What Is Threat Intelligence?
Threat intelligence is threat information that has been aggregated, transformed, analyzed, interpreted, or enriched to give a security team the context it needs to make decisions.
A suspicious domain, a file hash, or a command-and-control IP address is threat information (opens in new tab); it becomes intelligence once analysts establish who is behind it, which assets it targets, how the campaign was built, and what to do about it. Analytical processing, context, and action-oriented decision support are what separate the two.
How threat intelligence works
Security teams produce threat intelligence through a cycle from national intelligence practice (opens in new tab): planning and direction, collection, processing, analysis and production, and dissemination.
Enterprise teams add a sixth feedback phase to this structure:
- Planning and direction. The team writes Priority Intelligence Requirements (PIRs), the questions management has approved (opens in new tab) and resourced. Private-sector teams often overlook this phase (opens in new tab).
- Collection. Collection sources (opens in new tab) include open-source intelligence, dark web forums, domain and DNS registration data, TLS certificates, internal telemetry, ISAC feeds, and commercial feeds.
- Processing. Teams normalize and structure (opens in new tab) raw data, commonly in STIX 2.1 (opens in new tab).
- Analysis. Analysts cluster intrusions into threat groups and apply structured techniques such as competing hypotheses (opens in new tab), then map behavior (opens in new tab) to MITRE ATT&CK.
- Dissemination. Finished intelligence reaches stakeholders through reports and briefings. Machine-readable feeds travel over TAXII 2.1 (opens in new tab), and a Traffic Light Protocol (opens in new tab) label sets who may share it further.
- Feedback. Alert verification, false-positive tuning, and answered or revised PIRs restart the cycle (opens in new tab).
In brand protection, the PIR is "which impersonation campaigns are targeting our customers this quarter." Collection pulls newly registered lookalike domains, DNS and SSL records, paid ads, and spoofed social profiles.
Analysis links one domain's registrar, hosting IP, and listed phone number to a scam ad and a fake support account, turning separate alerts into one campaign. Dissemination gives the registrar's abuse contact and the hosting IP to whoever files the complaint, following the NCSC response sequence (opens in new tab) for brand impersonation.
Why threat intelligence matters
Threat intelligence is what lets a team apply threat information (opens in new tab) to its own environment and the actors actually targeting it. It also sets how much a defender costs the attacker: the Pyramid of Pain (opens in new tab) places hashes, IPs, and domains at the bottom because an adversary changes them cheaply, and tactics, techniques, and procedures at the top because changing them is expensive.
Indicators from generic feeds (opens in new tab) are transient and noisy, and indicator-based detection fails the moment attackers move to new infrastructure (opens in new tab), so a shift toward actor tracking (opens in new tab) and ATT&CK-mapped hunting is replacing reactive indicator use.
That shift matters more as AI reshapes attacker tradecraft (opens in new tab). Threat groups use commercial and jailbroken LLMs such as WormGPT and FraudGPT (opens in new tab) to automate social engineering, and deepfake video and audio now support impersonation attacks that pose as trusted contacts (opens in new tab) and executives.
Intelligence programs also support required testing: regulators expect intelligence (opens in new tab) to drive controls, and under DORA's testing framework (opens in new tab), selected financial entities must run threat-led penetration tests at least every three years on live production systems.
Types of threat intelligence
Three levels (opens in new tab) form the most widely used model: strategic, operational, and tactical. A four-level model may split out technical intelligence (opens in new tab) as a fourth level: technical intelligence holds raw indicators, while tactical intelligence covers TTPs.
- Strategic threat intelligence covers developments that drive high-level strategy. At horizons of months to years, senior decision-makers (opens in new tab) up to board level use it to decide which threats matter and whether security investments reduced them.
- Operational threat intelligence identifies warning signs (opens in new tab) of active or impending attacks through continuous monitoring the threat environment. Security managers, threat hunters, and responders use it to learn which campaigns are active in their industry.
