Security · Intelligence

Threat Intelligence

Knowing who is likely to come for you and how they operate — and turning that into detections rather than a newsletter.

Security
01

Intelligence, Not Information

Threat intelligence is information about adversaries that has been analysed for your context and can change a decision. A feed of ten thousand malicious IP addresses is data; knowing that a group targeting your sector uses a technique your estate cannot detect is intelligence.

LevelAudienceAnswers
StrategicExecutivesWho is likely to target us and why — drives investment
OperationalSecurity leadershipWhich campaigns and techniques are active now
TacticalAnalysts and engineersSpecific behaviours and indicators to detect
The test for any intelligence programme is whether it changed something: a new detection, a patch prioritised, a control added. If the output is a report nobody acts on, it is a subscription rather than a capability.
02

Indicators Versus Behaviours

The Pyramid of Pain ranks what you can detect by how much it costs the adversary to change. Blocking a hash is trivially defeated; detecting the technique forces them to change how they work.

Detect onCost to the adversary
File hashesTrivial — recompile
IP addressesEasy — new infrastructure
Domain namesSimple — register another
Network or host artefactsAnnoying — retooling required
ToolsChallenging — build or buy new ones
Tactics and techniquesGenuinely hard — change how they operate
Indicators still have a place: they are cheap, fast and catch commodity attacks. The mistake is stopping there, because indicator-only detection expires the moment the adversary rotates infrastructure.
03

MITRE ATT&CK

ATT&CK is a public catalogue of adversary tactics and techniques observed in the real world, organised by objective — initial access, persistence, privilege escalation, lateral movement, exfiltration, impact.

Used forHow
Coverage mappingWhich techniques do we detect, and where are the holes
Common languageOne vocabulary across intel, detection and red team
PrioritisationFocus on techniques used by groups targeting your sector
Hunt planningPick a technique and go looking for it
Purple teamingEmulate a technique, verify the detection fires
A coverage heat map is a planning aid, not a scorecard. Claiming coverage of a technique because a rule exists means little until someone emulates the technique and confirms the alert actually fires.
04

The Intelligence Lifecycle

StageDetail
DirectionWhat do we actually need to know, and who asked
CollectionFeeds, sharing communities, vendor reporting, internal incidents
ProcessingNormalise, deduplicate, enrich with internal context
AnalysisWhat does this mean for us, specifically
DisseminationTo the people who can act, in a form they can use
FeedbackWas it useful — refine the direction

Your own incidents are the highest-quality source you have. They are unquestionably relevant to your estate, and the detections they produce are already tuned to your environment.

05

Making It Operational

PracticeEffect
Feed indicators into detection automaticallyRemoves the copy-and-paste step that never happens
Enrich alerts with intelligence contextAnalysts triage faster with attribution and known behaviour
Map detections to ATT&CKGaps become visible and plannable
Prioritise by sector relevanceIgnore campaigns that will never target you
Share back through communitiesSector sharing groups are reciprocal by design
Attribution is difficult, frequently wrong, and rarely changes what you should do. Naming a group is interesting; detecting the technique is what protects you.
06

Interview Questions

What separates intelligence from information?

Analysis for your context and the ability to change a decision. A raw feed of indicators is data; knowing a technique used against your sector is undetectable in your estate is intelligence.

Strategic, operational, tactical — the difference?

Strategic informs executive investment, operational describes active campaigns for security leadership, tactical gives analysts specific behaviours and indicators to detect.

Why prefer behaviours over indicators?

Hashes, IPs and domains are trivially changed. Detecting tactics and techniques forces an adversary to change how they operate, which is genuinely expensive.

What is MITRE ATT&CK used for?

A shared vocabulary and a catalogue of real techniques — used to map detection coverage, prioritise by relevant threat groups, plan hunts and validate detections through emulation.

What is the best source of intelligence?

Your own incidents. They are unquestionably relevant and produce detections already tuned to your environment.

How much does attribution matter?

Less than people assume. It is hard, often wrong, and rarely changes the defensive action — detecting the technique does.

Quick Quiz

1. The hardest thing for an adversary to change is…
2. Tactical intelligence is aimed at…
3. MITRE ATT&CK is best used to…
4. The highest-quality intelligence source is usually…
5. An intelligence programme is working when…