Threat Intelligence: Types, sources, and how to use it in your organization
Threat feeds can give security teams thousands of indicators, alerts, vulnerability notices, and reports. But a long list of KRIs does not automatically tell you which threats matter to your organization.
Threat intelligence adds context to threat information so security teams can understand what attackers are doing, which threats are relevant, and what action to take. NIST defines threat intelligence as threat information that has been aggregated, transformed, analyzed, interpreted, or enriched to support decision-making.
The difference matters. A suspicious IP address is threat data. Knowing that the address appears in a campaign targeting your industry and using techniques relevant to your environment gives your team information it can act on.
- What is threat intelligence?
- Where does threat intelligence come from?
- How threat intelligence is analyzed
- How to turn threat data into actionable intelligence
- How CyberArrow supports threat-informed risk management
- FAQs
- What is the difference between threat data and threat intelligence?
- What are common sources of threat intelligence?
- How does threat intelligence support vulnerability management?
- How does threat intelligence support incident response?
- What makes threat intelligence actionable?
- How does threat intelligence differ from risk intelligence?
What is threat intelligence?
Threat intelligence analyzes information about cyber threats, threat actors, attack techniques, vulnerabilities, and campaigns, providing context for security decisions.
NIST’s guidance includes indicators of compromise, threat actor tactics, techniques, and procedures (TTPs), security alerts, threat intelligence reports, and incident analysis among the types of threat information organizations can use.
The key distinction between threat information and threat intelligence is:
- Threat data: Raw observations such as an IP address, domain, file hash, or vulnerability identifier.
- Threat information: Data that has been organized or interpreted to describe a threat.
- Threat intelligence: Analyzed and enriched information that gives you enough context to make a decision.
For example, a vulnerability alert might indicate that attackers are exploiting a specific flaw. Threat intelligence provides information on the affected technology, attack methods, targeted industries, active campaigns, and indicators of exploitation.
What are the types of threat intelligence?
Threat intelligence generally falls into four categories based on the decisions it supports.
| Types | Focus | Usage |
| Strategic | Long-term threat trends, actors, and geopolitical or industry developments. | Security strategy and executive decisions |
| Tactical | Adversary techniques, tactics, and procedures | Security controls and defensive planning |
| Operational | Specific campaigns, incidents, and threat activity | Threat investigations and incident preparation |
| Technical | Indicators such as IP addresses, domains, hashes, and malicious artifacts | Detection and blocking |
These categories can overlap. A single threat report may contain strategic context about an actor, tactical information about its techniques, and technical indicators that a security team can use for detection.
Where does threat intelligence come from?
Start with the intelligence you actually need, then choose sources that can answer those questions. Collecting every available feed creates more data without necessarily producing better intelligence.
Internal sources
Your own environment can provide valuable threat information, including:
- Security alerts.
- Incident investigations.
- Endpoint telemetry.
- Network activity.
- Authentication logs.
- Malware analysis.
- Vulnerability findings.
- Previous threat-hunting results.
Internal data tells you what is happening within your environment and provides external intelligence with the context it needs.
External sources
External sources can provide information about threats your organization may encounter:
- Government cyber security advisories.
- Computer emergency response teams.
- Security researchers.
- Industry information-sharing groups.
- Threat intelligence providers.
- Vulnerability databases.
- Malware and campaign research.
- Security vendor reports.
NIST recommends establishing information-sharing goals, identifying relevant sources of cyber threat information, defining the scope of sharing activities, and establishing rules for how threat information is distributed and used.
How threat intelligence is analyzed
Threat intelligence becomes useful when analysts turn disconnected pieces of information into a coherent picture.
Use a process such as:
Collect → Validate → Enrich → Correlate → Analyze → Distribute → Act
1. Collect relevant information
Gather data based on your intelligence requirements rather than subscribing to every possible source. For example, if your organization relies heavily on Microsoft technologies, intelligence about threats targeting those technologies may have more immediate value than unrelated threat reports.
2. Validate the information
Check whether the information is accurate, current, and relevant before acting on it. For an indicator, examine its source, age, confidence, and relationship to known malicious activity. Don’t automatically block every IP address or domain that appears in a feed.
