
Guide
What is cyber threat intelligence?
Threat intelligence is information analysed until it changes a decision. What NIST actually says, where the four types came from, and how to tell the two apart.
Cyber threat intelligence is information about attackers that has been analysed to the point where it changes a decision. Most products sold under the name stop before that point, which is not a scandal and is worth knowing before the invoice arrives. This guide sets out what the word means, who avoids using it and why, where the four types everybody repeats actually came from, and what the analysis step looks like when it is done on a real case rather than described in the abstract.
Last reviewed:
Cyber threat intelligence is information about attackers that has been analysed to the point where it changes a decision you were going to make anyway. That last clause is the whole subject. A feed of malicious domains is not intelligence, it is information; it becomes intelligence when somebody establishes what it means for a particular organisation and that organisation does something differently as a result.
Before the argument, the mechanism, because the words are easier to keep straight once you have watched them work on something ordinary.
The same three steps, on a cold morning and on a security problem
Look at what changes between the second and third columns. Nothing new is collected. Nobody goes out and gathers another fact. Somebody takes what is already sitting in the middle column, works out what it means for one particular reader with one particular problem, and says so plainly enough to act on.
That is the whole job, and it is why a feed cannot do it for you. The feed can fill the first two columns for thousands of items a second. It cannot fill the third, because the third column contains your delivery van, your payroll supplier, your firewall rule.
The distinction sounds pedantic until you notice who insists on it. The United States government's flagship publication in this space is NIST Special Publication 800-150, Guide to Cyber Threat Information Sharing, published in October 2016 by Johnson, Badger and Waltermire of NIST with Snyder and Skorupka of MITRE. It defines its subject like this:
Cyber threat information is any information that can help an organization identify, assess, monitor, and respond to cyber threats.
Read the title again. Information sharing. Across the whole document NIST does not use the phrase "cyber threat intelligence" as its term of art, and the definition it does give is deliberately broad: any information that can help. An industry that sells intelligence has spent a decade building on a foundation whose most cited government document carefully says information instead.
Europe went the other way, which is worth knowing if you buy from vendors on both sides of the Atlantic. ENISA, the European Union Agency for Cybersecurity, uses the term freely: its 2020 threat landscape series includes a dedicated Cyber Threat Intelligence Overview, it has published a study of threat intelligence platforms, and it runs an annual CTI conference. So the same activity is called information sharing in Washington and threat intelligence in Brussels, and neither is wrong. If a definition seems to shift depending on whose document you are reading, that is because it does.
It is worth being fair to NIST about why. SP 800-150 is a guide to sharing, and sharing is something you do with information. The moment a producer analyses something for a specific consumer, it stops being generally shareable, because the analysis is bound to that consumer's estate and risk appetite. The word choice is not an oversight or a criticism of the industry. It is a precise description of what can be passed between organisations, and it quietly marks the boundary this guide is about.
The commercial consequence is the part worth carrying into a procurement meeting. Information and intelligence are priced similarly, described in similar language, and are not substitutes for one another. A buyer comparing two products on coverage, update frequency and integration count is comparing two collection systems, which is a reasonable thing to do and tells you nothing about whether either will change a decision.

Information or intelligence: the test is whether it changes a decision
Most products sold as threat intelligence sit in one quadrant, and it is not the one the brochure implies.
Where a threat product actually sits
Raw feed
Domains, hashes and addresses at volume. Useful as input, and on its own it changes nothing.
Tuned detection
The same feed filtered to your stack and wired to an alert somebody owns. Specific, and it changes what your tooling does.
Vendor report
A well-written account of a campaign that may or may not touch you. Generic by design, and often excellent.
Intelligence
An assessment of what a threat means for your organisation, delivered to somebody who can act, with the uncertainty stated.
The bottom-left quadrant is not a criticism. A raw feed is a perfectly good product and every programme needs one. The failure is a budget line labelled threat intelligence that buys only the bottom left, and an annual review that never asks which decisions moved.
Notice also that the top right cell is the only one that cannot be bought as a product, because it is defined partly by your organisation. A vendor can get most of the way there with a well-run intelligence service that knows your sector and your stack, and the last step, deciding what to do, is not something anybody can sell you.
The intelligence cycle, and the single phase that does the work
Every textbook draws the same loop, and the loop is genuinely useful. What the textbooks tend not to say is that five of its six phases move information around and exactly one of them produces intelligence.
