Cyber threat intelligence (CTI)

Table of contents
Cyber threat intelligence (CTI)

What is cyber threat intelligence?

Cyber threat intelligence (CTI) is information about cyber adversaries — their identities, infrastructure, methods, and targets — that has been collected, analyzed, and packaged so a security or investigative team can use it to anticipate, detect, or respond to a threat. CTI turns raw signals like malware samples, leaked credentials, or attacker chatter into a picture of who is behind an attack and what they are likely to do next.

CTI sits between raw data and a decision. A list of IP addresses associated with a botnet is data. Knowing that those addresses belong to a specific ransomware group, which victims they typically target, and which vulnerability they exploit to gain access is intelligence.

CTI is generally organized into four types, each built for a different audience:

  • Strategic CTI: High-level trends and risk framing for executives and policymakers, covering things like which threat actor groups are targeting a sector or region.
  • Operational CTI: Detail on a specific campaign or incident, used by investigators and incident responders to understand an active threat.
  • Tactical CTI: The tactics, techniques, and procedures (TTPs) attackers use, mapped to frameworks like MITRE ATT&CK, so defenders know what behavior to watch for.
  • Technical CTI: Machine-readable indicators of compromise (IOCs) such as malicious IPs, domains, file hashes, and malware signatures, consumed directly by security tools.

CTI draws on multiple source types to build this picture, including open source intelligence, dark web and deep web intelligence, commercial threat feeds, malware analysis, and information-sharing partnerships between the public and private sector.

{{54-cyber-threat-intelligence-glossary-callout-1}}

{{horizontal-line}}

How does cyber threat intelligence work?

CTI is typically produced through a six-stage lifecycle:

Stage What it involves
Planning and direction Defining the intelligence requirements: which threats, sectors, or actors matter most to the organization
Collection Gathering raw data from technical feeds, OSINT, dark web sources, malware repositories, and human source
Processing Normalizing and structuring that raw data so it can be analyzed, often correlating indicators across multiple sources
Analysis Turning processed data into findings: attribution, motive, likely next steps, and confidence level
Dissemination Delivering the finished intelligence to the people who need it, in the format they need it in, whether that's a technical feed for a SOC or a briefing for leadership
Feedback Using how the intelligence was used (or not used) to refine future collection priorities

Each cycle feeds the next. For example, a campaign uncovered during analysis often reshapes what intelligence an organization collects going forward.

{{horizontal-line}}

How do different teams use CTI?

CTI translates the same underlying signal — an attacker's identity, infrastructure, and intent — into a different action depending on the team using it. Security and CTI teams hunt and detect known infrastructure, investigators build attribution into a case, fraud and financial crime teams assess exposure at financial institutions, corporate security teams manage enterprise risk, compliance and government bodies apply it to due diligence and policy, and law enforcement disrupts the infrastructure directly.

CTI and security operations teams

CTI shifts detection from reactive to anticipatory. Instead of waiting for an alert, teams can hunt for the specific infrastructure and behavior a known threat actor uses.

Investigators and case teams

CTI provides attribution and context, enabling investigators to answer questions like, "Whose infrastructure is this?", "What else have they done?", and "Where has this pattern shown up before?". That context turns an isolated technical finding into a case with a subject.

Financial crime and fraud teams

Banks and other financial institutions increasingly see cyber intrusions and payment fraud as the same problem: a compromised credential or a phished employee often leads directly to an account takeover or a fraudulent wire. CTI lets fraud and cyber teams work from the same picture of an attacker's infrastructure, instead of treating the two as separate cases.

Corporate security and enterprise risk teams

CTI helps corporate security and enterprise risk teams assess exposure from vendors, executives, and infrastructure before an incident (e.g. ransomware attacks, business email compromise, insider threats), not just respond after one.

Compliance, sanctions, and supply chain risk teams

CTI increasingly informs due diligence, sanctions screening, and supply chain risk assessments, particularly where cybercriminal infrastructure overlaps with sanctioned entities, ransomware payment networks, or compromised vendors upstream of an organization.

Regulatory and policy teams

Regulators and policymakers use aggregated CTI trends (e.g. which sectors are targeted or which techniques are rising) to calibrate supervisory guidance and incident-reporting requirements, even when they aren't running tactical investigations themselves. This is the strategic CTI described above, applied at the level of a sector or jurisdiction rather than a single case.

National security and law enforcement teams

CTI is foundational to identifying and disrupting the infrastructure behind ransomware, nation-state intrusions, and cyber-enabled fraud before losses compound. The FBI's Internet Crime Complaint Center reported more than USD 20.8 billion in losses from cyber-enabled crime in 2025 — a scale that makes early, well-attributed CTI a priority.

{{horizontal-line}}

What are the biggest challenges in cyber threat intelligence today?

Three challenges dominate most CTI programs:

  1. Volume: The number of feeds, alerts, and indicators available today outpaces most teams' ability to review them manually.
  2. Fragmentation: CTI, OSINT, dark web monitoring, and financial intelligence often live in separate tools with no shared case view, so analysts spend more time stitching context together than analyzing it. 
  3. Attribution confidence: Distinguishing a new threat actor from reused infrastructure or a copycat requires corroborating evidence across sources, not a single indicator.

{{horizontal-line}}

Frequently asked questions (FAQs)

1. What is the difference between cyber threat intelligence (CTI) and a threat feed?

A threat feed is a stream of raw indicators (e.g. IPs, hashes, domains). CTI is the analyzed product built from those indicators — including attribution, context, and confidence level — that tells a team what the indicators mean and what to do about them.

2. What is the difference between CTI and OSINT?

Open-source intelligence (OSINT) is one collection method — gathering publicly available information. Cyber threat intelligence (CTI) is the broader discipline of turning collected information — including OSINT, technical feeds, and dark web monitoring — into intelligence specifically about cyber threats.

3. Who typically uses cyber threat intelligence?

Security operations centers (SOCs), incident responders, threat hunters, dedicated CTI or threat intelligence teams, fraud and compliance teams, and government agencies investigating cyber crime or nation-state activity all consume CTI, usually in different formats suited to their role.

4. How is CTI shared across organizations?

Through information-sharing partnerships, industry ISACs (Information Sharing and Analysis Centers), and government programs. The Cybersecurity and Infrastructure Security Agency (CISA) runs several such programs for cyber threat information sharing between public and private sector organizations.

Subscribe and stay up to date with our insights

Access our coverage of TRON, Solana and 23 other blockchains

Fill out the form to speak with our team about investigative professional services.

Services of interest
Select
Transaction Monitoring/Wallet Screening
Training Services
Training Services
 
By clicking the button below, you agree to the TRM Labs Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

MITRE ATT&CK is a free, publicly maintained knowledge base of real-world adversary tactics and techniques, organized into a matrix that maps how attackers typically operate at each stage of an intrusion. CTI teams use it as a common reference to describe threat actor behavior, map detections, and compare coverage across tools.