Glossary

Threat intelligence

Analyzed information about attacker groups, tools, and techniques used to anticipate and defend against threats, not just react to them.

Also called: cyber threat intelligence, CTI

Threat intelligence is information about active or emerging threats, attacker groups, their tools, infrastructure, and techniques, collected and analyzed to help an organization anticipate and defend against attacks rather than only react to them. It ranges from low-level technical feeds of indicator of compromise data to strategic reporting on which threat actors target a given industry and why.

Practitioners distinguish tactical intelligence, feeds and IOCs consumed automatically by a SIEM or endpoint detection and response tool, from operational intelligence about specific campaigns and strategic intelligence written for leadership decisions. Threat intelligence is frequently mapped against the MITRE ATT&CK framework so defenders can describe an attacker's behavior in a shared vocabulary rather than only listing indicators.

Threat intelligence matters because it lets a SOC prioritize defenses around threats actually relevant to the organization instead of treating every possible attack equally. A common pitfall is consuming intelligence feeds without a process to act on them: intelligence that never gets turned into a detection rule, a blocked domain, or a patched vulnerability provides no protection regardless of how current it is.

Last reviewed September 22, 2026

In the index now

Related terms

Related tools

Related guides