
- Google Threat Intelligence use of Mandiant, VirusTotal, Google visibility, enrichment, campaign analysis, and hunting
- https://learn.microsoft.com/en-us/defender/threat-intelligence/what-is-microsoft-defender-threat-intelligence-defender-ti
Supports
- Microsoft Threat Intelligence actor, tool, vulnerability, indicator, and investigation context inside Defender workflows
- https://dropbox.tech/security/changing-how-we-identify-malicious-urls-in-shared-documents
Supports
- Dropbox discovery that URLs submitted to a security vendor were visible to the vendor's paid subscribers and partners
- Operational response to stop submissions and remove the disclosed data
