Cyber Threat Intelligence (CTI) turns raw data about threats into decisions — helping you defend against the attackers most likely to target you. It's the strategic partner to threat hunting and the SOC.
The Threat Intelligence Cycle
Turning raw data into actionable defence.
Tap or hover a part to learn more.
What to know.
Define the intelligence requirements: which threats and questions matter to your organisation and sector.
Check your understanding
1. What are the levels of threat intelligence?
2. Why value TTPs over IOCs?
Keep learning
The essentials
- The intelligence lifecycle — direction → collection → processing → analysis → dissemination → feedback.
- Levels — strategic (big-picture, for leadership), operational (campaigns/actors) and tactical (specific IOCs and TTPs for defenders).
- IOCs vs TTPs — indicators are perishable; TTPs (behaviours) are more durable and valuable.
- Frameworks — MITRE ATT&CK and the Diamond Model structure analysis.
- Feeds & sharing — commercial, open-source (OSINT) and community sharing (ISACs) feed the picture.
Good CTI makes defence proactive and prioritised rather than reactive.
