Skip to content
CIM-024 Cyber Incidents & Offender Methods

What is threat intelligence?

Threat intelligence is information assessed to help understand malicious activity, infrastructure, tools, methods or threat actors.

Avoid the dangerous assumption

The dangerous assumption is that threat intelligence is direct proof of who committed the activity in your investigation.

It is not.

Threat intelligence may include known malicious IP addresses or domains, file hashes, malware characteristics, phishing infrastructure, observed techniques, criminal service information, assessments about groups or campaigns or reports from previous incidents.

It can come from government, commercial providers, industry groups, internal investigations or open sources.

Its value depends on source, age, specificity, confidence and relevance.

An intelligence report may help explain why an alert was generated, identify related infrastructure, suggest likely methods or support preservation requests. It may also help investigators recognise patterns not visible from one incident alone.

But intelligence often contains assessment rather than direct observation. Labels such as “associated with”, “linked to”, “used by” or “attributed to” may reflect different confidence levels.

Ask what source supports the intelligence, when the information was collected, whether the infrastructure was shared, whether the assessment is current, what confidence is stated and whether the intelligence relates to the same incident or only a similar method.

Threat intelligence should guide enquiries, not close them prematurely.

A domain used in one campaign may later be repurposed. Malware may be copied by several groups. A technique may be common across many offenders.

Preserve the intelligence product and its metadata, but separate its assessment from the direct records in your case.

Operational takeaway

Use threat intelligence to generate and prioritise lines of enquiry, while keeping its assessments separate from direct evidence of activity in the incident.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.