What Is Threat Intelligence? A Complete Guide
A plain-English guide to cyber threat intelligence (CTI): what it is, why it matters, the four types, the six-stage lifecycle, where it comes from, and how teams actually use it.
Read guideClear, in-depth guides to cyber threat intelligence — from core concepts to frameworks, detection and vulnerability management. Written for analysts, SOC teams and anyone getting started with threat intel.
A plain-English guide to cyber threat intelligence (CTI): what it is, why it matters, the four types, the six-stage lifecycle, where it comes from, and how teams actually use it.
Read guideThreat intelligence comes in four flavors — strategic, operational, tactical and technical. Learn what each one is, who consumes it, and how they fit together.
Read guideQuality intelligence is produced by a repeatable process. Walk through all six stages of the threat intelligence lifecycle and the pitfalls that derail each one.
Read guideOSINT turns publicly available information into intelligence. Learn what OSINT is, how attackers and defenders use it, the collection process, tools and ethics.
Read guideTTPs describe the behavior of an adversary — the most durable thing to defend against. Learn what tactics, techniques and procedures mean, with examples.
Read guideVulnerability, threat and risk are used interchangeably but mean different things. Learn the difference with a simple formula and examples that clarify security decisions.
Read guideA plain-English A–Z of cyber threat intelligence — 60+ key terms defined in a sentence each, with links to in-depth guides. Your quick reference for the language of threat intel and cybersecurity.
Read guideAdvanced persistent threats are the most sophisticated adversaries in cyber. Learn what defines an APT, how the attack lifecycle works, famous groups, and how to defend.
Read guideA threat actor is anyone behind a cyberattack. Learn the main types — nation-states, cybercriminals, hacktivists, insiders and more — their motives, and how to track them.
Read guideRansomware-as-a-service turned extortion into a franchise business: operators build the malware, affiliates deploy it, and they split the profits. Here's how the model works and why it's so dangerous.
Read guideInitial access brokers are the real-estate agents of cybercrime: they break into organizations, then sell that foothold to whoever wants it — most often ransomware gangs. Here's how the market works.
Read guideThe most dangerous attacker may already be inside, holding a valid badge. Insider threats come from people with legitimate access — and because the perimeter trusts them, they're uniquely hard to catch.
Read guideHacktivism is hacking with a message — disruption and exposure in the name of a political or social cause rather than money. Here's how hacktivists operate, who they are, and how to defend.
Read guideWho did it? In cyberspace that question is famously hard to answer — attackers hide, share tools, and plant false flags. Here's how analysts build attribution, and why certainty isn't required to act.
Read guideFrom Russia's Sandworm to North Korea's Lazarus Group and the LockBit ransomware empire, these are the 20 most dangerous threat actors of all time — ranked by real-world damage, with aliases, motives, and the billions they've cost.
Read guideSandworm (APT44 / Seashell Blizzard) is the Russian GRU unit behind NotPetya — the most financially destructive cyberattack on record — and the first cyber-induced power blackouts. A full threat-actor profile.
Read guideLazarus Group is North Korea's most consequential cyber program — part espionage service, part crypto-theft machine responsible for the $1.5B Bybit hack and billions more in stolen funds. A full threat-actor profile.
Read guideREvil (Sodinokibi) defined the big-game-hunting ransomware era of 2019-2021, culminating in the Kaseya and JBS attacks and $700M+ in ransom demands before a multinational takedown. A full threat-actor profile.
Read guideFIN7 is one of the most adaptable career cybercrime organizations on record — from point-of-sale card theft and the €1B Carbanak bank heists to modern ransomware enablement. A full threat-actor profile.
Read guideLockBit industrialized affiliate ransomware to become the most prolific RaaS franchise of the early 2020s — 2,000+ victims and $120M+ in payments — before the 2024 Operation Cronos takedown. A full profile.
Read guideALPHV/BlackCat was the most technically polished Rust-based RaaS of its generation, taking nearly $300M from 1,000+ victims before the Change Healthcare attack and an apparent 2024 exit scam. A full profile.
Read guideConti was both a ransomware brand and the public face of the Wizard Spider / TrickBot empire — one of the most capable Russia-based cybercrime enterprises ever, whose alumni seeded Black Basta and BlackSuit. A full profile.
Read guideCl0p turned zero-day exploitation into an industrial mass-extortion playbook — MOVEit alone yielded $100M+ — making it one of the most financially productive 'few clicks, many victims' crews of the era. A full profile.
Read guideAPT41 is unusual among top-tier adversaries — a Chinese state-sponsored espionage group that also runs financially motivated operations, tied to intrusions at 100+ victims across 14+ countries. A full profile.
