Skip to content

CTI fundamentals

Cyber Threat Intelligence (CTI) turns threat data into actionable knowledge for better decisions: who to defend against, how, and with what priority. It’s not a list of IOCs; it’s an analysis process that answers business and defense questions.

Data a hash, an IP -> raw, no context
Information "this IP is a C2" -> processed data
Intelligence "group X, which targets YOUR sector, uses this C2 and this TTP; prioritize Y"
-> analyzed information + context + an actionable recommendation
# CTI answers: who's attacking me, how, why, and what do I do about it?
Strategic trends, actors, sector risk; for management/CISO (decisions)
Operational campaigns and TTPs of specific adversaries; for the SOC and hunting
Tactical specific IOCs and TTPs; for detection and blocking (def-deteccion)
Technical concrete artifacts (hashes, C2); short-lived, feed controls
1. DIRECTION define requirements (PIR): what does the organization need to know?
2. COLLECTION sources: OSINT, feeds, ISAC, dark web, own telemetry, internal IR
3. PROCESSING normalize, translate, deduplicate, structure (STIX)
4. ANALYSIS turn into intelligence: context, assessment, confidence
5. DISSEMINATION deliver to the right consumer in a useful format (see cti-informes)
6. FEEDBACK did it help? adjust requirements -> the cycle repeats
OSINT vendor blogs, public reports, social media, repositories
Feeds commercial and open (MISP, AlienVault OTX, abuse.ch)
ISAC/ISAO sector sharing (finance, health, energy...)
Internal your own telemetry and IR -> the MOST relevant intelligence for you
Dark web forums, markets, leaks (with legal care and OPSEC)
STIX structured format to describe threats (indicators, TTPs, actors)
TAXII transport/sharing protocol for CTI
MISP platform to share and exchange indicators between organizations
TLP Traffic Light Protocol: marks who it can be shared with (RED/AMBER/GREEN/CLEAR)
  • Start from requirements (PIR): intelligence with no business question is noise.
  • Prioritize your own intelligence (IR, telemetry) and the actors targeting your sector.
  • Operationalize: CTI feeds detection (Detection & logging), hunting (Threat hunting), and vuln management (Vulnerability management).
  • Measure relevance and actionability, not feed volume; respect TLP when sharing.
  • Vendor reports (Mandiant, CrowdStrike, Microsoft) on APTs are reference strategic/operational CTI.
  • ISACs (e.g. FS-ISAC in finance) have enabled coordinated sector responses to campaigns.
  • Open feeds (abuse.ch, OTX) and MISP sustain tactical sharing between organizations.
  • Intelligence requirements (PIR) defined by the business
  • Sources selected (OSINT, feeds, ISAC, internal)
  • Processing and structuring (STIX/MISP)
  • Analysis with context and confidence level
  • Dissemination to the right consumer (see Intelligence reporting)
  • Operationalize into detection/hunting/vulnmgmt
  • Respect TLP when sharing; feedback and cycle improvement