Security has historically been inward-looking: identify what we want to protect, build walls around it, and watch the walls. Threat intelligence turns the telescope outward, who is likely to attack us, how do they operate, and what should we change because of it?

A working definition

Threat intelligence is evidence-based knowledge about existing or emerging threats, context, indicators, mechanisms and actionable advice, that can inform decisions about how to respond. The key word is decisions. Data that changes nothing is not intelligence; it is inventory.

Three levels, three audiences

Level Question it answers Consumer
Strategic Who threatens us and why? Leadership, risk owners
Operational How do those actors campaign? SOC leads, IR teams
Tactical What observables can we detect right now? Analysts, SIEM content

Most “threat intel programs” buy tactical feeds and stop there. The feeds are the least valuable layer without the context above them: an IP address means little; an IP address attributed to a campaign currently targeting your sector means a hunt.

The intelligence lifecycle in a SOC

  1. Direction: define requirements (“are we exposed to the techniques in this ransomware wave?”).
  2. Collection: feeds, ISACs, vendor reporting, and your own incidents, the most underrated source.
  3. Processing: normalize, deduplicate, map to MITRE ATT&CK.
  4. Analysis: separate “interesting” from “relevant to us”.
  5. Dissemination: watchlists into the SIEM, briefs to leadership, hunting hypotheses to analysts.
  6. Feedback: did any of it change a decision? If not, adjust direction.

Pyramid of pain, briefly

Indicators age out fast, hashes in hours, IPs in days, domains in weeks. Behaviors (TTPs) persist. A mature program continuously shifts detection investment from the bottom of the pyramid toward techniques, because that is where attackers pay a real cost to adapt.

Frequently asked

Do small teams need threat intelligence? Yes, but as a discipline, not a product. Even one hour a week reviewing sector-relevant reporting and turning it into a hunt or a watchlist entry beats an unread feed.

This article was originally published on Medium.