Last updated: April 29, 2026
Why this module exists. Threat intelligence is one of the most-purchased and least-utilised security investments. Companies subscribe to feeds that nobody reads, vendor reports that nobody actions. Done well, TI shapes detection, prioritisation, and strategy. Done badly, it’s expensive noise.
The three altitudes of TI
| Type | Audience | Outputs | Cadence |
|---|---|---|---|
| Strategic | Executives, board | Threat landscape, risk-driven prioritisation, geopolitical context | Quarterly |
| Operational | SOC leadership, IR | Campaign-specific intel, TTP analyses, victim-organisation patterns | Weekly to ad-hoc |
| Tactical | SOC analysts, automated detections | IOCs (IPs, domains, hashes), Sigma rules, YARA rules | Real-time |
Each requires different sources, different skills, different consumption patterns.
Strategic TI — what it answers
- Which threat actors target organisations like ours?
- What are their typical TTPs?
- What’s the trend over the last 12 months?
- What investments would meaningfully reduce risk?
Sources: Mandiant M-Trends, CrowdStrike Global Threat Report, Microsoft DSR, IBM X-Force, ENISA Threat Landscape, regional reports (CERT-In bulletins, NCIIPC). Read 2-4 of these annually + relevant updates.
Operational TI — what it answers
- Is this campaign targeting us right now?
- What TTPs is the actor using? Do our detections cover them?
- What other organisations should we coordinate with?
Sources: ISACs (FS-ISAC for finance, H-ISAC for healthcare; India equivalents emerging), threat-intel platforms (Mandiant, Recorded Future, RST Threat Feed), trusted peer networks.
Tactical TI — what it answers
- Should we block this IP, this domain, this hash?
- Should we add this signature to our IDS / EDR / SIEM?
Sources: paid feeds, free feeds, vendor blocklists, internal IOC database from past incidents.
The TI lifecycle
- Direction — what intelligence questions need answering?
- Collection — sources to gather from.
- Processing — normalisation, deduplication, contextualisation.
- Analysis — what does it mean? So what?
- Dissemination — to the right audience in the right form.
- Feedback — what was useful? What wasn’t? Iterate.
The vendor-feed problem
Bought a feed of “1 million IOCs daily.” Now what?
- If you add all to blocklist → tens of false positives daily; users complain; SOC overwhelmed.
- If you ignore → wasted money.
- Right answer: ingest into TIP (Threat Intelligence Platform) like MISP / OpenCTI / Anomali; enrich your alerts with reputation; surface high-confidence matches.
The pyramid of pain (revisited)
From Module 6: hunt for TTPs > tools > artefacts > domains > IPs > hashes. Same applies to TI:
- Tactical IOC feeds (IPs, hashes) age out within days. Useful for retroactive search; less for prevention.
- TTP-level intel (e.g., “actor X uses living-off-the-land binaries via WMI”) drives durable detection rules.
Indian-context TI sources
- CERT-In — advisories, vulnerability notes, sectoral alerts
- NCIIPC — for critical-infrastructure entities
- Sectoral CERTs — RBI’s IDRBT for banking, etc.
- DSCI — Data Security Council of India publications
- India-region threat reports — Recorded Future, Mandiant occasionally publish regional analysis
- Open feeds — abuse.ch, ThreatFox, Phishtank
Measuring TI value
- IOC match rate — % of TI IOCs that ever matched in your environment. Low = noisy feed; cancel it.
- Detections sourced from TI — how many of your active rules came from TI input?
- Alerts enriched by TI — % of alerts where TI added context.
- Strategic decisions — security investments that traced back to TI insights.
Defender’s checklist
- TI requirements documented — what questions need answers?
- Curated source list — quality over quantity. 3-5 great sources beat 30 mediocre ones.
- TIP deployed (MISP / OpenCTI / commercial) — ingestion + enrichment + sharing.
- Auto-enrichment in SOAR — every alert gets TI context.
- Strategic TI report quarterly to executives.
- Membership in relevant ISAC for your sector.
- Source ROI review annually — drop low-value feeds.
Module Quiz · 6 questions
Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.