Understanding threat intelligence reporting
Threat intelligence reports are documents that detail attacks, indicators, campaigns, adversaries (for example, threat actors), TTPs, and target system information. They represent a well-structured form of threat information, supporting business decisions (actionable intelligence). Internal security functions (such as forensics, incident response, fraud, and patch management teams) can use threat intelligence reports to facilitate their tasks. A CTI analyst needs to understand the two types of threat intelligence reports.
Types of threat intelligence reports
Based on its characteristics and content, there are two types of CTI reports that can be actionable and used by other teams: threat landscape reports that provide global threat awareness and threat analysis reports that provide details of performed threat analyses.
The threat landscape report
Understanding the threat landscape is a crucial part of a CTI analyst job. The...