Threat Analysis

Threat Intelligence

Threat Intelligence

Threat intelligence (TI) is actionable, evidence-based knowledge about cybersecurity threats — including context, mechanisms, indicators, implications, and actionable advice — that helps organizations make informed security decisions.

Types of Threat Intelligence

Strategic

High-level intelligence for executives and decision-makers, focusing on threat trends, risk landscapes, and long-term planning.

Tactical

Details about adversary TTPs used by defenders and detection engineers to build specific countermeasures.

Operational

Information about specific, imminent attacks or ongoing campaigns that require immediate defensive action.

Technical

Indicators of compromise (IOCs) such as malicious IPs, domains, file hashes, and email addresses used in automated detection.

Sources of Threat Intelligence

  • Open Source (OSINT): Publicly available threat reports, CVE databases, social media
  • Commercial Providers: Paid threat feeds and intelligence platforms
  • Government/CERTs: National cybersecurity organizations and advisories
  • Industry Sharing (ISACs): Sector-specific information sharing groups
  • Internal Telemetry: An organization's own security logs and incident data

Applying Threat Intelligence

  1. Enrich SIEM alerts with contextual threat data
  2. Proactively hunt for indicators of known campaigns
  3. Prioritize vulnerability remediation based on active exploitation
  4. Inform detection engineering priorities with current threat actor TTPs

Related Terms

Related Reading

Blog

What CERT-In’s AI Threat Blueprint Means for Adversarial Exposure Validation

CERT-In’s blueprint points toward a cybersecurity model that is continuous, threat-informed, and evidence-led. Here is what that means in practice, and how adversarial exposure validation helps organisations test whether their controls actually work against AI-assisted threats.

Blog

Red, Blue, and Purple Teaming: A collaborative approach to Security Assurance

Purple Teaming is a new cybersecurity approach aiming to improve the collaboration between the red and blue teams. It involves sharing knowledge, continuous evaluation, and better communication between the two teams to improve the organization's cybersecurity posture.

Guide

Meet FourCore at AISS 2023

Geared up for a deep dive into the world of revolutionary cybersecurity discussions and groundbreaking innovation at India's Biggest Cyber Security Summit, AISS 2023. Discover how we make offensive security accessible for all security teams - red and blue alike and arm them with the expert capability to protect against the most imminent threats.

Guide

Meet FourCore @BlackHat MEA 2023

Gearing up for a deep dive into the world of revolutionary cybersecurity discussions and groundbreaking innovation. We are gearing up for our striking debut at the spectacular Black Hat MEA 2023. Discover how we make offensive security accessible for all security teams - red and blue alike and arm them with the expert capability to protect against the most imminent threats.