Back
Cyber Security
Mon Jan 05 2026

Threat Intelligence

                              Threat Intelligence 

What is Threat Intelligence

Threat intelligence is the process of collecting, processing and analyzing data to understand the attackers motive, how they performed the attack and how we can avoid that attack happening again. It also provides other cybersecurity practitioners knowledge on what they should avoid to minimize the threats. So threat intelligence is an evidence based,decision oriented and actionable report which tells us how they were attacked, why they were attacked, and how the attack was found and what they can do to avoid it. It helps us understand the attackers TTP’s (tactics, techniques, procedures), also with the rise of APT’s(Advanced Persistence Threats) we can identify them as it provides information on attackers TTP’s, motives and indicators of compromises(IOCs).

Who is benefiting from Threat Intelligence and how?

It is rather helpful for small scale businesses as they don't have enough budget for a separate threat intelligence team. The small scale businesses can use the threat intelligence report of others to implement necessary procedures, training and awareness to minimize their companies risk of being attacked and having their data leaked which can cause a massive loss to their already small scale business.  The big scale businesses can also use the report to improve their existing cybersecurity team and have them upgrade their vulnerabilities.

When is Threat Intelligence carried out?

Threat Intelligence is carried out both before and after the attack.

Threat intelligence carried out before the attack can be said to be in a pro-active stance i.e being ready for the attack. It is carried out by following process

  • Preventation: In this stage the security team investigates the threat data to analyze the attackers TTP’s and various malwares that can be used to attack the system. They collect data and use that data to strengthen their system, patch vulnerabilities and educate employees in advance.
  • Threat hunting: It is the process of actively looking for breaches in the system that can be used to compromise the system. It helps to prevent major accidents by solving them before they happen. It can be looking out for unusual activity logs from users, Network traffic analysis(NTA) etc.
  • Decision making: After collecting data it can be presented to the heads for them to make a decision on what to do. It can be used to invest money on vulnerable sites.

The ones carried out during and after the attack can be referred to as reactive stance. Things done in reactive stance are of as following

  • Improving incident response: During an attack, intelligence can find out the attackers TTP’s, and indicators of compromise(IOCs) which can help the incident responders contain the threats more easily.
  • Post-Incident Review: After an attack, intelligence can be used to piece together exactly how the incident occurred, identify any remaining exposure, and inform future defenses to prevent similar events.  
  • Forensics: It can be used to find out if any back doors are left behind in the server which the attackers can use to again gain access to the server. It helps prevent any loop holes left behind by the attackers.

How Threat Intelligence is carried out?

Threat intelligence is carried out by a continuous process of 

  1. Requirement
  2. Data collection
  3. Data processing
  4. Analysis
  5. Feedback 
  • Requirement: 

In this stage a team is made where they discuss the agendas and goals of the threat intelligence. It is a crucial step. They also discuss the budget of the threat intelligence.

  • Data collection:

After the team is formed they begin to collect data. The data collected in this stage is referred to as raw data as they are unprocessed and generally not correlated to each other. The raw data that the team collects in this stage is generally collected from different sources such as online social media platforms and available public data through OSINT, through humans by interviewing, social engineering etc. They are generally not correlated and not fact checked.

  • Data processing:

In this process the raw data collected are fact checked and cross checked as well as analyzed to find the correlation between the various data. There are thousands of raw data collected and we have to go through each and every one of them. They also need to decrypt the data collected to be easy to understand.

  • Analysis:

Finally the processed data is analysed and made ready for the shareholders and responsible authorities. The analysis is done so that the important information can be conveyed to the stakeholders and immediate actions can be taken.

  • Feedback:

Here the processed data is provided to the stakeholders and after discussion of the data the feedback that was given is taken into consideration and further actions are taken such as improvement of threat information and what we have to focus more on going on, what to do with this present data and so on.

This is how threat intelligence is carried out. It helps for threat hunting, assists security operations centers(SOC)  during cyber attacks and many more. 

Types of Threat Intelligence:

The types of threat intelligence are:

  1. Strategic Threat Intelligence (executives, business risk)

It is mainly done for executives, CISOS etc. It provides a high level overview of threat landscapes focusing on long term trends, emerging threats and potential business risk. It helps them understand how cyber threats may impact organizational objectives and how they can prevent it.

  1. Operational Threat Intelligence (campaigns, attacks)

It involves analyzing specific, incoming or emerging threats and helps us understand “why” and “when” of attacks. It assists the incident responders in the future by providing them with necessary information and intelligence on how to respond to that threat. 

  1. Tactical Threat Intelligence (TTPs, adversary behavior)

It focuses on the TTPs (Tactics, Techniques and procedures) of how the attack is happening. It helps incident responders understand how attacks are carried out including initial access, persistence, lateral movement and data exploitation.

  1. Technical Threat Intelligence (IPs, hashes, domains)

It focuses on specific clues or evidence of an attack and creates a base to analyze such attacks by scanning for IOCs(indicators of compromise) which includes reported IP addresses, the contents of phishing emails, malware samples etc. It is important to submit in time as the IOCs become obsolete in a few days

OSINT

OSINT (Open source intelligence) is the process of acquiring data and information already available in the open sources such as social media, various websites etc. It is helpful in threat intelligence as it helps identify the relations connections and other vulnerabilities that the company's staff has that can be used by attackers. OSINT may also support limited dark web monitoring; however, such intelligence is not always freely accessible and often requires paid access, credentials, or specialized intelligence feeds. One of the tools for OSINT is spiderfoot which can be used to find variabilities in a website.