Understanding threat intelligence

Like some terms in information security and incident response, threat intelligence is a bit nebulous. Various organizations such as the government and academics produce information and data that is often touted as threat intelligence. Various commercial providers also have information available, either through free or paid subscriptions, that is touted as threat intelligence. This often results in difficulty when determining what threat intelligence is and what, simply, data or information is.

A good starting point to determine what comprises threat intelligence is to utilize a definition. Here is the Gartner research company's definition of threat intelligence:

"Threat intelligence is evidence-based knowledge, ...

Get Digital Forensics and Incident Response - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.