The cycle, with what each phase produced on one real case
One more thing about the loop before leaving it. The phases are drawn as a circle because the output of feedback is supposed to become the input to direction: you learn what your last assessment missed, and that shapes the next question you ask. In practice most programmes run it as a line, and a line has no mechanism for getting better. The organisations that produce genuinely good internal intelligence are almost always the ones that treat the last arrow as real, which costs nothing except the willingness to hear that a report changed nothing.
Direction is a question. Collection is acquisition. Processing is parsing and deduplication. Dissemination is delivery. Feedback is asking whether it mattered. Only analysis takes a set of facts that were already public and produces a statement that was not.
That is why the cycle is worth drawing rather than listing. If you can buy the first three phases and automate the fourth, then a programme can be fully staffed, fully funded and producing nothing that did not arrive in the post.
The cost profile explains why this happens. Direction is a meeting. Collection is a subscription. Processing is a pipeline somebody builds once. Each has a clear owner, a clear price and a clear completion state. Analysis has none of those: it takes an experienced person an unpredictable amount of time, produces a judgement rather than an artefact, and cannot be scheduled in advance because you do not know what you will find. It is the only phase in the loop that behaves like research, and it is therefore the first thing cut when the quarter is tight.
Feedback fails for a different reason. It requires going back to somebody and asking whether the thing you sent them made any difference, which is a question with an uncomfortable answer often enough that the habit rarely forms. A cycle that never closes is not a cycle. It is a pipeline with an arrow drawn on the diagram.
Where programmes actually stop
The rungs a programme reaches, and the ones it does not
B · Where most programmes stop
- ✓Direction
A question someone asked
- ✓Collection
The feed, the report, the alert
- ✓Processing
Deduplicated, parsed, in a table
- ●Analysis
Someone decides what it means
- Dissemination
To a person who can act
- Feedback
Did a control change?
Buying a feed accomplishes the first three rungs on the day the contract is signed, which is why a programme can look complete while having done none of the work. Analysis is where it starts. Feedback is the rung that would tell you whether any of it changed a control, and it is the one nobody schedules.
Buying a feed accomplishes direction, collection and processing on the day the contract is signed. That is what makes the failure so hard to see from a management report: three of six phases are green, the invoice is being paid, and nobody has yet had to form a view about anything.
The four types everyone repeats came from one paper
Search for threat intelligence types and you will find the same four on almost every page: strategic, operational, tactical and technical. They are usually presented as though they were doctrine, in a pyramid, with no source attached.
It is worth pausing on how unusual that is. Four categories, repeated across hundreds of vendor pages, training courses and job descriptions, presented as settled professional consensus, with no citation anywhere. Not because anybody is hiding the source, but because each page copied the page before it and the attribution fell off somewhere around the third hop. This is worth knowing for its own sake, and it is also a reasonable proxy for how carefully a given page was researched: if it lists the four types and names the origin, somebody read something.
They come from one document. Threat Intelligence: Collecting, Analysing, Evaluating, written by David Chismon and Martyn Ruks at MWR InfoSecurity, published in 2015 in conjunction with CERT-UK and the Centre for the Protection of National Infrastructure. Thirty-six pages, and every page footer carries all three sponsors.
Two of those three no longer exist under those names, which matters if you go looking. CERT-UK was absorbed into the National Cyber Security Centre when it became operational on 3 October 2016, alongside CESG and the Centre for Cyber Assessment. The Centre for the Protection of National Infrastructure became the National Protective Security Authority in March 2023, with a broader remit, under MI5. The model outlived both of its institutional sponsors, which is a reasonable definition of influential and also a reason the citation trail went cold.
The four types, and who they are actually for
| Type | Who consumes it | What it is for |
|---|---|---|
| Strategic | Boards and executives | Risk, motivation and direction of travel. Prose, not indicators. |
| Operational | Those defending a specific expected attack | The form and scale of something incoming. The hardest of the four to obtain. |
| Tactical | Security managers and architects | Attacker methodology, so defences are built against how people actually work. |
| Technical | Detection and response tooling | Indicators consumed by machines, with the shortest useful life of the four. |
The four-type split is more useful than the pyramid that later replaced it, because it divides by consumer rather than by seniority. A board paper and a detection rule are not two rungs of the same ladder with the board at the top. They are different products, for different readers, with different useful lifetimes, and the same underlying finding may support both or neither.
The paper is also careful about something the summaries drop entirely: operational intelligence, meaning specific forewarning of an attack about to happen to you, is by far the hardest of the four to obtain, and for most organisations it is not realistically available at all. Anyone selling it should be asked how they came by it. That caution is not a footnote in the original and it is absent almost everywhere the four types are repeated.
Reading the table is one thing and using it is another, so here is the same finding from the case later in this guide, turned into four different products for four different readers.
