H3AD-REF / REFERENCES / THREAT INTEL CYCLES

Two Cycles CTI Runs On.
One Slow, One Fast.

CTI Lifecycle is the strategic cycle — requirements through dissemination, over weeks. F3EAD is the tactical one: find, fix, finish, exploit, analyze, disseminate, run per-target inside a single engagement, feeding straight back into the next Find.

PART OF A 4-FILE SERIES ON SECURITY FRAMEWORKS & MODELS Attack Lifecycle & Adversary Models · Incident Response & Analysis Models · Defensive & Hunting Maturity Models · Threat Intel Cycles

CTI Lifecycle

The classic intelligence cycle, adapted for cyber threat intel. Six phases, cyclical, consumer feedback drives the next round of requirements.

01
DIRECTION
Define intelligence requirements (PIRs)
›
02
COLLECTION
Gather raw data: OSINT, feeds, telemetry
›
03
PROCESSING
Normalize, decrypt, translate, structure
›
04
ANALYSIS
Turn processed data into assessed intel
›
05
DISSEMINATION
Deliver intel to SOC, IR, and leadership
›
06
FEEDBACK
Consumers rate usefulness, refine scope
↻ CYCLE REPEATS — Feedback reshapes the next Direction phase

F3EAD

Military-derived operational intel cycle. Where the CTI Lifecycle above is strategic (requirements → dissemination over weeks), F3EAD is tactical — built to run per-target, fast, feeding straight back into the next operation.

01
FIND
Locate the target — a host, an actor, an infrastructure node
›
02
FIX
Confirm identity and position with enough precision to act
›
03
FINISH
Act — contain, block, or take down the target
›
04
EXPLOIT
Extract everything the action just revealed — artifacts, infra, TTPs
›
05
ANALYZE
Turn what was exploited into assessed intelligence
›
06
DISSEMINATE
Push findings back out — often straight into the next Find
↻ CYCLE REPEATS — Disseminate feeds the next Find, often within the same engagement