What Is Threat Intelligence?

On this page
  1. What are the levels of threat intelligence?
  2. How is threat intelligence used well?

Threat intelligence is evidence-based knowledge about adversaries — who they are, how they operate, and what they are after — analyzed so it can inform decisions. It is the difference between a list of bad IP addresses and an understanding of why those addresses matter to you. Done well, it points finite defensive effort at the threats that actually target your kind of organization.

What are the levels of threat intelligence?#

Intelligence serves different audiences at different time horizons:

LevelAudienceExample
StrategicLeadership”Ransomware groups increasingly target our sector”
OperationalDefenders / SOC”This actor uses spear-phishing then this toolkit”
TacticalTools / analystsSpecific hashes, domains, IOCs

The mistake is consuming only the tactical layer — feeds of indicators — while ignoring the operational context that makes them actionable, or the strategic view that guides investment.

How is threat intelligence used well?#

By making it relevant and actionable. Generic feeds create noise; intelligence about the actors who actually target your industry, mapped to MITRE ATT&CK techniques, tells you which detections to build first. It turns “there are infinite threats” into “these three techniques are our priority.”

Threat intelligence turns raw IOCs into prioritized risk decisions. More at the Security Fundamentals hub.

Frequently asked questions#

What is cyber threat intelligence?

Cyber threat intelligence is evidence-based knowledge about threats — who is attacking, how, and why — that is analyzed to inform security decisions. It goes beyond raw data like IP blocklists to add context: the actor, their motivation, and their techniques, so defenders can act on understanding rather than isolated alerts.

What are the levels of threat intelligence?

Strategic (high-level trends and risk for leadership), operational (specific campaigns and actor techniques for defenders), and tactical (concrete indicators like hashes and domains for tools). Each serves a different audience and time horizon, from board-level risk decisions down to feeding a firewall.

Sources & further reading