One finding becomes four products, or three and a gap
One finding, four readers
The finding
The domains this campaign rotated through were bought in batches up to a year before anyone reported it.
Strategic
The board, the budget holder
A control we rely on is weaker than assumed against prepared adversaries. Worth revisiting what else assumes newness equals risk.
Operational
Whoever would defend a specific incoming attack
Nothing. This tells us no attack is coming, and no feed can.
Tactical
Security managers and architects
Attackers buy infrastructure in bulk, months ahead. Stop weighting domain age, and pivot on registrar and registration window instead.
Technical
Detection tooling, and the people who feed it
31 domains, one registrar, two purchase dates. A hunting query, with the shortest useful life of the four.
Four audiences, not four levels of quality. The same finding is a budget conversation, a design decision and a detection rule, and for one of the four it is nothing at all. A vendor selling you the second column should be asked how they came by it.
Two things to take from that. The first is that the four types are not four levels of quality with the board at the top, they are four audiences, and a finding that is valuable to one may be worthless to another. The second is that the empty box is the normal case, not a failure. If somebody offers to sell you operational intelligence, the reasonable question is how they came by advance knowledge of an attack aimed specifically at you.
The paper is worth reading in full for a second reason, and it is the thing that reframed this guide while researching it. Its first reference is the Butler Review of Intelligence on Weapons of Mass Destruction, 2004: the British public inquiry into how intelligence assessments on Iraq went wrong.
That is the founding document of UK cyber threat intelligence opening with a citation to an inquiry into intelligence failure. The lineage is worth naming as British rather than universal: an American account of the same discipline would more likely start from military doctrine and the intelligence cycle as taught at Langley, and a European one from ENISA's threat landscape work. The vocabulary is shared, the ancestry is not. Not a vendor case study, not a breach report. An inquiry into confident assessments that turned out to be untrue.
That choice sets the professional standard the field inherited and mostly ignores. The lesson of Butler is not that intelligence is unreliable. It is that intelligence which does not carry its own uncertainty is dangerous, because the caveats get stripped as an assessment travels upward and what reaches the decision-maker is a confident sentence that nobody in the chain would have signed. Any threat report that never says probably, never says we could not verify this, and never distinguishes what was observed from what was inferred, has failed a test that predates cyber security by decades.
Where the vocabulary came from
2004
The Butler Review
UK inquiry into intelligence on Iraqi weapons of mass destruction, and reference 1 of the 2015 paper below.
2015
Chismon and Ruks
Threat Intelligence: Collecting, Analysing, Evaluating. MWR InfoSecurity with CERT-UK and CPNI. Source of strategic, operational, tactical and technical.
Oct 2016
NIST SP 800-150
Guide to Cyber Threat Information Sharing. Defines cyber threat information and does not adopt the word intelligence.
2020
ENISA takes the opposite view
The EU agency publishes a Cyber Threat Intelligence Overview in its threat landscape series, using the term the US guidance avoids.
2026
Where it has got to
A market in which most products are information, sold under a word borrowed from a discipline that audits its own failures.
What analysis actually looks like, on one real case
Abstractions are cheap here, so this section walks one case end to end. On 18 August 2026 Microsoft Defender Experts published an analysis of MacSync Stealer, a macOS information stealer, extending earlier work by RST Cloud. The report links more than thirty domains by behaviour rather than by matching, and is explicit that the domain count is a by-product of the method rather than the finding.
That report is collection. The indicator table in it is processing. Neither is intelligence yet, and Microsoft would not claim otherwise.
Direction came first, though it is easy to skip past. The question was not what is MacSync Stealer, which the report already answers well. The question was whether the controls a typical organisation already runs would have caught this infrastructure, because that is the thing a reader can act on and the thing no vendor report can answer for them.
Analysis was querying every domain in that table against Verisign's RDAP service and looking at when each was registered.
The reasoning was ordinary, which is the point. If infrastructure is being rotated in response to disclosure, as the reporting describes, then replacement domains should be young: registered shortly before or during the campaign. That is a prediction, it is cheap to test, and registry data is public. Nothing here required access to the malware, a sandbox, or a commercial feed.
$ curl -sL -H 'Accept: application/rdap+json' https://rdap.org/domain/lumenagnet.com{"objectClassName":"domain","ldhName":"LUMENAGNET.COM",
"events":[{"eventAction":"registration","eventDate":"2025-09-26T14:02:11Z"},
{"eventAction":"expiration","eventDate":"2026-09-26T14:02:11Z"}]}One of the 31 domains in Microsoft's indicator table, queried on 18 August 2026. Repeated across all 31 and counted with a script rather than by eye. RDAP is a passive registry lookup: it does not contact the malicious host.
