Threat intel,
in plain English.
Short, jargon-free explanations of the terms that come up every day in CTI. Bookmark it, share it with the new hire, cite it in the next vendor briefing.
The basics
What is threat intelligence? →
What CTI actually is, who consumes it, and why your security team needs it before the next CVE drops.
What is threat clustering? →
How thirty articles about the same incident become one cluster, and why that matters for an analyst's morning.
What are IOCs? →
Indicators of Compromise — IPs, hashes, domains, URLs. The breadcrumbs that prove an attack happened.
What are STIX and MISP? →
The two formats most CTI teams use to share indicators between platforms, vendors, and partners.
Frameworks
Threats
What is ransomware? →
Encryption-for-extortion, modern leak sites, double extortion, and why every CTI team tracks it daily.
What is an APT? →
Advanced Persistent Threat. State-sponsored actors with the patience and budget to stay inside for months.
What is a zero-day? →
A vulnerability that's exploited before the vendor knows it exists. Why "zero" days — the patch isn't out yet.
What is the dark web? →
The part of the internet that needs Tor or similar to reach. Where ransomware leak sites live.
Threat intelligence, explained
What is the difference between threat intelligence and threat data?
Data is the raw material: indicators, articles, advisories, leak site posts. Intelligence is what you get after it has been collected, deduplicated, assessed and made relevant to a specific organisation. A feed of ten thousand indicators is data. Knowing which three of them appear in your environment is intelligence.
What is the difference between an IOC and a TTP?
An IOC is an artefact of a specific incident, such as an IP address or file hash, and it stops being useful when the attacker changes it. A TTP describes how an adversary operates, and it is far more expensive for them to change. Detection built on TTPs outlives detection built on indicators.
How is threat intelligence actually used day to day?
Most commonly for four things: deciding what to patch first, deciding whether an incident elsewhere affects you, building detections for behaviour you have not seen yet, and briefing people who need to make a decision without reading the underlying reporting.
What is the difference between strategic, operational and tactical intelligence?
Tactical is indicators and detections for the SOC. Operational is campaigns and adversary behaviour for threat hunters and incident responders. Strategic is sector and geopolitical context for the people setting budget and risk appetite. Most teams need all three and most tools only serve one.
Why do the same threat actors have several different names?
Vendors name groups independently based on their own visibility, so one set of activity can be tracked under half a dozen labels. The names are not always exactly equivalent, since different vendors may be clustering slightly different activity, which is why mapping between them matters.
What does attribution actually mean?
Assessing who was responsible, at varying levels of confidence and to varying degrees of specificity. It can mean a named state programme, a criminal group, or simply the same actor as last time. Confident public attribution usually depends on evidence that is not open source.
How many threat intelligence sources is enough?
The number matters less than the deduplication. Thirty sources covering the same incident produce one story, and a feed that delivers thirty notifications for it has made the volume problem worse, not better.
What is the difference between the dark web and the deep web?
The deep web is everything not indexed by search engines, most of which is mundane, such as anything behind a login. The dark web is the much smaller portion requiring Tor or similar to reach, which is where leak sites and criminal markets operate.
Does a leak site listing mean the victim was definitely breached?
Not always. Listings are made by the attacker, they are a pressure tactic, and they are occasionally inflated, recycled or wrong. Corroboration matters, which is why source spread across independent reporting is worth checking before acting on one.
Is threat intelligence only for large organisations?
No, though pricing has historically implied it. The core requirement, knowing whether something in the news affects you, applies at any size. What changes with size is how much filtering and automation you need around it.
How often should threat intelligence be reviewed?
Tactical indicators continuously or near it. Campaign and adversary reporting daily or weekly, depending on sector exposure. Strategic assessment quarterly, aligned to whatever risk cycle you already run.
What is a threat model?
A structured picture of who is likely to target you, how they operate and what they want. Sector threat models are the common starting point, narrowed by your own technology, geography and supply chain.
Want the terms in context?
Every concept on this page shows up live in the platform. Sign up to see them in action: real clusters, real entities, real indicators.