CTI Foundations
A file hash in a threat feed is not intelligence. Neither is a list of malicious IPs. Intelligence is information that has been collected, processed, analyzed, and contextualized to support a specific decision. This chapter establishes what threat intelligence actually is, how it moves through an organization, and who uses it.
What Is Threat Intelligence?
Threat intelligence is analyzed information about adversaries and their capabilities that enables better security decisions. That definition has three load-bearing words.
The Three Load-Bearing Words
- Analyzed: raw data has been processed and interpreted, not just collected.
- Adversaries: the focus is on human actors with intent, not generic vulnerability data.
- Decisions: intelligence exists to reduce uncertainty at a specific choice point, whether blocking an IP, escalating an alert, or briefing an executive on sector risk.
Data vs. Information vs. Intelligence
The intelligence community distinguishes three tiers of maturity for the same underlying observation:
| Tier | Definition | Example |
|---|---|---|
| Data | Unprocessed observations | Log lines, packet captures, domain registration records |
| Information | Data parsed and structured into something meaningful | A domain registered to a known hosting provider in a country associated with threat activity |
| Intelligence | Information analyzed, contextualized, and assessed against a specific question | "Is this domain part of the actor campaign our IR team is working? What is the confidence level? What should we do?" |
Why the Distinction Matters
Most of what gets called threat intelligence in vendor feeds is actually data or information. A file hash list is data. An IP reputation score is information. A finished analysis explaining which APT group is using a specific toolset, what their targeting patterns look like in your sector, and which TTPs to prioritize for detection is intelligence.
The difference is not pedantic. Analysts who treat raw feeds as finished intelligence make worse decisions and waste triage time on low-confidence, decontextualized indicators.
The Intelligence Cycle
The intelligence cycle is the repeating process through which raw collection becomes finished intelligence and eventually feeds back into new requirements. Most frameworks break it into five or six phases, and the specifics vary by organization, but the core sequence is consistent.
Direction: Where the Cycle Begins
Someone with a decision to make articulates what they need to know. These are formalized as Priority Intelligence Requirements (PIRs) or Standing Intelligence Requirements (SIRs). The specificity of the requirement determines how useful the eventual intelligence will be.
- A SOC team might define: "What are the current active C2 infrastructure ranges for ransomware groups targeting healthcare?"
- A CISO preparing for a board meeting might need: "What is the current threat landscape for financial institutions in APAC?"
Collection: Acquiring Raw Data
Collection is the systematic acquisition of raw data that could answer the requirement, drawn from four kinds of sources:
- Open-source intelligence (OSINT): public threat reports, vendor advisories, and social media.
- Commercial intelligence feeds: providers like Recorded Future, Mandiant, or CrowdStrike.
- Technical sources: malware sandbox analysis, network traffic, and honeypot data.
- Human sources: ISAC sharing communities and vendor briefings.
Processing: Making Data Analyzable
Processing converts raw collection into something analyzable: parsing structured data, translating foreign-language reports, normalizing IOC formats, and deduplicating entries across feeds. A significant portion of CTI team time goes into processing work that never appears in finished products but determines whether analysis is possible at all.
Analysis: The Cognitive Core
Analysis is where collected information becomes intelligence. An analyst applies context, draws connections, assesses confidence, identifies gaps, and produces an assessment. Good analysis requires knowing what you do not know as clearly as what you do, and communicating both.
