Cyber Threat Intelligence

Also known as:CTI

Cyber Threat Intelligence: Processed information regarding threat actors, tactics, indicators, and risks. This capability prepares information about threats and attackers in an actionable format. Source assessment, context, timeliness, structured dissemination, and feedback into protective measures determine its utility.

How it works and where it fits

Cyber Threat Intelligence structures knowledge about potential adversaries, their objectives, capabilities, infrastructure, and observed behavior. Individual indicators are short-lived and easy to change, while behavioral patterns and technical relationships often have greater analytical value. Reporting should distinguish observed facts, assessments, and assumptions.

Practical security relevance

Practical use depends on source quality, timeliness, and relevance to the organization’s own attack surface. Information is prioritized, correlated with internal data, and converted into searches, detections, or safeguards. Investigation feedback continuously improves the assessment. Confidentiality and permitted sharing are as important as technical exchange formats.

  • Threat ActorThreat ActorAn individual, group, or organization that intentionally carries out or supports cyberattacks.: An individual, group, or organization that intentionally carries out or supports cyberattacks.
  • Indicator of CompromiseIndicator of CompromiseTechnical artifact indicating a potential compromise.: Technical artifact indicating a potential compromise.
  • Threat HuntingThreat HuntingSearches for previously undetected attacker activity based on hypotheses.: Searches for previously undetected attacker activity based on hypotheses.
  • Threat Intelligence PlatformThreat Intelligence PlatformCollects, normalizes, and distributes threat intelligence and indicators.: Collects, normalizes, and distributes threat intelligence and indicators.