CTI fundamentals
Cyber Threat Intelligence (CTI) turns threat data into actionable knowledge for better decisions: who to defend against, how, and with what priority. It’s not a list of IOCs; it’s an analysis process that answers business and defense questions.
What intelligence is (and isn’t)
Section titled “What intelligence is (and isn’t)”Data a hash, an IP -> raw, no contextInformation "this IP is a C2" -> processed dataIntelligence "group X, which targets YOUR sector, uses this C2 and this TTP; prioritize Y" -> analyzed information + context + an actionable recommendation# CTI answers: who's attacking me, how, why, and what do I do about it?CTI levels
Section titled “CTI levels”Strategic trends, actors, sector risk; for management/CISO (decisions)Operational campaigns and TTPs of specific adversaries; for the SOC and huntingTactical specific IOCs and TTPs; for detection and blocking (def-deteccion)Technical concrete artifacts (hashes, C2); short-lived, feed controlsThe intelligence cycle
Section titled “The intelligence cycle”1. DIRECTION define requirements (PIR): what does the organization need to know?2. COLLECTION sources: OSINT, feeds, ISAC, dark web, own telemetry, internal IR3. PROCESSING normalize, translate, deduplicate, structure (STIX)4. ANALYSIS turn into intelligence: context, assessment, confidence5. DISSEMINATION deliver to the right consumer in a useful format (see cti-informes)6. FEEDBACK did it help? adjust requirements -> the cycle repeatsSources
Section titled “Sources”OSINT vendor blogs, public reports, social media, repositoriesFeeds commercial and open (MISP, AlienVault OTX, abuse.ch)ISAC/ISAO sector sharing (finance, health, energy...)Internal your own telemetry and IR -> the MOST relevant intelligence for youDark web forums, markets, leaks (with legal care and OPSEC)Standards and sharing
Section titled “Standards and sharing”STIX structured format to describe threats (indicators, TTPs, actors)TAXII transport/sharing protocol for CTIMISP platform to share and exchange indicators between organizationsTLP Traffic Light Protocol: marks who it can be shared with (RED/AMBER/GREEN/CLEAR)Blue Team / operation
Section titled “Blue Team / operation”- Start from requirements (PIR): intelligence with no business question is noise.
- Prioritize your own intelligence (IR, telemetry) and the actors targeting your sector.
- Operationalize: CTI feeds detection (Detection & logging), hunting (Threat hunting), and vuln management (Vulnerability management).
- Measure relevance and actionability, not feed volume; respect TLP when sharing.
Real-world cases
Section titled “Real-world cases”- Vendor reports (Mandiant, CrowdStrike, Microsoft) on APTs are reference strategic/operational CTI.
- ISACs (e.g. FS-ISAC in finance) have enabled coordinated sector responses to campaigns.
- Open feeds (abuse.ch, OTX) and MISP sustain tactical sharing between organizations.
Testing checklist
Section titled “Testing checklist”- Intelligence requirements (PIR) defined by the business
- Sources selected (OSINT, feeds, ISAC, internal)
- Processing and structuring (STIX/MISP)
- Analysis with context and confidence level
- Dissemination to the right consumer (see Intelligence reporting)
- Operationalize into detection/hunting/vulnmgmt
- Respect TLP when sharing; feedback and cycle improvement