Lesson 28 of 35TITI

What is TI?Threat Intelligence explained

Collects current information about threat groups, techniques, malicious infrastructure, and active campaigns so teams can tune detections and prioritize relevant threats.

By Reviewed

Verified Sources: ibm.com, cloudflare.com, cloudflare.com

The lesson

How defenders learn an attacker's next move

You can't defend against threats you've never heard of. This lesson explains how knowledge about attacker groups, tools, and infrastructure gets collected, vetted, and pushed into your defenses.

If it helps, think of it as… the neighborhood watch bulletin

When a burglary crew works a city, police brief the neighborhoods: what van the crew drives, how they case houses, which locks they pick. Residents don't have to catch the crew themselves — knowing what to watch for turns a hundred ordinary sightings into an early warning. Threat intelligence is that bulletin, written for networks.

Malware analysis

What captured samples actually do

Honeypots & sensors

Attacks observed in the wild

Dark web monitoring

Leaked data and criminal chatter

Sharing communities

Indicators exchanged via STIX/TAXII

Incident reports

Lessons from investigated breaches

Threat intel program

Vet, enrich, map to MITRE ATT&CK

IOC blocklists

Known-bad IPs, domains, file hashes

Adversary profiles

Who targets you and how they operate

Alert enrichment

Context piped into SIEM and SOAR

Patch priorities

Which flaws are exploited right now

Raw observations from many places are vetted and enriched into intelligence that tunes tools automatically and guides human decisions.

What it does

Threat intelligence (TI) is organized knowledge about attackers: which groups are active, what they're after, the tools and infrastructure they use, and the traces they leave behind. It arrives in two broad forms. Technical indicators — called indicators of compromise, or IOCs — are concrete artifacts like a malicious file hash, domain, or IP address that tools can match automatically. Behavioral knowledge — tactics, techniques, and procedures, or TTPs — describes how a group operates, usually organized with MITRE ATT&CK, a free public catalog of real-world attacker techniques.

The job of a threat intelligence program is to turn a flood of raw observations into a small amount of relevant, current, usable knowledge.

The attack it stops

A criminal group launches a phishing campaign against hospitals, registering look-alike domains and reusing the same malware family it used last month. Researchers who analyzed that malware publish the domains and file hashes it uses. Hospitals subscribed to a well-run intelligence feed ingest those indicators automatically: their email filters now quarantine messages linking to the domains, and their firewalls refuse connections to the group's command-and-control (C2) servers — the machines the malware phones home to for instructions.

For one hospital, the campaign simply never lands. When an employee at another does click a copy that slipped through, the outbound C2 connection is blocked and flagged — so what could have been a ransomware incident becomes a ten-minute cleanup.

How it works, step by step

  1. Plan. Decide what actually matters to your organization: which industries, regions, and systems attackers would target.
  2. Collect. Raw data flows in from malware analysis, honeypots, researcher reports, dark web monitoring, and sharing communities — often exchanged in open standards called STIX and TAXII, built for describing and transporting indicators between organizations.
  3. Process and analyze. Duplicates and stale indicators get pruned, and analysts add the context that makes data into intelligence: who uses this infrastructure, with which techniques, at what confidence.
  4. Disseminate. Indicators feed automatically into blocking and detection tools, while written adversary profiles brief the humans making bigger decisions.
  5. Feed back. What proved useful shapes what gets collected next — the whole loop is known as the intelligence lifecycle.

What it doesn't do

Intelligence describes the threat; it doesn't defend anything by itself. An indicator nobody feeds into a firewall blocks nothing. And IOCs age fast — attackers rotate domains and recompile malware within days, which is why behavioral TTPs hold their value far longer than any blocklist.

The common beginner misconception is that subscribing to more feeds means more security. Unvetted feeds pile up stale, irrelevant indicators that trigger false alarms and bury real ones. Good intelligence is judged on relevance, timeliness, and whether anyone can act on it — not on volume.

How it fits the stack

Threat intelligence is a supporting layer for nearly everything else. It enriches alerts in the SIEM so analysts see "known ransomware infrastructure" instead of a bare IP address, powers the automated lookups inside SOAR playbooks, and tells your vulnerability management program which flaws attackers are actively exploiting right now.

