Security has historically been inward-looking: identify what we want to protect, build walls around it, and watch the walls. Threat intelligence turns the telescope outward, who is likely to attack us, how do they operate, and what should we change because of it?
A working definition
Threat intelligence is evidence-based knowledge about existing or emerging threats, context, indicators, mechanisms and actionable advice, that can inform decisions about how to respond. The key word is decisions. Data that changes nothing is not intelligence; it is inventory.
Three levels, three audiences
| Level | Question it answers | Consumer |
|---|---|---|
| Strategic | Who threatens us and why? | Leadership, risk owners |
| Operational | How do those actors campaign? | SOC leads, IR teams |
| Tactical | What observables can we detect right now? | Analysts, SIEM content |
Most “threat intel programs” buy tactical feeds and stop there. The feeds are the least valuable layer without the context above them: an IP address means little; an IP address attributed to a campaign currently targeting your sector means a hunt.
The intelligence lifecycle in a SOC
- Direction: define requirements (“are we exposed to the techniques in this ransomware wave?”).
- Collection: feeds, ISACs, vendor reporting, and your own incidents, the most underrated source.
- Processing: normalize, deduplicate, map to MITRE ATT&CK.
- Analysis: separate “interesting” from “relevant to us”.
- Dissemination: watchlists into the SIEM, briefs to leadership, hunting hypotheses to analysts.
- Feedback: did any of it change a decision? If not, adjust direction.
Pyramid of pain, briefly
Indicators age out fast, hashes in hours, IPs in days, domains in weeks. Behaviors (TTPs) persist. A mature program continuously shifts detection investment from the bottom of the pyramid toward techniques, because that is where attackers pay a real cost to adapt.
Frequently asked
Do small teams need threat intelligence? Yes, but as a discipline, not a product. Even one hour a week reviewing sector-relevant reporting and turning it into a hunt or a watchlist entry beats an unread feed.
This article was originally published on Medium.