Threat Intelligence
Collecting, analyzing, and applying data about current cyber threats.
Term
description · examples · notesCollecting, analyzing, and applying data about current cyber threats.
Description
Includes IOCs (indicators of compromise), TTPs, and attacker information.
Feeds integrate into SIEM, EDR, and firewalls for proactive detection.
Strategic TI informs management, operational TI informs the SOC team.
Sources include OSINT, commercial feeds, ISACs, and dark web monitoring.
What people often say
- More feeds do not mean better protection — quality and relevance matter more than quantity.
- TI is not just a list of IOCs — strategic analysis is equally important.
Covers / does not cover
Covers
- IOC feeds (IP addresses, hashes, domains)
- TTP analysis of threat groups
- Early warning of new campaigns
Does not cover
- Automated incident response (that is SOAR)
- Detection without integration into tools
- Internal threats without external indicators
Mentioned in the news
- 28. MAR 2026. Zašto je threat intelligence u središtu bezbednosnih integracija →
- 28. MAR 2026. ESET predstavio eCrime izveštaje za praćenje ransomware i infostealer pretnji →
- 28. MAR 2026. ISAC organizacije oprezno gledaju na AI u deljenju threat intelligence podataka →
- 18. APR 2026. Hunt.io mapirao više od 1.250 C2 servera kod ruskih hosting provajdera →
Threats
reduces 6Threats it reduces. Select one to open its page.
Techniques
neutralizes 5Techniques it neutralizes. Select one to open its page.