Terms you just met

Each links to its plain-language definition in the glossary.

The field guide

Evaluating this category

A second pass for buyers: market context, distinctions that matter, and what to weigh when tools in this category start looking alike.

Defenders make hundreds of small decisions a week: which alerts to chase, which vulnerabilities to patch first, which login attempts to treat as hostile. Those decisions are only as good as what the team knows about who is actually attacking organizations like theirs, and how. Threat intelligence is that knowledge, packaged as a product — a continuously updated picture of active attacker groups, their techniques, and the specific technical fingerprints they leave behind.

It arrives in two broad forms: machine-readable feeds of indicators — malicious IP addresses, domains, file hashes — that plug directly into other security tools, and human-readable research that helps analysts and leadership understand adversaries, campaigns, and emerging risks.

The problem it solves

Without outside intelligence, a security team can only learn from attacks it has personally experienced — which means every lesson is paid for with an incident. Meanwhile the questions that shape defensive priorities go unanswered: is this vulnerability being exploited in the wild right now, or just theoretically severe? Is that odd domain in the logs a known phishing operation? Are credentials from our organization circulating on criminal marketplaces?

The raw information exists, scattered across malware repositories, underground forums, incident write-ups, and honeypots — but collecting, validating, and maintaining it is a full-time research operation few security teams can staff. Stale indicators are worse than none: they generate false alerts and block legitimate traffic.

How it works

Providers run large collection operations — sensor networks, malware analysis pipelines, crawlers over criminal forums and marketplaces, and in many cases human researchers who track specific adversary groups for years. What they collect gets validated, deduplicated, scored for confidence, and enriched with context: not just "this IP is bad" but which campaign it belongs to, what malware family it serves, and when it was last seen active.

The output flows to customers in two channels. Feeds integrate with the rest of the stack — a SIEM matches incoming events against known-bad indicators, an automation playbook queries a suspicious file hash during triage, a firewall blocklist updates itself. A research portal serves the human side: profiles of adversary groups mapped to standard technique frameworks, vulnerability exploitation tracking, and monitoring for the organization's own leaked credentials, impersonated domains, or data turning up for sale.

Strategic vs tactical intelligence

Tactical intelligence is the machine-speed layer: indicators and technique details whose value is measured in freshness, precision, and how automatically they reach enforcement points. It answers "should this connection be blocked?" Strategic intelligence operates on a longer horizon for a human audience — which adversary groups target this industry, how ransomware economics are shifting, what a new conflict means for the threat landscape. It answers "what should we invest in next quarter?" Many products bundle both, but a team buying feed enrichment and a team buying executive briefings are buying different things, and a product excellent at one may be mediocre at the other.

Choosing one

Judge collection before presentation. A polished portal wrapped around commodity data adds little over free community sources — ask where a provider's visibility genuinely comes from: original research, unique sensor coverage, dark-web access, incident-response casework. Coverage relevant to your industry and region matters more than raw indicator volume.

Then confirm the intelligence can actually reach your tools. Value is realized through integration — if enriching an alert or pushing a blocklist requires manual export, the subscription becomes an expensive newsletter. Free community feeds and sharing platforms are a legitimate starting point; paid products earn their cost through curation, context, and lower false-positive rates.

Capability taxonomy

What buyers typically evaluate when comparing tools in this category.

Curated IOC feeds
Provides vetted lists of malicious IPs, domains, and file hashes.
Adversary & TTP profiles
Documents known attacker groups and the techniques they typically use.
Dark web & brand monitoring
Watches for leaked credentials, data, or brand impersonation outside the organization.
SIEM/SOAR enrichment integration
Automatically feeds intelligence context into alerts and playbooks.
Vulnerability & exploit intelligence
Tracks which vulnerabilities are being actively exploited in the wild.
Analyst research portal
Gives analysts a searchable portal to investigate threats manually.

Tools in this category

Now that you know what TI does, see who does it.

Search Cyber Tool Stack

Jump to any tool, vendor, category, or glossary term.