31
Domains checked
Every entry in the published indicator table, not a sample.
1
Registrar, for all of them
A single registrar of record across the entire set.
0
Registered in 2026
The newest predates the report by 263 days. The oldest is October 2024.
14
Bought on two days
Eight on 26 September 2025 and six on 28 November 2025.
When the rotating infrastructure was actually registered
The conclusion is one sentence and it is not in either vendor report: the domains were not registered as the campaign rotated, they were bought in batches up to a year in advance. Rotation and registration are different activities.
The prediction failed, and a failed prediction is usually where the finding is. Every domain predated the report by months. The operator was not registering infrastructure as the campaign burned through it. They were working through stock bought in advance, which is a different operation with different economics and a different detection profile.
That is intelligence rather than information, by the test set out at the top, because it changes a decision. Scoring or blocking newly registered domains is a widely deployed control, it is cheap, and against this campaign it is worth nothing, because every one of these domains had been sitting unused for months before it served anything.
One indicator, and what it does and does not tell you
dogtrainersgeorgia[.]comRegistered 28 November 2025Same registrar as the other 30Same purchase day as five othersAn innocuous small-business name
- 01
dogtrainersgeorgia[.]com: The indicator itself. Blockable, and worthless the moment it is replaced. - 02
Registered 28 November 2025: Older than the campaign report by 263 days, so a domain-age control never fires. - 03
Same registrar as the other 30: A pivot available from DNS logs alone, with no endpoint telemetry required. - 04
Same purchase day as five others: One confirmed hit is a thread back to a batch, which is what makes this analysis rather than a list. - 05
An innocuous small-business name: Reads like a compromised third party and is not one. Registration places it in the same batch as the rest, so there is nobody to notify.
Two honest limits belong with that finding. Registry data is point-in-time and a registrar of record can be a reseller, so this identifies a pattern rather than an owner, and none of it names a person. And two of the 31 domains did not resolve at all, so the counts describe twenty-nine. Stating both is not throat-clearing. An assessment that hides its own limits is exactly the failure mode the Butler Review was convened to examine.
That last part is the one that changes an incident response. A defender who sees a dog-training company in a malicious domain list reasonably assumes a small business got compromised and starts looking for someone to contact. There is no one. The name is cover, bought on the same day as five others.
The same case, mapped to the cycle
| Phase | What it was here | Information or intelligence |
|---|---|---|
| Direction | Does this campaign touch our estate, and do our controls catch it | Neither, it is a question |
| Collection | The Microsoft and RST Cloud reports, both primary | Information |
| Processing | Their table of 31 domains, parsed into a list | Information |
| Analysis | RDAP on all 31: one registrar, none from 2026, 14 on two days | Intelligence |
| Dissemination | A published briefing naming the affected control | Intelligence, if it reaches someone who can act |
| Feedback | Did anyone actually stop scoring domains by age | The phase that decides whether the rest counted |
Try the analysis step yourself, in about ten minutes
The fastest way to understand the difference is to do the last column once. Nothing here needs a licence, a platform or a login.
Take any published indicator list, from any vendor report you can find. Pick the domains out of it. For each one, ask a public registry when it was registered, which is a single command and costs nothing:
$ curl -sL https://rdap.org/domain/example.com | python3 -m json.tool | grep -A1 registrationRDAP is the structured successor to WHOIS. This is a passive registry lookup and nothing contacts the domain itself. example.com is used here because it is reserved for documentation and is always safe to query.
Now ask one question of the answers: is this pattern what I expected? If every domain in a supposedly fast-rotating campaign turns out to be older than the campaign, you have found something the report did not say. If they are all a week old, you have confirmed the report and learned that domain-age scoring would help you here.
Either answer is intelligence, because either one changes what you would do. That is the entire step, and the only expensive part is being willing to look.
Where this sits next to the SOC
A common and reasonable confusion is where threat intelligence ends and the security operations centre begins, because both look at attacker activity and both produce written output.
The difference is the direction of the question. A SOC starts from something that happened in your estate and works outward: this alert fired, what is it, does it matter. Threat intelligence starts from something happening in the world and works inward: this campaign exists, does it reach us, and would we notice. Threat hunting sits between them, starting from a hypothesis about what might already be present and looking for evidence either way.
They feed each other in both directions, and a programme that runs one without the others tends to fail in a predictable way. Intelligence with no SOC produces assessments nobody can action. A SOC with no intelligence is permanently reactive, because every alert is triaged on its own merits with no view of what is currently being done to organisations like yours. Hunting without intelligence is a search with no priority ordering, which in a large estate is indistinguishable from luck.