- Tactical threat intelligence covers the TTPs intrusion sets use to carry out attacks. Detection engineers, SOC analysts, and red/blue/purple teams turn it into detection rules and prioritized hunts.
- Technical threat intelligence covers indicators of compromise: IPs, file hashes, malicious domains, URLs, and email subject lines.
Automated platforms consume it over STIX/TAXII.
How to implement threat intelligence
Start with decisions (opens in new tab), then work backwards to collection. Write PIRs (opens in new tab) that name the business decision each one informs, break them into Essential Elements of Information, and issue Requests for Information against them.
A collection plan then converts those requirements into specific sources and cadences, and teams should grade every source: the Admiralty System (opens in new tab) scores source reliability and information credibility on separate scales, so a grade like "B2" tells a reader how much weight a claim carries, and analysts still owe independent validation (opens in new tab) to any indicator from an untrusted source before it reaches detection.
Correlate behaviors into campaigns. Map adversary tradecraft (opens in new tab) to ATT&CK, write chained analytics, and treat indicators as supporting evidence for the campaign story. Push that context into SIEM and SOAR (opens in new tab) so intelligence drives alert prioritization and can trigger automated response workflows.
Close the loop with the people attackers target. An anti-phishing program works when employee awareness, simulated attacks (opens in new tab), and results analysis feed each other, with live impersonation campaigns supplying the source material for those simulations.
How Doppel helps
Doppel is the Frontier AI Social Engineering Defense (SED) platform that unifies Digital Risk Protection (DRP) and Human Risk Management (HRM). It uses campaign intelligence from outside the perimeter as direct input to simulations and training inside it.
The Doppel Threat Graph is a signal correlation engine for impersonation. It ingests spoofed domains, fake profiles, scam ads, phone numbers, app listings, and dark web mentions, then links them into a single view of an attacker's multi-channel infrastructure; takedown results feed back into the graph.
Doppel's agentic AI acts on that intelligence, correlating and prioritizing campaigns to execute takedowns at scale while analysts focus on escalations that need human judgment. It also turns a detected impersonation campaign into an employee Simulation, so the threat your customers saw this week trains your workforce next week, tracking each campaign from first signal to dismantled infrastructure and making it too costly to rebuild.
Request a demo to get started.
Frequently asked questions about threat intelligence
What is threat intelligence?
Threat intelligence is threat information that security teams collect, analyze, and contextualize so they can act on it. Analytical processing (opens in new tab) separates it from raw threat data: a list of malicious IPs is data, while an assessment of which group uses those IPs, what they target, and how to detect them is intelligence. Its outputs run from board-level trend reports at the strategic end to machine-readable indicator feeds at the technical end.
What is threat intelligence in cybersecurity?
Cyber threat intelligence (CTI) provides knowledge of attackers' activities (opens in new tab), from a narrative of a threat actor's motivations through detailed TTPs. SOC analysts use it for detection, threat hunters for hypotheses, incident responders for context during an incident, and executives for risk decisions. Machine-readable standards such as STIX let organizations exchange it automatically.
What is the difference between threat intelligence and threat hunting?
Threat intelligence is the knowledge about adversaries and their methods. Threat hunting is the proactive search (opens in new tab) for those adversaries inside an environment before any alert fires. Hunters use intelligence to form hypotheses, map them to MITRE ATT&CK, and query logs and telemetry to test them. A threat hunter works as a proactive incident responder (opens in new tab) looking for compromise that tools haven't flagged yet, and findings from a hunt flow back to the intelligence team as new indicators and refined requirements.
What is an example of threat intelligence in practice?
A financial institution receives an advisory that threat actors are calling employees while posing as IT help desk staff to extract passwords and multi-factor authentication codes. Threat actors used exactly this campaign against regulated firms in February 2026 (opens in new tab). The security team treats the advisory as operational intelligence: it briefs the help desk on the pretext, reviews credential-reset procedures, and runs a voice-phishing simulation using the same script, while the same event informs longer-term authentication decisions at the strategic level.


