Back to glossaryCyber

Threat intelligence (cyber threat intelligence)

Cyber threat intelligence, encompassing the collection and analysis of indicators of compromise and attacker tactics to anticipate and detect intrusions.

Definition

Threat intelligence is the discipline that involves collecting, analyzing and sharing information about malicious actors, their tools, techniques and indicators of activity, in order to anticipate attacks and improve detection. It operates at several levels. Tactical threat intelligence provides concrete and immediately actionable indicators of compromise (IOC) such as malicious IP addresses, malware file hashes or domain names used by attackers. Operational threat intelligence describes ongoing campaigns and the TTPs (Tactics, Techniques and Procedures) of active groups. Strategic threat intelligence analyzes trends, actor motivations and the evolution of the threat landscape to guide security investment decisions. Exchange standards are STIX (description language) and TAXII (transport protocol), used by platforms such as MISP (Malware Information Sharing Platform). For insurance, threat intelligence is used at two levels: in underwriting, to assess whether an insured is actively targeted or whether its systems expose vulnerabilities exploited in the wild; and in claims management, to attribute the attack and assess the risk of a second incident.

Example

A cyber insurer subscribes to a threat-intelligence feed that flags a known APT group targeting health insurers publishing new IOCs. The insurer immediately alerts its 40 healthcare insureds, three of whom detect in their logs an IP address matching the IOCs, enabling containment before any ransomware deployment.

Related terms
Also known as

CTI, cyber threat intelligence, renseignement sur les menaces, IOC, STIX, TAXII