GlossarySOC and monitoring

Threat intelligence

Short answer

Threat intelligence is information about the attackers, techniques and indicators that are relevant to an organisation, collected and analysed so it can anticipate attacks, improve detection and prioritise defences. It ranges from strategic reports for management to technical data that security tools use directly.

Four levels

Strategic intelligence describes trends and threat actors for management decisions. Operational intelligence covers specific campaigns, such as a group targeting a sector. Tactical intelligence describes attacker techniques, usually mapped to the MITRE ATT&CK framework. Technical intelligence is the raw data, called indicators of compromise: malicious IP addresses, domains and file hashes.

Where it comes from

Sources include commercial feeds, security vendors, open source research, national CERTs such as INCIBE-CERT and CCN-CERT, sector sharing groups and the annual threat landscape reports from ENISA. Information that is not relevant to the business, or that nobody acts on, adds noise rather than value.

How it is used

Feeds of indicators are loaded into the SIEM, EDR and firewalls to block or alert on known threats. Tactical intelligence helps the SOC write detections for the techniques attackers actually use. News of an actively exploited zero day tells the team what to patch first.

Where it shows up in compliance

Threat intelligence became a control in ISO 27001:2022 (Annex A 5.7). NIS2 encourages information sharing between entities, and DORA includes threat information sharing as one of its five pillars.

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, SOC operations, detection engineering and incident handling.

Go to the topic hub