Read guideEvil Corp is the rare criminal organization that evolved from the Dridex banking trojan to enterprise ransomware — stealing $100M+ — and then survived U.S. sanctions by repeatedly rebranding. A full profile.
Read guideBlack Basta emerged in 2022 as a credible heir to Conti's intrusion tradecraft, pulling in more than $100M before a 2025 chat leak exposed its inner workings and fractured the brand. A full threat-actor profile.
Read guideAkira moved from mid-tier brand to top-earning extortion actor remarkably fast, generating roughly $244M in proceeds by late 2025 by exploiting VPNs and encrypting ESXi. A full threat-actor profile.
Read guideDarkSide's public lifetime was short but its impact was outsized — the Colonial Pipeline attack made ransomware a national-security issue. It took $90M+ in Bitcoin before rebranding as BlackMatter. A full profile.
Read guideScattered Spider is the most operationally significant English-speaking cybercrime collective of the cycle, weaponizing help-desk social engineering and SIM swaps to breach 100+ organizations for $100M+. A full profile.
Read guideHive was one of the most successful RaaS brands of 2021-2023, hitting 1,500+ victims for $100M+ before the FBI covertly infiltrated its infrastructure and disrupted it in a landmark 2023 takedown. A full profile.
Read guideRoyal evolved into BlackSuit, a Conti-adjacent 'continuity syndicate' tied to $370M+ in ransom payments before a 2025 DOJ takedown seized its infrastructure. Successor risk remains high. A full profile.
Read guideShinyHunters is a data-theft-first actor that graduated from database trading to broad extortion, driving the Snowflake breach wave that hit Ticketmaster, Santander, and others. A full threat-actor profile.
Read guideAPT29 is Russia's patient SVR espionage service — the actor behind the SolarWinds supply-chain compromise and an expert in cloud and identity persistence. A full nation-state threat-actor profile.
Read guideAPT28 (Fancy Bear) is Russia's GRU cyber-espionage unit, combining classic military intelligence collection with hack-and-leak operations, credential theft, and near-front-line targeting around Ukraine. A full profile.
Read guideAPT10 (menuPass, Stone Panda) industrialized managed-service-provider compromise with the Cloud Hopper campaign — breaching IT providers to reach their downstream clients at scale. A full nation-state profile.
Read guideRansomware is the most disruptive cyber threat facing organizations today. Learn how it works, the double-extortion and RaaS models, famous groups, and how to defend.
Read guidePhishing is the most common entry point for cyberattacks. Learn how it works, the main types — spear phishing, whaling, smishing and vishing — and how to defend.
Read guideMalware is the umbrella term for malicious software. Learn the main types — viruses, worms, trojans, ransomware, spyware, rootkits, botnets — and how to defend.
Read guideSocial engineering hacks people, not computers. Learn the techniques — pretexting, baiting, phishing, tailgating — the psychology behind them, and how to defend.
Read guideA data breach exposes sensitive data to people who shouldn't have it. Learn the common causes, the breach lifecycle, the real-world impact, and how to prevent them.
Read guideA distributed denial-of-service (DDoS) attack overwhelms a website or network with junk traffic so legitimate users can't get through. Here's how DDoS attacks work and how to stop them.
Read guideA botnet is an army of infected computers and devices controlled remotely by an attacker. Here's how botnets are built, what they're used for, and how to detect and dismantle them.
Read guideInstead of attacking you directly, adversaries compromise a trusted supplier or software component and ride it into your environment. Here's how supply chain attacks work and how to defend against them.
Read guideA Trojan horse hides malicious code inside something that looks legitimate, tricking you into installing it yourself. Here's how trojans work, the main types, and how to defend.
Read guideA rootkit gives an attacker deep, privileged control of a system while hiding its own presence — and that of other malware — from the operating system and security tools. Here's how they work.
Read guideSpyware secretly watches what you do and quietly steals your data — from keystrokes and passwords to your location. Here's how it works, the main types, and how to remove it.
Read guideA computer worm copies itself across networks automatically, with no host file and no human action required — which is why worms cause some of the fastest, most damaging outbreaks in history.
Read guideFileless malware leaves almost nothing on disk — it runs in memory and abuses trusted system tools like PowerShell, so traditional antivirus has nothing to scan. Here's how it works.
Read guideInfostealers grab your saved passwords, session cookies, and crypto wallets in seconds, then sell them in bulk. They've become a primary on-ramp to ransomware and major breaches. Here's how.
Read guideIn a man-in-the-middle attack, an attacker secretly sits between you and the service you're talking to — reading, and sometimes altering, everything that passes. Here's how MITM works and how to stop it.