3. Enrich the data
Add context from other sources. An IP address might become more useful when you know:
- Which threat actor has used it.
- Which campaign it relates to.
- When it was observed.
- What activity it supported.
- Which industries it targeted.
- Which TTPs appeared alongside it.
4. Correlate related activity
Look for connections between indicators, vulnerabilities, threat actors, campaigns, and techniques. For example, several seemingly unrelated alerts may point to the same attack campaign when they share infrastructure or TTPs.
5. Analyze the threat
Determine what the information means for your organization. Ask:
- Does this threat target our industry?
- Does the attacker use technologies we operate?
- Do we have the affected vulnerability?
- Does the activity match anything we’ve observed?
- Which assets could be exposed?
- What defensive action should we take?
6. Distribute the intelligence
Send the right information to the team that can act on it. A SOC analyst may need indicators and TTPs. A vulnerability management team may need exploitation information about a specific CVE. Security leadership may need a summary of an emerging campaign and its potential effect on the organization.
NIST’s threat-information guidance emphasizes sharing information in ways that support identification, assessment, monitoring, and response to cyber threats.
How to turn threat data into actionable intelligence
Threat data becomes useful when you connect it to your own environment and use it to answer a specific security question.
For example, suppose security researchers report active exploitation of a vulnerability affecting a VPN product.
- Start with the external threat data: You learn that attackers are exploiting the vulnerability and that the attacks involve a specific set of techniques and indicators.
- Check whether it applies to you: Your asset inventory shows that your organization runs the affected VPN product. Two instances are internet-facing, and one provides remote access for employees.
- Enrich the finding: Threat reports indicate that attackers are exploiting the vulnerability to gain initial access and have identified specific IP addresses and attack patterns associated with the activity.
- Assess what you need to do: Your security team checks whether the vulnerable versions are deployed, whether the relevant indicators appear in network or endpoint telemetry, and whether existing controls reduce the exposure.
Take action
Patch the affected VPN instances, investigate relevant telemetry for signs of exploitation, add known indicators or behaviors to detection rules, and increase monitoring until remediation is verified.
This is what makes the information actionable: threat intelligence. You don’t stop at knowing that a threat exists. You determine whether it affects your environment and translate the finding into a specific security response.
How CyberArrow supports threat-informed risk management
CyberArrow can help connect threat-related findings with the broader GRC processes that teams use to manage risk.
- Risk management: Record and track risks identified from threat intelligence.
- Vulnerability management: Connect threat activity with affected assets and vulnerabilities.
- Control mapping: Map relevant controls across multiple frameworks.
- Incident management: Connect threat findings with incidents and response activities.
- Third-party risk: Track security risks associated with suppliers and service providers.
- Evidence management: Keep supporting evidence connected to risks, controls, and remediation activities.
- Reporting: Give security and risk teams visibility into threat-related exposure and treatment.
Turn threat intelligence into actionable risk management with CyberArrow.
FAQs
What is the difference between threat data and threat intelligence?
Threat data consists of raw observations such as IP addresses, domains, hashes, or vulnerability information. Threat intelligence analyzes and enriches that information to provide context for a security decision.
What are common sources of threat intelligence?
Sources include internal security telemetry and incident data, government advisories, security researchers, industry information-sharing groups, vulnerability databases, threat intelligence providers, and security research reports.
How does threat intelligence support vulnerability management?
Threat intelligence can show whether attackers are actively exploiting a vulnerability, which threat actors use it, and whether the activity targets your industry or technology. Teams can use that context alongside asset exposure and business criticality to prioritize remediation.
How does threat intelligence support incident response?
Incident responders can use intelligence about threat actors, campaigns, malware, infrastructure, and TTPs to investigate suspicious activity, identify related indicators, and understand the techniques involved in an incident.
What makes threat intelligence actionable?
Actionable intelligence connects threat information to a specific decision or security activity. It should tell the relevant team what the threat means for the organization and what action they need to consider.
How does threat intelligence differ from risk intelligence?
Threat intelligence focuses on threats, threat actors, campaigns, vulnerabilities, and attacker behavior. Risk intelligence combines threat information with organizational context and other risk data to support broader risk decisions.