Cyber threat intelligence (CTI) is information about attackers, their goals, their methods and the tools and infrastructure they use, collected and analyzed so that an organization can make better security decisions. It turns raw data, such as suspicious IP addresses or file hashes, into context: who is behind an activity, which industries and systems they target, and what defenders should do about it.
Not to be confused with Computer Telephony Integration, which is also abbreviated CTI: linking phone systems with business software such as a CRM.
At a glance
- CTI is analyzed, contextual information about threats, not just lists of bad addresses or files.
- It is usually described at three levels: strategic (for leadership), tactical and operational (attacker behavior and campaigns), and technical (indicators tools can consume).
- Sources include commercial providers, government advisories, industry sharing groups, security vendors’ research and your own incidents.
- Its value comes from use: prioritizing patches, enriching alerts, tuning detections and informing risk decisions.
- Most mid-sized organizations consume CTI through their security tools and service providers rather than producing it themselves.
What problem it solves
Security teams face more alerts, vulnerabilities and headlines than they can act on. Without context, every alert looks equally urgent and every newly disclosed vulnerability seems to need patching tonight. Attackers, meanwhile, tend to reuse methods and target particular industries and technologies.
Threat intelligence narrows the field. It tells defenders which vulnerabilities are being exploited, which ransomware and phishing campaigns are active against organizations like theirs, and what those attackers do once inside. That helps analysts decide which alerts to investigate first, helps IT decide which patches can’t wait, and gives leadership a grounded view of risk rather than a reaction to the news.
How it works
CTI is usually produced in a repeating cycle:
- Direction. Decide what you need to know, for example which threats target your industry, or whether a newly reported campaign affects your technology.
- Collection. Gather data from commercial feeds, open sources, government and industry advisories, information sharing and analysis centers (ISACs), vendor research and internal logs and incidents.
- Processing and analysis. Remove duplicates and noise, connect related findings and assess what they mean. Analysts often describe attacker behavior as tactics, techniques and procedures (TTPs), commonly mapped to the MITRE ATT&CK framework.
- Dissemination. Deliver results in a form each audience can use: briefings for leadership, reports for analysts, and machine-readable indicators of compromise (IOCs) for tools.
- Feedback. Users report what helped, and requirements are adjusted.
In practice, technical intelligence is fed into SIEM, SOAR, EDR and XDR tools, firewalls and email security, where it enriches alerts and blocks known-bad activity. Analysts also use it to guide threat hunting.
When it matters for buyers
- When comparing detection tools and services. Ask what intelligence is built in, where it comes from and how it is kept current.
- When choosing a managed security provider. Providers that see many customers can apply intelligence from one incident across others; ask how they do it.
- When buying feeds or platforms. More feeds create more noise unless someone uses them; budget for the people or service that will act on the intelligence.
- When prioritizing vulnerabilities. Knowing which flaws are being actively exploited is one of the most practical uses of CTI.
- When briefing leadership. Strategic intelligence helps explain which threats are relevant to the business and why.
Most organizations put threat intelligence to work through their detection stack; see our extended detection and response (XDR) overview.
Questions to ask vendors
- What are your intelligence sources, and how much is your own research versus aggregated feeds?
- How quickly do new indicators and detections reach our tools?
- How is intelligence tailored to our industry, region and technology?
- How do you measure accuracy and limit false positives from indicators?
- In what formats and through which integrations do you deliver intelligence?
- Who on your side analyzes intelligence, and can we ask them questions?
How it differs from a threat intelligence platform (TIP)
Cyber threat intelligence is the information and analysis itself. A threat intelligence platform (TIP) is software that collects intelligence from many sources, removes duplicates, scores it and distributes it to security tools and analysts. A TIP helps manage intelligence but doesn’t create insight on its own; it is only as good as the sources fed into it and the people using it. Many mid-sized organizations don’t need a separate TIP because their SIEM, XDR or managed service provider handles intelligence for them.
