1/9
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Threat intelligence
Information about threats and threat actors used to inform security decisions, tooling, and training.
OSINT (Open-Source Intelligence)
Threat information gathered from publicly available sources: forums, social media, government reports, published financial or commercial data.
Threat intelligence service (third-party/commercial)
Paid providers who compile threat data across many organizations simultaneously, spotting trends before they reach any single customer.
Cross-organization threat visibility
The key advantage of third-party intel services: seeing attack patterns across multiple enterprises at once, enabling early warning.
Classified-to-public threat data
Some compiled threat intelligence originates from classified sources that have since been declassified or made public.
CTA (Cyber Threat Alliance)
An alliance of organizations that gather, standardize, validate, and score threat submissions, then share that intelligence across all members.
Threat scoring/validation (CTA)
Submissions to a sharing alliance are validated and assigned a severity score before distribution.
Dark web
An overlay network running on top of the internet, accessible only via specialized software; hosts hacking group activity, stolen data marketplaces, and direct insight into attacker tools and techniques.
Threat feed
A continuously updated stream of threat indicators (malicious IPs, domains, file hashes, TTPs) that security tools can ingest automatically; the deliverable output of threat intelligence sources.
Strategic vs tactical threat intelligence
Strategic: high-level trends for leadership and long-term planning. Tactical: specific, actionable indicators fed into tools for real-time decisions.