Understanding threat intelligence
Cyber threat intelligence (CTI) consists of the collection, analysis, correlation, and sharing of cybersecurity-related data from public and non-public data sources. The information retrieved through CTI is used not only to adapt and strengthen defenses but also to assess risk and justify funding for these improvements. Therefore, accurate and complete information retrieval is crucial for cybersecurity in enterprises and other organizations.
We can differentiate the following types of threat intelligence:
- Tactical: Tactical threat intelligence focuses on providing data about potential attacker activity. This means to gather data about malware, network traffic patterns, malicious URLs, phishing, and similar. The data is structured as tactics, techniques, and procedures (TTPs) and can be used to adjust the defensive security tools to provide optimal protection.
- Strategic: While tactical threat intelligence provides more particular and...