What to ask anyone selling you intelligence
The market's structural problem is that the first three phases are easy to sell and the fourth is expensive to staff.
What a feed subscription delivers, and where it stops
- Direction, collection, processingFeed subscription
- Matching, at volumeYour SIEM or EDR
- Some true, most notAlerts
- Analysis, and the part nobody sold youA person deciding what it means
Take this with you
Questions that separate the two, and none of them is technical
- Ask what decision the last report changed. Not what it covered, what changed. A vendor with a good answer will have one ready and a vendor without one will describe their collection.
- Ask how the product accounts for your estate. If nothing in it would differ for a competitor in your sector, it is information, which may be exactly what you need and should be priced accordingly.
- Ask how uncertainty is expressed. Analysis that never says probably, or never says we could not verify this, is either extraordinary or is not analysis. The Butler Review is largely about this.
- Ask who receives it and whether they can act. Intelligence delivered to a mailbox nobody owns has failed at dissemination regardless of quality.
- Ask what happens at feedback. Almost nobody has a good answer, and asking the question tells you more about the programme than any sample report will.
Starting without a budget
Everything above is achievable with no platform and no subscription, and the worked example in this guide was done that way deliberately to prove it.
The three things that actually gate a useful programme are a named question, a place to write the answer down, and somebody who will read it. Registry lookups are free. Vendor reports are free. Your own logs are the highest-value collection source you have and you already own them, because they are the only source that knows your estate. What a platform buys is scale and speed in the phases that were never the bottleneck.
If you are starting from nothing, the honest first move is not to buy a feed. It is to write down the last three security decisions your organisation made and ask what information would have made each of them better. That list is your collection requirement, and it will be shorter and stranger than any vendor's coverage map.
The position
Most of what is sold as cyber threat intelligence is cyber threat information, and NIST has been quietly using the more accurate word since 2016.
That is not a reason to buy less of it. Information is the input and the pipeline does not run without it. It is a reason to be precise about what has been bought, because a programme that mistakes the input for the output will keep paying for collection and wonder why nothing changes.
None of this is an argument for cynicism about the vendors. The MacSync analysis this guide leans on is careful work, states its own method, and explicitly declines to lead with the number that would have made the better headline. The gap that mattered was not a mistake in it. The gap was that an indicator table is not an analysis and was never presented as one, and the reader who wanted a decision had to do the last step themselves.
That last step is the job. It is also the only part of this that cannot be outsourced, bought as a subscription, or automated by the current generation of tooling, which makes it the part worth building a team around.
The test survives every vendor conversation and every internal review: name the decision that changed. If nobody can, then whatever else was produced, it was not intelligence. The discipline this one borrowed its name from learned that lesson expensively enough to hold a public inquiry into it, and the paper that gave this field its vocabulary put that inquiry first in its bibliography.
Common questions
›What is the difference between threat data, threat information and threat intelligence?
Data is raw observations such as a list of addresses. Information is data with context, which is what NIST SP 800-150 defines and what most commercial feeds sell. Intelligence is information that has been analysed for a specific consumer and that changes a decision. The boundary that matters commercially is the second one, because products either side of it are priced similarly and are not comparable.
›What are the four types of cyber threat intelligence?
Strategic, operational, tactical and technical. They come from Threat Intelligence: Collecting, Analysing, Evaluating by Chismon and Ruks, published in 2015 by MWR InfoSecurity with CERT-UK and CPNI. The model divides intelligence by who consumes it rather than by a hierarchy of value, which is a distinction lost in most later summaries that redraw it as a pyramid.
›Does NIST define cyber threat intelligence?
Not as a term of art. NIST SP 800-150, Guide to Cyber Threat Information Sharing, October 2016, defines cyber threat information as any information that can help an organisation identify, assess, monitor and respond to cyber threats. The publication is about information sharing throughout and does not adopt intelligence as its subject.
›Do we need a threat intelligence platform to start?
No. A platform helps with collection and processing, which are the phases you can already buy. The step that produces intelligence is somebody forming an assessment, and the worked example in this guide was done with a public indicator list and passive registry queries. Start by naming a decision you want to make better, then find the smallest thing that informs it.
›How do we know whether our threat intelligence is any good?
Ask what it last changed. A programme that can point to a control that was altered, a hunt that was prioritised, or a purchase that was cancelled because of an assessment is producing intelligence. One that reports volumes collected and reports published is measuring its own activity, which is the failure the feedback phase of the cycle exists to catch.
Where to go next