Threat Intelligence

Technology Fundamentals

Threat Intelligence

1 min readPublished 22 Jul 2026

Track your progress. Sign in to mark this guide complete and build your Job Readiness Score.

Cyber Threat Intelligence (CTI) turns raw data about threats into decisions — helping you defend against the attackers most likely to target you. It's the strategic partner to threat hunting and the SOC.

Interactive explainer

The Threat Intelligence Cycle

Turning raw data into actionable defence.

11. Direction22. Collection & processing33. Analysis44. Dissemination & feedback

Tap or hover a part to learn more.

1. Direction

What to know.

Define the intelligence requirements: which threats and questions matter to your organisation and sector.

Check your understanding

1. What are the levels of threat intelligence?

2. Why value TTPs over IOCs?

Keep learning

Practise this in AI Interview™

The essentials

  • The intelligence lifecycle — direction → collection → processing → analysis → dissemination → feedback.
  • Levelsstrategic (big-picture, for leadership), operational (campaigns/actors) and tactical (specific IOCs and TTPs for defenders).
  • IOCs vs TTPs — indicators are perishable; TTPs (behaviours) are more durable and valuable.
  • FrameworksMITRE ATT&CK and the Diamond Model structure analysis.
  • Feeds & sharing — commercial, open-source (OSINT) and community sharing (ISACs) feed the picture.

Good CTI makes defence proactive and prioritised rather than reactive.

Interview Intelligence

How this topic actually shows up in interviews — and how to demonstrate you understand it.

Why employers ask about this

CTI makes defence proactive, and analysts who can produce and use it are in high demand.

Technical questions
Walk me through the threat intelligence lifecycle.+

Direction, collection, processing, analysis, dissemination and feedback — turning raw data into actionable intelligence.

Behavioural questions
Tell me about turning information into a decision.+

Show analysing data and communicating an actionable recommendation.

Real-world scenarios
“Leadership ask which threats to prioritise for your sector.”+

Expected answer: Produce intelligence: gather feeds/OSINT, analyse actors and TTPs against ATT&CK, and recommend prioritised defences.

Employability Intelligence

Where this knowledge takes you — the jobs, skills and certifications it feeds into.

Relevant roles
Threat Intelligence AnalystSOC AnalystThreat Hunter
Skills you're proving
Threat intelligenceIntel lifecycleMITRE ATT&CK
Recommended certifications
CompTIA CySA+GIAC GCTI
Career progression

Cyber Fundamentals → CTI/SOC roles.

What employers expect

That you understand core security principles and can apply them to real risks, controls and incidents.

Frequently asked questions

What is cyber threat intelligence?

The process of collecting and analysing data about threats to produce actionable insight that guides defence.

What are the levels of threat intelligence?

Strategic (leadership/big-picture), operational (campaigns and actors) and tactical (specific IOCs and TTPs).

Why are TTPs more valuable than IOCs?

IOCs (like IPs/hashes) change easily; TTPs describe durable adversary behaviour that's harder for attackers to alter.

Related guides

Practise what you've learned

Turn this guide into real, evidenced progress

Missiora helps you measure, improve and evidence the capabilities employers actually value — start with the tools best suited to this topic.

M
Published by
Missiora

Missiora is an AI Employability Intelligence platform. Our resources are researched and reviewed by the Missiora team to help you measure, improve and prove your career readiness.