What Is CTI (Cyber Threat Intelligence)?

Also called: Threat intelligence

Related problems: Security tools flag thousands of alerts with no context on which ones matter; Don't know which threats actually target our industry; Paying for threat feeds that nobody uses; Board asking how exposed we are to the latest attack in the news

Cyber threat intelligence (CTI) is information about attackers, their goals, their methods and the tools and infrastructure they use, collected and analyzed so that an organization can make better security decisions. It turns raw data, such as suspicious IP addresses or file hashes, into context: who is behind an activity, which industries and systems they target, and what defenders should do about it.

Not to be confused with Computer Telephony Integration, which is also abbreviated CTI: linking phone systems with business software such as a CRM.

At a glance

  • CTI is analyzed, contextual information about threats, not just lists of bad addresses or files.
  • It is usually described at three levels: strategic (for leadership), tactical and operational (attacker behavior and campaigns), and technical (indicators tools can consume).
  • Sources include commercial providers, government advisories, industry sharing groups, security vendors’ research and your own incidents.
  • Its value comes from use: prioritizing patches, enriching alerts, tuning detections and informing risk decisions.
  • Most mid-sized organizations consume CTI through their security tools and service providers rather than producing it themselves.

What problem it solves

Security teams face more alerts, vulnerabilities and headlines than they can act on. Without context, every alert looks equally urgent and every newly disclosed vulnerability seems to need patching tonight. Attackers, meanwhile, tend to reuse methods and target particular industries and technologies.

Threat intelligence narrows the field. It tells defenders which vulnerabilities are being exploited, which ransomware and phishing campaigns are active against organizations like theirs, and what those attackers do once inside. That helps analysts decide which alerts to investigate first, helps IT decide which patches can’t wait, and gives leadership a grounded view of risk rather than a reaction to the news.

How it works

CTI is usually produced in a repeating cycle:

  1. Direction. Decide what you need to know, for example which threats target your industry, or whether a newly reported campaign affects your technology.
  2. Collection. Gather data from commercial feeds, open sources, government and industry advisories, information sharing and analysis centers (ISACs), vendor research and internal logs and incidents.
  3. Processing and analysis. Remove duplicates and noise, connect related findings and assess what they mean. Analysts often describe attacker behavior as tactics, techniques and procedures (TTPs), commonly mapped to the MITRE ATT&CK framework.
  4. Dissemination. Deliver results in a form each audience can use: briefings for leadership, reports for analysts, and machine-readable indicators of compromise (IOCs) for tools.
  5. Feedback. Users report what helped, and requirements are adjusted.

In practice, technical intelligence is fed into SIEM, SOAR, EDR and XDR tools, firewalls and email security, where it enriches alerts and blocks known-bad activity. Analysts also use it to guide threat hunting.

When it matters for buyers

  • When comparing detection tools and services. Ask what intelligence is built in, where it comes from and how it is kept current.
  • When choosing a managed security provider. Providers that see many customers can apply intelligence from one incident across others; ask how they do it.
  • When buying feeds or platforms. More feeds create more noise unless someone uses them; budget for the people or service that will act on the intelligence.
  • When prioritizing vulnerabilities. Knowing which flaws are being actively exploited is one of the most practical uses of CTI.
  • When briefing leadership. Strategic intelligence helps explain which threats are relevant to the business and why.

Most organizations put threat intelligence to work through their detection stack; see our extended detection and response (XDR) overview.

Questions to ask vendors

  • What are your intelligence sources, and how much is your own research versus aggregated feeds?
  • How quickly do new indicators and detections reach our tools?
  • How is intelligence tailored to our industry, region and technology?
  • How do you measure accuracy and limit false positives from indicators?
  • In what formats and through which integrations do you deliver intelligence?
  • Who on your side analyzes intelligence, and can we ask them questions?

How it differs from a threat intelligence platform (TIP)

Cyber threat intelligence is the information and analysis itself. A threat intelligence platform (TIP) is software that collects intelligence from many sources, removes duplicates, scores it and distributes it to security tools and analysts. A TIP helps manage intelligence but doesn’t create insight on its own; it is only as good as the sources fed into it and the people using it. Many mid-sized organizations don’t need a separate TIP because their SIEM, XDR or managed service provider handles intelligence for them.

Frequently Asked Questions

What is the difference between threat data and threat intelligence?
Threat data is raw: lists of malicious IP addresses, domains or file hashes. Threat intelligence adds analysis and context, such as who is using those indicators, in what campaigns, against which industries, and what you should do about it.
Do we need a dedicated threat intelligence team?
Most mid-sized organizations don't. They get intelligence built into their security tools, from their managed detection and response or security operations provider, and from industry sharing groups. A dedicated team makes sense when you have a mature security operation that can act on what it produces.
What are the types of threat intelligence?
It is commonly grouped into strategic intelligence for leadership (trends, motives, risk), tactical or operational intelligence on attacker behavior and campaigns, and technical indicators that tools can use directly. Definitions vary between sources, but the point is matching the intelligence to who will use it.
Where does threat intelligence come from?
Sources include commercial providers, open-source reporting, government advisories, industry sharing groups such as ISACs, security vendors' research, and your own incidents and logs. Quality varies, so judge sources by how accurate, timely and relevant they are to you.
How do we know threat intelligence is worth paying for?
Tie it to decisions. Useful intelligence changes something: which vulnerabilities you patch first, which alerts analysts investigate, which detection rules you add. If a feed or report doesn't change any decisions, it isn't earning its cost.

Related Terms

Computer Telephony Integration (CTI)

Linking the phone system with CRM and other software for screen pops, click-to-call and call logging.

Threat Intelligence Platform (TIP)

Software that gathers, scores and distributes threat intelligence to security tools and analysts.

Indicators of Compromise (IOC)

Evidence such as malicious IPs, domains or file hashes that suggests a breach.

Tactics, Techniques and Procedures (TTP)

How attackers operate: their goals, methods and specific steps.

Threat Hunting

Proactively searching for hidden attackers that automated alerts missed.

Information Sharing and Analysis Center (ISAC)

A sector-based member group where organizations share cyber threat information and warnings.

Security Information and Event Management (SIEM)

Collects and correlates security logs to detect, investigate and report on threats.

Security Orchestration, Automation, and Response (SOAR)

Software that connects security tools and automates alert triage and response with playbooks.

Advanced Persistent Threat (APT)

A skilled, targeted attacker that tries to stay hidden in a network long term.

Attack Surface Management (ASM)

Continuously finding and monitoring everything you expose to the internet.

Phishing

A scam that impersonates a trusted sender to steal credentials, money or access.

Ransomware

Malware that locks you out of your systems or data until you pay.

Malware

Any software built to damage, spy on or take over systems and data.

Digital Risk Protection Services (DRPS)

External monitoring for brand impersonation, leaked data and credentials, often with takedown help.

MITRE ATT&CK Framework

A public catalog of attacker tactics and techniques, used as a common security vocabulary.

More Security terms

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.