Read guideSQL injection tricks a web application into running an attacker's database commands by smuggling them in through ordinary input fields. It's one of the oldest and most damaging web vulnerabilities.
Read guideCross-site scripting turns a trusted website into a delivery vehicle for the attacker's code, running it in your browser. Here's how XSS works, the three main types, and how to prevent it.
Read guideCredential stuffing takes username/password pairs leaked in one breach and tries them, by the millions, against other sites — cashing in on the fact that people reuse passwords. Here's how to stop it.
Read guideAttackers rarely land with the access they need. Privilege escalation is how they climb from a low-level foothold to admin or root — the pivotal step that turns a small breach into a full compromise.
Read guideAfter breaking in, attackers rarely stay put. Lateral movement is how they quietly hop from one system to the next, hunting for the data and access that's actually their goal. Here's how to catch it.
Read guideOnce attackers compromise a system, they need a way to control it. Command and control (C2) is that channel — and finding the secret conversation between an implant and its operator is one of detection's biggest wins.
Read guideBusiness email compromise skips the malware and goes straight for the wire transfer — impersonating a trusted executive or vendor to trick an employee into sending money. It's one of the costliest cybercrimes.
Read guideAI is a force multiplier for attackers — making phishing flawless, automating reconnaissance, and powering convincing deepfakes. Here's how adversaries weaponize AI, and why the fundamentals still matter.
Read guideA digest of the most important ransomware statistics and trends — prevalence, cost, double extortion, targeted sectors, and the RaaS model — synthesized from major industry reports, with sources to check for the latest figures.
Read guideSome of history's largest data breaches exposed billions of records — and each one taught a hard lesson about patching, third-party risk, or password reuse. Here are the most significant, and what they teach.
Read guideCVEs are the universal IDs for security vulnerabilities. Learn how CVE identifiers and CVSS scores work, how CVE differs from CWE, and how to prioritize what to patch.
Read guideZero-days are the vulnerabilities no patch exists for yet. Learn the difference between a zero-day vulnerability, exploit and attack, why they're prized, and how to defend.
Read guideCVSS tells you how severe a vulnerability is; EPSS tells you how likely it is to be exploited. Learn the difference and how to combine them to patch what matters first.
Read guideVulnerability management is the ongoing cycle of discovering, prioritizing, remediating, and verifying security weaknesses across your environment. Here's how the lifecycle works and how to prioritize what matters.
Read guideTens of thousands of vulnerabilities are published yearly, but only a fraction are actually exploited. The CISA KEV catalog is the authoritative list of which ones — making it the ultimate patch-first signal.
Read guideYou can't protect what you don't know you have. Attack surface management continuously discovers every internet-facing asset — including the forgotten and unknown ones — by seeing your org as an attacker does.
Read guideIndicators of compromise are the forensic breadcrumbs of an attack. Learn the main IOC types, real examples, IOC vs IOA, the Pyramid of Pain, and how to operationalize them.
Read guideIOCs and IOAs are both detection signals, but they work very differently. Learn the difference between indicators of compromise and indicators of attack, with examples.
Read guideThe Pyramid of Pain is a simple model with a profound lesson: detect attackers by their behavior, not their disposable artifacts. Learn all six levels and how to use it.
Read guideThreat hunting assumes attackers are already inside and goes looking for them. Learn the core methodologies, a repeatable process, example hypotheses, and how to start.
Read guideYARA rules let analysts describe malware as patterns of strings and conditions, turning research into reusable detection. Here's how YARA works, how rules are structured, and how to use them.
Read guideA raw IP address or file hash tells you almost nothing on its own. IOC enrichment surrounds it with context — reputation, history, related activity — so analysts can decide what it means and what to do.
Read guideMalware analysis is how defenders dissect malicious code to learn what it does, where it came from, and how to detect it. Here's static vs dynamic analysis, the four types, and the tools involved.
Read guideA honeypot is a deliberate trap — a decoy system that looks valuable but exists only to be attacked. Because no legitimate user should ever touch it, any interaction is a high-confidence sign of trouble.
Read guideDetection engineering treats threat detections like software: designed, tested, version-controlled, and continuously improved. It's how mature teams move from buying black-box alerts to building reliable ones.
Read guideSigma is a generic, vendor-neutral way to write detection rules for log data — write a rule once and convert it to run on any SIEM. It's become the lingua franca of shareable log-based detection.
Read guideMITRE ATT&CK is the common language of adversary behavior. Learn its tactics, techniques and sub-techniques, the matrices, and practical ways to use it for defense.
Read guideThe Cyber Kill Chain breaks an attack into seven stages so defenders can disrupt it at each step. Learn all seven stages, how to use it, and how it compares to ATT&CK.
