Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is threat intelligence?

Threat intelligence is assessed information about malicious infrastructure, tools, techniques, campaigns or actors.

It can help you recognise patterns, prioritise preservation and identify useful things to search for.

It should guide the investigation, not replace the incident evidence.

Intelligence can describe different things

It may contain:

  • IP addresses;
  • domains;
  • URLs;
  • file hashes;
  • malware characteristics;
  • phishing infrastructure;
  • certificates;
  • techniques;
  • campaign information;
  • threat-group assessments.

The source may be government, industry, a security vendor, internal cases or open reporting.

Provenance and age matter

Suppose intelligence says an IP address was associated with phishing infrastructure six months ago.

That does not automatically mean the same address was malicious in your incident today.

Infrastructure can be:

  • reassigned;
  • shared;
  • rented;
  • compromised;
  • reused by unrelated actors.
Example intelligence item
Indicator: 198.51.100.143Observed: 2026-06-12 to 2026-06-19Assessment: phishing infrastructureConfidence: mediumLocal incident match: 2026-09-14

That creates a useful question. It does not settle the answer.

Use intelligence to generate testable enquiries

Threat intelligence can help you:

  • search for related infrastructure;
  • identify known malware;
  • find similar events;
  • preserve related records;
  • explain why a detection fired;
  • prioritise systems for review.

Then test the local incident using its own source records.

Does a threat-intelligence match identify an offender? takes the attribution problem further.

The practical point is: threat intelligence gives you informed leads and context. Prove this incident from the records created by this incident.

Reference: CIM-024Cyber Incidents & Offender Methods