Short, jargon-free explanations of the terms that come up every day in CTI. Bookmark it, share it with the new hire, cite it in the next vendor briefing.
What CTI actually is, who consumes it, and why your security team needs it before the next CVE drops.
How thirty articles about the same incident become one cluster, and why that matters for an analyst's morning.
Indicators of Compromise — IPs, hashes, domains, URLs. The breadcrumbs that prove an attack happened.
The two formats most CTI teams use to share indicators between platforms, vendors, and partners.
Encryption-for-extortion, modern leak sites, double extortion, and why every CTI team tracks it daily.
Advanced Persistent Threat. State-sponsored actors with the patience and budget to stay inside for months.
A vulnerability that's exploited before the vendor knows it exists. Why "zero" days — the patch isn't out yet.
The part of the internet that needs Tor or similar to reach. Where ransomware leak sites and credential markets live.
Data is the raw material: indicators, articles, advisories, leak site posts. Intelligence is what you get after it has been collected, deduplicated, assessed and made relevant to a specific organisation. A feed of ten thousand indicators is data. Knowing which three of them appear in your environment is intelligence.
An IOC is an artefact of a specific incident, such as an IP address or file hash, and it stops being useful when the attacker changes it. A TTP describes how an adversary operates, and it is far more expensive for them to change. Detection built on TTPs outlives detection built on indicators.
Most commonly for four things: deciding what to patch first, deciding whether an incident elsewhere affects you, building detections for behaviour you have not seen yet, and briefing people who need to make a decision without reading the underlying reporting.
Tactical is indicators and detections for the SOC. Operational is campaigns and adversary behaviour for threat hunters and incident responders. Strategic is sector and geopolitical context for the people setting budget and risk appetite. Most teams need all three and most tools only serve one.
Vendors name groups independently based on their own visibility, so one set of activity can be tracked under half a dozen labels. The names are not always exactly equivalent, since different vendors may be clustering slightly different activity, which is why mapping between them matters.
Assessing who was responsible, at varying levels of confidence and to varying degrees of specificity. It can mean a named state programme, a criminal group, or simply the same actor as last time. Confident public attribution usually depends on evidence that is not open source.
The number matters less than the deduplication. Thirty sources covering the same incident produce one story, and a feed that delivers thirty notifications for it has made the volume problem worse, not better.
The deep web is everything not indexed by search engines, most of which is mundane, such as anything behind a login. The dark web is the much smaller portion requiring Tor or similar to reach, which is where leak sites and criminal markets operate.
Not always. Listings are made by the attacker, they are a pressure tactic, and they are occasionally inflated, recycled or wrong. Corroboration matters, which is why source spread across independent reporting is worth checking before acting on one.
No, though pricing has historically implied it. The core requirement, knowing whether something in the news affects you, applies at any size. What changes with size is how much filtering and automation you need around it.
Tactical indicators continuously or near it. Campaign and adversary reporting daily or weekly, depending on sector exposure. Strategic assessment quarterly, aligned to whatever risk cycle you already run.
A structured picture of who is likely to target you, how they operate and what they want. Sector threat models are the common starting point, narrowed by your own technology, geography and supply chain.
Every concept on this page shows up live in the platform. Sign up to see them in action: real clusters, real entities, real indicators.