Read guideThe Diamond Model connects every intrusion across four features — adversary, capability, infrastructure and victim — enabling powerful pivoting. Learn how to use it.
Read guideSTIX is the language for describing threat intelligence; TAXII is the protocol for sharing it. Learn how they work together to let tools and organizations exchange CTI.
Read guideThe Cyber Kill Chain tells the story of an attack in seven linear stages; MITRE ATT&CK catalogs the hundreds of specific techniques attackers actually use. Here's how they differ — and why you want both.
Read guideThreat modeling asks 'what could go wrong?' while a system is still on the whiteboard — finding security flaws in the design before they're ever built. Here's the process and the STRIDE methodology.
Read guideBorrowed from military special operations, F3EAD tightly fuses 'finding and finishing' a threat with exploiting and analyzing what you learn — creating a fast loop between action and intelligence.
Read guideA SIEM is the nerve center of many security operations. Learn how it collects, correlates and analyzes log data to detect threats — plus SIEM vs SOAR vs XDR.
Read guideEDR is modern endpoint security that detects and responds to threats antivirus misses. Learn how it works, EDR vs antivirus vs XDR vs MDR, and its core capabilities.
Read guideThe SOC is the team that monitors and defends an organization around the clock. Learn what a SOC does, its roles and analyst tiers, its tools, and SOC models compared.
Read guideThreat intelligence and threat hunting are often confused. One produces knowledge about threats; the other proactively searches for them. Learn how they differ and combine.
Read guideDark web monitoring watches hidden forums and markets for your leaked credentials and data. Learn how it works, what it detects, and how it fits into threat intelligence.
Read guideA practical, step-by-step guide to building a threat intelligence program from scratch — from defining requirements to sources, processing, analysis, tooling and metrics.
Read guideIncident response is the organized way a team detects, contains, and recovers from a security incident. Here are the six phases of the IR lifecycle and how to build a plan before you need it.
Read guideThe Traffic Light Protocol is a simple set of labels that tells you exactly how far a piece of threat intelligence can be shared. Here's what TLP:RED, AMBER, GREEN and CLEAR mean in TLP 2.0.
Read guideISACs are trusted, industry-specific communities where organizations share threat intelligence so the whole sector can defend together. Here's how they work and how to join one.
Read guideCyber threat intelligence is one of the most in-demand specialisms in security. Here's what a CTI analyst actually does, the skills and certifications that matter, and a realistic path to break in.
Read guideXDR breaks security tools out of their silos, correlating signals across endpoint, network, email, identity, and cloud into one picture. Here's what XDR is and how it differs from EDR and SIEM.
Read guideSOAR turns repetitive security tasks into automated playbooks, so analysts spend their time on judgment instead of copy-paste. Here's what SOAR is, its three pillars, and how it differs from SIEM.
Read guideUEBA learns what 'normal' looks like for every user and machine, then flags the deviations. It's how organizations catch insider threats, account takeovers, and subtle attacks that rules miss.
Read guideEDR, XDR, and MDR sound alike but answer different questions. Two are technologies and one is a service. Here's the clear distinction — and how to choose the right fit for your team.
Read guideSIEM, SOAR, and XDR are the backbone of modern security operations — and constantly confused. The simplest way to remember them: SIEM sees, SOAR acts, XDR unifies. Here's the full comparison.
Read guideIn security, red attacks, blue defends, and purple makes sure they learn from each other. Here's what red, blue, and purple teams actually do — and why the most value comes from their collaboration.
Read guideAttackers don't break in anymore — they log in. ITDR is the security discipline built to catch identity-based attacks: stolen credentials, account takeover, and attacks on the identity systems themselves.
Read guideWhen an attack can stop a power grid or contaminate water, the stakes change. OT/ICS threat intelligence focuses on the industrial systems that run physical processes — where safety, not just data, is on the line.
Read guideYou don't need a big budget to start a threat-intel program. Here are the best free and open-source tools and feeds — platforms, feeds and enrichment — and how to combine them.
Read guideA threat intelligence platform centralizes and operationalizes threat data. Learn what a TIP does, its core capabilities, how it differs from a SIEM, and how to choose.
Read guideMISP is the most widely used open-source platform for storing and sharing threat intelligence. Learn what it is, how it works, its key features, and who uses it.
Read guideYou can build a serious threat-intel capability for free. Here are the best free threat intelligence feeds across government, vendor, community and aggregated sources.
Read guideTheory meets practice on our live feed — the top cyber threats from the last 24 hours, aggregated from 30+ sources, deduplicated and ranked by priority.