Back to glossary

Threat intelligence

2 min read

In security operations, threat intelligence is information about adversaries, refined into something a defender can actually act on. The refining is the whole discipline: raw data about attacks is abundant and nearly free, and the difficulty is turning it into a decision that would otherwise have been made differently.

July 24, 2026
Compartir:

How it works

Three levels serve three audiences. Strategic intelligence describes who is likely to target this sector and why, and informs investment decisions over years. Operational intelligence describes campaigns and adversary behaviour, and informs what to prepare for over months. Tactical intelligence is the artefacts, principally indicators, and informs detection today.

The durability of each level is inverted against its convenience. Indicators are easy to consume and expire quickly, because infrastructure rotates. Behaviour, described as tactics, techniques and procedures and mapped through ATT&CK, is harder to operationalise and lasts, because changing how an operation works costs the adversary real effort.

What goes wrong

Feeds are bought and consumed as volume. A subscription loaded into a SIEM without filtering produces alerts on stale entries, shared hosting and legitimate services, and the noise is what causes an analyst to close the one that mattered. The value of a feed is not its size.

The second failure is intelligence with no requirement behind it. A programme that has not defined what decisions it needs to inform ends up producing reports that are read and change nothing. The test is direct: name the decision this changed. If a briefing about an adversary group did not alter a detection, a control or a priority, it was reading.

Third, relevance is assumed rather than assessed. A report about an actor targeting a sector and geography unlike the client’s is interesting and not actionable, and treating all published intelligence as equally applicable is how teams end up preparing for the adversary with the best publicity rather than the one likely to arrive.

Where this shows up in an audit

The intelligence we produce is about the client rather than about the world: credentials and sessions from their domains appearing in criminal logs, access to their estate being advertised, their brand being impersonated, their data on a leak site, their suppliers compromised. That is narrow, verifiable and immediately actionable, which is the opposite of a generic feed. On the offensive side we use adversary behaviour to select what an exercise emulates, so the techniques we run are ones a plausible attacker uses rather than the ones we happen to like. This is part of how intelligence about your own exposure is collected.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.