NEONIX SECURITY FABRICEXPOSURE / APPLICATION / IDENTITY
Security research

Research note · Threat intelligence

Threat intelligence

What threat intelligence is, the four levels teams use it at, and how to make it change decisions instead of filling a feed.

Type
Overview and practical guidance
Related products
Cybrmonk

Overview

Threat intelligence is information about who is attacking, how they work and what they target, shaped so that a team can make a decision with it. Information that does not change a decision is data, not intelligence.

The common failure is volume without context: feeds of indicators arrive faster than anyone can judge which ones matter to this organization.

Key concepts

  1. 01

    Four levels

    Strategic intelligence informs leaders about trends and risk. Operational intelligence describes campaigns and actor intent. Tactical intelligence covers techniques and procedures. Technical intelligence is the indicators, such as addresses, domains and file hashes.

  2. 02

    Indicators age, behavior lasts

    Indicators of compromise expire as attacker infrastructure changes. Tactics, techniques and procedures describe how an actor works and stay useful longer, so detection built on behavior ages better.

  3. 03

    The intelligence cycle

    Direction, collection, processing, analysis, dissemination and feedback. Skipping direction, the step where a team decides what it needs to know, is the usual reason feeds go unread.

  4. 04

    Context makes it actionable

    An indicator matters when it is tied to something you own: an asset, a brand, a credential or a supplier.

What good looks like

  • Write down the three or four questions intelligence should answer for your organization.
  • Tie every source to an owner and to a decision it supports.
  • Prefer behavior-based detection over indicator lists where you can.
  • Feed what you learn from incidents back into collection.

Common pitfalls

  • Adding feeds instead of defining requirements.
  • Treating every indicator as equally urgent.
  • Never sharing back, so the process never improves.

How Neonix helps

Cybrmonk brings threat actor, dark web, ransomware and CVE intelligence together with the asset view, so intelligence arrives attached to what it affects.

Prioritized context can be delivered to SIEM and SOAR workflows for response.

This note is an overview of the topic and of how Neonix approaches it. It does not report original incident data.