Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 295

Cyber Threat Intelligence (CTI)

Reviewed byCybersecurity entrepreneur & security researcher

What is Cyber Threat Intelligence (CTI)?

Cyber Threat Intelligence (CTI)Evidence-based knowledge about adversaries, their motivations, and methods, used to inform defensive decisions and prioritize controls.


Cyber Threat Intelligence is the discipline of collecting, processing, analyzing, and disseminating information about cyber threats so that defenders can make better decisions. It transforms raw signals (malware samples, leaked credentials, dark-web chatter, telemetry) into curated intelligence about who is targeting the organization, what they want, and how they operate.

CTI work is structured by well-known models. The intelligence cycle (direction → collection → processing → analysis → dissemination → feedback) governs the workflow, while analytical frameworks like Lockheed Martin's Cyber Kill Chain, the Diamond Model of Intrusion Analysis, and MITRE ATT&CK give analysts a shared vocabulary for adversary, capability, infrastructure, and victim. CTI is usually divided into strategic, operational, and tactical tiers, each serving a different audience from executives to SOC analysts.

Indicators and reports are commonly exchanged in STIX (structured data format) over TAXII (transport protocol), letting ISACs and vendors share machine-readable intelligence at scale. Mature programs feed CTI into SIEM, EDR, vulnerability management, and incident response — for example, prioritizing patches for a CVE that an actor known to target the sector is actively exploiting — shortening detection and response time and turning reactive defense into anticipation.

flowchart LR
  A[Direction] --> B[Collection]
  B --> C[Processing]
  C --> D[Analysis]
  D --> E[Dissemination]
  E --> F[Feedback]
  F --> A
  D --> G[Strategic: board]
  D --> H[Operational: IR / hunt]
  D --> I[Tactical: SOC / SIEM]

Examples

  1. 01

    Receiving a STIX/TAXII feed of IoCs associated with a ransomware affiliate.

  2. 02

    Briefing the board on geopolitical risk influencing the threat landscape.

Frequently asked questions

What is Cyber Threat Intelligence (CTI)?

Evidence-based knowledge about adversaries, their motivations, and methods, used to inform defensive decisions and prioritize controls. It belongs to the Defense & Operations category of cybersecurity.

What does Cyber Threat Intelligence (CTI) mean?

Evidence-based knowledge about adversaries, their motivations, and methods, used to inform defensive decisions and prioritize controls.

How do you defend against Cyber Threat Intelligence (CTI)?

Defences for Cyber Threat Intelligence (CTI) typically combine technical controls and operational practices, as detailed in the full definition above.

What are other names for Cyber Threat Intelligence (CTI)?

Common alternative names include: Threat intelligence, CTI.

Related terms

See also