166 terms · 75/46/45
Defense № 019 · class: monitoring / response

Threat Intelligence

Collecting, analyzing, and applying data about current cyber threats.

Term

description · examples · notes

Collecting, analyzing, and applying data about current cyber threats.

Description

Includes IOCs (indicators of compromise), TTPs, and attacker information.

Feeds integrate into SIEM, EDR, and firewalls for proactive detection.

Strategic TI informs management, operational TI informs the SOC team.

Sources include OSINT, commercial feeds, ISACs, and dark web monitoring.

What people often say

  • More feeds do not mean better protection — quality and relevance matter more than quantity.
  • TI is not just a list of IOCs — strategic analysis is equally important.

Covers / does not cover

Covers

  • IOC feeds (IP addresses, hashes, domains)
  • TTP analysis of threat groups
  • Early warning of new campaigns

Does not cover

  • Automated incident response (that is SOAR)
  • Detection without integration into tools
  • Internal threats without external indicators

Mentioned in the news

Composite

Threats

reduces 6

Techniques

neutralizes 5

Techniques it neutralizes. Select one to open its page.