ELI5: What is Threat Intelligence?

It is like getting a heads-up from your neighbor that someone has been trying doorknobs on your street. Threat intelligence is information about what bad guys are doing, what tools they use, and who they are targeting. When security teams get this information early, they can lock the right doors before the bad guys even show up. The better your information, the better you can prepare.

Overview

Threat intelligence is the collection, processing, and analysis of data about current and potential cyber threats to help organizations make informed security decisions. It transforms raw data into actionable intelligence that can be used to prevent, detect, and respond to attacks. Threat intelligence operates at strategic, operational, tactical, and technical levels.

Key Concepts

Exam Tips

Remember

Intelligence levels: Strategic (WHY/WHO - executives) → Operational (WHAT campaigns) → Tactical (HOW - TTPs) → Technical (specific IoCs - machines). STIX = format, TAXII = transport.

  • Not all threat intel is equally reliable — always assess source credibility and confidence
  • Open-source threat intelligence (OSINT) is free but requires more validation
  • ISACs enable industry peers to share threat data — know they exist and their purpose

Connections

  • Provides context that enriches siem alerts and correlation rules
  • Supplies indicators-of-compromise used by security tools for automated detection
  • Informs threat-hunting hypotheses about where and how to look for adversaries
  • Intelligence about threat actors overlaps with understanding threat-actors motivations and capabilities

Practice Questions

Scenario

See case-threat-intelligence for a practical DevOps scenario applying these concepts.