Dissemination and Feedback
Dissemination delivers the finished intelligence to the consumer in a format they can act on. Timing matters: a report about an active campaign delivered three days after the actor moved off that infrastructure is useless. Format matters too: an executive brief with 40 IOC appendices will not be read. Feedback from consumers closes the loop, reporting whether the intelligence supported the decision, what was missing, and what should be prioritized next cycle.
| Phase | Core Activity | Common Failure |
|---|---|---|
| Direction | Define PIRs and collection targets | Vague requirements produce generic products nobody uses |
| Collection | Acquire raw data from multiple sources | Single-source collection creates blind spots and bias |
| Processing | Parse, normalize, and deduplicate | Poor processing means analysis operates on corrupt data |
| Analysis | Contextualize, assess, produce finished intel | Treating data as finished intel; omitting confidence levels |
| Dissemination | Deliver to consumer in actionable format | Wrong format for the audience; late delivery |
| Feedback | Refine requirements based on outcomes | No feedback loop means cycle never improves |
Types of Intelligence
Intelligence is commonly divided into four types based on the time horizon and consumer it serves. Each type requires different sources, different analytical techniques, and different output formats. Conflating them is one of the most common failures in CTI programs.
Four Types, Four Audiences
| Type | Consumer | Time Horizon | Typical Question | Content |
|---|---|---|---|---|
| Strategic | CISOs, boards, executive teams | Months to years | "Is our sector being targeted more frequently than last year? Are nation-state actors shifting focus toward our supply chain?" | Assessments, trend lines, and recommendations; rarely contains IOCs |
| Operational | Security managers, IR leads, threat hunt teams | Weeks to months | "There is an active ransomware campaign targeting mid-size logistics companies using a specific initial access vector. What do we know about the actor, delivery mechanism, and affected regions?" | Active campaign context that helps teams prioritize hunts, plan IR exercises, and scope defenses |
| Tactical | SOC analysts (where most work happens) | Days to weeks | "This actor uses T1059.001 (PowerShell) with a specific base64 encoding pattern and drops a RAT to C:\Users\Public\svchost.exe before beaconing to a DGA domain." | Adversary TTPs that feed detection rule development, hunt hypotheses, and IR playbook updates |
| Technical | SIEM, firewall, and EDR automation | Hours to days | Individual IOCs: IP addresses, file hashes, domains, URLs | High-volume, fast-decaying data; the tier most commonly mislabeled as "threat intelligence" when it is really just data |
Conflating the Tiers Is a Common Failure
A team producing only tactical IOC feeds for a CISO is not serving that audience, and a team producing only strategic assessments for a SOC is leaving analysts without actionable data.
The TLP Framework
Traffic Light Protocol (TLP) is the sharing classification system used across the security community to control how intelligence can be distributed. It was developed by FIRST (Forum of Incident Response and Security Teams) and has become the de facto standard. Understanding TLP is required before engaging in any sharing community, ISAC, or intel exchange.
The Five Markings
| Marking | Distribution Scope | Typical Use |
|---|---|---|
| TLP:CLEAR | Unrestricted. The source has assessed that public release creates no harm. | Public threat reports, blog posts, and vendor whitepapers typically carry TLP:CLEAR or no marking at all. You may share, publish, and reference it openly. |
| TLP:GREEN | Community, not public release. | ISACs and sector sharing groups typically operate here. Share with peers in your sector and your organization, but not with media, public forums, or parties outside the relevant community. When in doubt about who counts as "community," ask the source first. |
| TLP:AMBER | Recipient organization and its clients. | Appears on vendor briefings, incident-specific reporting, and intelligence about active campaigns that could harm third parties if widely disclosed. Share within your organization on a need-to-know basis; do not distribute externally without explicit permission from the originating source. |
| TLP:AMBER+STRICT | Immediate recipient only, not clients or subsidiaries. | Used when the source has a specific reason to limit distribution even within the recipient organization. |
| TLP:RED | Named individuals or group only. | Covers highly sensitive information about active nation-state operations, unpatched zero-days, or ongoing law enforcement actions. Mishandling it can compromise ongoing investigations or harm victims. |
Intelligence Requirements
Intelligence requirements are formal statements of what a consumer needs to know to make a decision. They are the mechanism that prevents CTI programs from producing interesting-but-useless research. Every CTI product should trace back to a documented requirement, or the team is doing analysis for its own sake rather than serving the organization.
