Threat intel,
in plain English.

Short, jargon-free explanations of the terms that come up every day in CTI. Bookmark it, share it with the new hire, cite it in the next vendor briefing.

Threat intelligence, explained

What is the difference between threat intelligence and threat data?

Data is the raw material: indicators, articles, advisories, leak site posts. Intelligence is what you get after it has been collected, deduplicated, assessed and made relevant to a specific organisation. A feed of ten thousand indicators is data. Knowing which three of them appear in your environment is intelligence.

What is the difference between an IOC and a TTP?

An IOC is an artefact of a specific incident, such as an IP address or file hash, and it stops being useful when the attacker changes it. A TTP describes how an adversary operates, and it is far more expensive for them to change. Detection built on TTPs outlives detection built on indicators.

How is threat intelligence actually used day to day?

Most commonly for four things: deciding what to patch first, deciding whether an incident elsewhere affects you, building detections for behaviour you have not seen yet, and briefing people who need to make a decision without reading the underlying reporting.

What is the difference between strategic, operational and tactical intelligence?

Tactical is indicators and detections for the SOC. Operational is campaigns and adversary behaviour for threat hunters and incident responders. Strategic is sector and geopolitical context for the people setting budget and risk appetite. Most teams need all three and most tools only serve one.

Why do the same threat actors have several different names?

Vendors name groups independently based on their own visibility, so one set of activity can be tracked under half a dozen labels. The names are not always exactly equivalent, since different vendors may be clustering slightly different activity, which is why mapping between them matters.

What does attribution actually mean?

Assessing who was responsible, at varying levels of confidence and to varying degrees of specificity. It can mean a named state programme, a criminal group, or simply the same actor as last time. Confident public attribution usually depends on evidence that is not open source.

How many threat intelligence sources is enough?

The number matters less than the deduplication. Thirty sources covering the same incident produce one story, and a feed that delivers thirty notifications for it has made the volume problem worse, not better.

What is the difference between the dark web and the deep web?

The deep web is everything not indexed by search engines, most of which is mundane, such as anything behind a login. The dark web is the much smaller portion requiring Tor or similar to reach, which is where leak sites and criminal markets operate.

Does a leak site listing mean the victim was definitely breached?

Not always. Listings are made by the attacker, they are a pressure tactic, and they are occasionally inflated, recycled or wrong. Corroboration matters, which is why source spread across independent reporting is worth checking before acting on one.

Is threat intelligence only for large organisations?

No, though pricing has historically implied it. The core requirement, knowing whether something in the news affects you, applies at any size. What changes with size is how much filtering and automation you need around it.

How often should threat intelligence be reviewed?

Tactical indicators continuously or near it. Campaign and adversary reporting daily or weekly, depending on sector exposure. Strategic assessment quarterly, aligned to whatever risk cycle you already run.

What is a threat model?

A structured picture of who is likely to target you, how they operate and what they want. Sector threat models are the common starting point, narrowed by your own technology, geography and supply chain.

Want the terms in context?

Every concept on this page shows up live in the platform. Sign up to see them in action: real clusters, real entities, real indicators.