Cybersecurity glossary

What is Threat Intelligence?

Learn what threat intelligence is, how strategic tactical and operational intel differ, how to use it in detections without drowning in feeds, and how to judge source quality.

Logging, detection and responseUpdated August 13, 2026
Also known asCyber threat intelligenceCTIAdversary intelligence

Definition

Threat intelligence is processed, contextual knowledge about adversaries, their capabilities, infrastructure, and intent—used to prioritize defenses, detections, and response rather than raw lists of indicators alone.

Why more feeds are not more intelligence

A folder of PDFs and a blocklist is not a program. Threat intelligence is the analysis that answers “so what for us?”: which actors have motive and access to your sector, which techniques they reuse, and which of your controls would actually fail.

Without that filter, the SOC imports the internet’s problems and misses the campaign that matches last quarter’s incident.

Intel that different audiences can use

Strategic

Sector targeting, geopolitical drivers, and business risk—used for investment and board reporting, not hash blocking.

Operational

Active campaigns, malware families, and likely next-stage objectives that shape hunting sprints.

Tactical / technical

TTPs, IOCs, and detection ideas with enough detail to test in your telemetry.

Internal collection

Your incidents, canaries, and honeypots—often the highest-relevance intel you will ever get.

From report to action

1

Collect with a requirement

Start from questions (ransomware affiliates, BEC, insider SaaS abuse), not from every free feed.

2

Evaluate source and confidence

Vendor marketing, community share, and first-party observation are not equal.

3

Map to your stack

Drop techniques you cannot see and infrastructure you do not use. Track the rest as coverage work.

4

Decide the action

Patch, hunt, detect, block, or brief leadership—one primary output per item.

5

Expire and review

Indicators and even actor names go stale. Intelligence products need owners and review dates.

Quality tests for intel you operationalize

TestPassFail
RelevanceMatches your sector, identity stack, or known incidentsGeneric malware hashes with no victimology
ActionabilityA defender can hunt or change a control this weekVague “be aware of ransomware”
FreshnessTimestamps and expected expiryRecycled IOCs from last year’s report
Ethics and legalityNo victim data, no unsafe collection adviceIndicators that identify other victims
  • Write intelligence requirements with detection, IR, and vuln-management consumers.
  • Prefer TTP-rich reporting over indicator dumps as the default ingest.
  • Score and expire IOCs; never infinite-block shared cloud IPs from a feed.
  • Track which intel items produced true positives versus wasted hunts.
  • Share internally in STIX or a TIP, not screenshots in chat.
  • Protect collection sources—especially customers and law-enforcement partners.
  • Brief executives in business impact language, not actor folklore.
  • Feed your own incidents back into the intel cycle; you are a sensor too.

The practical takeaway

Threat intelligence is contextual adversary knowledge that changes a decision. Collect to requirements, map to your telemetry, and demand an action—or you are just forwarding someone else’s blocklist.

Related security terms

Frequently asked questions

What is threat intelligence in simple terms?

It is useful knowledge about who might attack you, how they work, and what to watch for—not a firehose of IPs without a sentence of context.

What are the usual intel levels?

Strategic (who and why, for leaders), operational (campaigns and targeting), and tactical/technical (TTPs and IOCs for detections). Names vary; the audience split matters.

Is a threat feed the same as intelligence?

A feed is data. Intelligence has relevance, confidence, analysis, and a recommended action for your environment.

How do you know intel is good?

Clear source, timestamps, confidence, whether it was observed or inferred, and whether it maps to your tech stack and threat model.

Should every report become a SIEM rule?

No. Most reports should change hunting hypotheses or patch priority. Only a subset deserves standing detections.

What is a threat intelligence platform (TIP)?

A system to ingest, deduplicate, score, and share indicators and reports, often via STIX/TAXII, so SOCs are not managing CSV attachments.

Who should consume CTI?

Executives (strategic risk), vulnerability management (what to patch first), detection engineers, and IR (what this actor does after initial access).

References

Explore authoritative guidance and frameworks related to threat intelligence.

Explore every security definition

Return to the glossary to search by term, alias, starting letter, or security category.

Browse glossary