Summary
This chapter has covered the most prevalent threat intelligence frameworks that a good threat analyst should know. We explained the general concept of threat intelligence frameworks and why it is important to integrate them into cyber threat intelligence programs. The analyst should know more about the frameworks to select the most appropriate one for an intelligence task. However, a few parameters can be looked at when choosing an intelligence framework. The more practical ones include how deep the framework goes into analyzing threats, what the scope of the framework is (what kinds of threats does it cover – cloud, enterprise, mobile?), how often the framework is updated to accommodate new threats, how easy it is to integrate into a threat intelligence program, and how easy it is to understand its overall structure. In the next chapter, we review the tradecrafts and standards of threat intelligence.