Three Requirement Types
- Priority Intelligence Requirements (PIRs): the highest-priority questions an organization needs answered, for example "What threat groups are currently targeting critical infrastructure in our region, and what initial access vectors are they using?" Set by organizational leadership in consultation with the security team and revisited regularly, usually quarterly. PIRs define what the CTI team collects against and what gets resourced.
- Specific Intelligence Requirements (SIRs): sub-requirements that must be answered to satisfy a PIR. If the PIR asks about initial access vectors for regional threat groups, SIRs would include "What phishing lure types does this actor group use?", "What exploit does the group use for internet-facing appliances?", and "What are the known C2 protocol signatures for the group's toolset?" SIRs guide specific collection tasks and analysis efforts.
- Requests for Information (RFIs): ad-hoc requirements from consumers outside the normal PIR process, for example an incident responder on an active case asking "Do you have any intel on infrastructure tied to this IP range or this file hash pattern?" RFIs are time-sensitive and should be triaged quickly: can this be answered from existing collection, or does it require new tasking? RFIs that recur frequently are candidates for elevation into standing SIRs.
The Anti-Pattern Requirements Discipline Prevents
The discipline of requirements management prevents a common CTI anti-pattern: the team that tracks everything interesting but produces nothing actionable. Every hour spent collecting and analyzing something should be justified by a requirement. When it is not, the team is building reports no one will read and missing the questions that actually matter to the organization.
What This Module Covers
Eight chapters build a complete CTI practitioner skill set from vocabulary through production-grade output. Chapter 1 (this chapter) establishes the foundational concepts that everything else builds on: intelligence vs data, the intelligence cycle, the four types, TLP, and requirements.
Chapter Breakdown
- Chapter 2, IOC Types and Confidence Scoring: not all indicators are equal, and treating a file hash the same as a TTP is one of the most common analytical errors.
- Chapter 3, Threat Actor Profiling: the Diamond Model, ATT&CK Groups, and naming conventions across vendors.
- Chapter 4, Structured Sharing: STIX 2.1, TAXII, MISP, and how to participate in a trust community without creating liability for yourself or your organization.
- Chapter 5, Intel-Driven Hunting: how to take a finished intelligence report and produce hunt hypotheses, pivot chains, and search queries from it.
- Chapter 6, Malware and Campaign Intelligence: reading sandbox reports, clustering samples to campaigns, and writing basic YARA rules from behavioral analysis.
- Chapter 7, CTI Report Writing: producing finished intelligence products that executives will read and analysts can act on.
- Chapter 8, Detection From Intel: converting intelligence directly into detection rules, ATT&CK coverage mappings, and tuned Sigma/KQL queries.
Key Takeaways
- Intelligence is analyzed, contextualized information that supports a specific decision. A hash list is data. A finished analysis about an actor campaign is intelligence.
- The intelligence cycle has six phases: direction, collection, processing, analysis, dissemination, and feedback. Each phase can fail independently.
- Four types of intelligence serve different consumers: strategic (executives), operational (hunt/IR teams), tactical (analysts), and technical (SIEM/firewall automation).
- TLP controls sharing scope: CLEAR (unrestricted), GREEN (community), AMBER (organization), AMBER+STRICT (recipient only), RED (named individuals only).
- PIRs define what the CTI program collects against. Every analysis product should trace back to a documented requirement or it is unlikely to be used.
- RFIs from incident responders are time-sensitive and are candidates for becoming standing SIRs if they recur.
Knowledge Check
Click an answer to reveal the explanation.
A vendor delivers a daily feed of 50,000 malicious IP addresses with no accompanying context. This is best described as:
A CISO asks: "Are nation-state actors increasingly targeting our sector, and what should we be doing about it?" This is best satisfied by:
An incident responder sends you a TLP:AMBER report about an active campaign and asks you to share it with a vendor partner for their input. What should you do?