Threat Intelligence: Understanding Attackers Before They Strike
Threat Intelligence: systematic collection of threat actor data, attack methods and IoCs. OSINT to commercial feeds, operational use.
Summary: Threat Intelligence (TI) is the systematic collection, analysis, and use of information about cyber threats: Indicators of Compromise (IOCs), Tactics, Techniques, and Procedures (TTPs), threat actors, and their motives. A distinction is made between Strategic (C-Level), Operational (SOC triage), and Tactical Intelligence (technical IOCs). Key sources: MISP, OpenCTI, VirusTotal, CISA, BSI, commercial feeds (Recorded Future, Mandiant, CrowdStrike Falcon Intel).
Sources & References
- [1] MITRE ATT&CK Framework - MITRE Corporation
- [2] STIX 2.1 Standard - OASIS
Questions about this topic?
Our experts advise you free of charge and without obligation.
About the Author
M.Sc. in Internet Security (if(is), Westfälische Hochschule). COO and authorized officer (Prokurist) with expertise in information security consulting and security awareness. Junior professor (Nachwuchsprofessur) for Cyber Security at FOM Hochschule, CISO lecturer at isits AG and doctoral candidate at the Graduierteninstitut NRW.
11 Publikationen
- Understanding Regional Filter Lists: Efficacy and Impact (2025)
- Privacy from 5 PM to 6 AM: Tracking and Transparency Mechanisms in the HbbTV Ecosystem (2025)
- A Platform for Physiological and Behavioral Security (2025)
- Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations Across Different Industries (2025)
- Exploring the Effects of Cybersecurity Awareness and Decision-Making Under Risk (2024)
- Sharing is Caring: Towards Analyzing Attack Surfaces on Shared Hosting Providers (2024)
- On the Similarity of Web Measurements Under Different Experimental Setups (2023)
- People, Processes, Technology - The Cybersecurity Triad (2023)
- Social Media Scraper im Einsatz (2021)
- Digital Risk Management (DRM) (2020)
- New Work - Die Herausforderungen eines modernen ISMS (2024)