Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert

What is Threat Intelligence?

DefinitionThreat Intelligence is information about attackers, campaigns, techniques and indicators of compromise, collected and analyzed to support defense decisions, such as prioritizing risks, tuning detections and guiding incident response.

Data is not intelligence

A list of malicious IPs is data. It becomes intelligence when it is analyzed and put into context: who uses these IPs, against which sector, for what purpose and what it means for your company. ISO/IEC 27001:2022 added threat intelligence to the Annex A controls, reinforcing its role in security management.

Types of Threat Intelligence

  • Strategic: trends and motivations of threat groups, aimed at leadership and risk management.
  • Tactical: attackers' tactics, techniques and procedures (TTPs), usually described using MITRE ATT&CK.
  • Operational: details of specific ongoing campaigns, such as targets and attack windows.
  • Technical: indicators of compromise (IoCs), such as hashes, domains and IP addresses.

In practice

Intelligence only creates value when it is applied. In the SOC, it enriches alerts in SIEM and SOAR, feeds detection rules and guides threat hunting hypotheses. In vulnerability management, lists such as CISA's KEV catalog help prioritize flaws that are already being exploited. Sources include commercial and open feeds, industry communities, CERTs and the environment's own telemetry. Because IoCs change quickly, the greatest return usually comes from understanding behaviors (TTPs), which are harder for attackers to change.

Network Secure applies threat intelligence to its SOC's detections and threat hunting.

Frequently asked questions

What is the difference between Threat Intelligence and Threat Hunting?

Threat Intelligence is analyzed information about threats. Threat Hunting is the proactive search for signs of compromise in the environment, often starting from hypotheses built on that intelligence.

What is an IoC?

An indicator of compromise (IoC) is a technical trace of malicious activity, such as a file hash, a domain or an IP address used by attackers.

Go deeper