From Data to Decision: What Threat Intelligence Is (and Isn't)
What is it?
Threat intelligence is analysed knowledge about adversaries that answers a decision-maker's question. It is the end of a chain: raw data (an IP, a hash) becomes information when given context (this IP is a C2 server), and becomes intelligence only when analysed to support a decision (this actor is targeting our sector, so we should hunt for their technique). A feed of indicators is not intelligence until someone analyses it against a question.
Why it matters
SOCs drown in feeds — millions of indicators, most irrelevant. The Tier-2 skill is not collecting more data but turning the right data into a decision: which alerts to prioritise, which actor to prepare for, which hunt to run next. Confusing a raw feed with intelligence wastes effort chasing indicators that answer no question; real intelligence changes what the team does.
Where you see it
Intelligence is produced through a cycle — direction (what do we need to know), collection (feeds, reports, telemetry), processing, analysis, and dissemination to whoever acts on it. It comes at three altitudes: strategic (board-level trends), operational (a campaign against our sector), and tactical (the specific TTPs and indicators an analyst uses today).
What normal looks like
Useful intelligence is tied to a requirement and an action: 'a ransomware group active in our industry uses this initial-access technique, so we hunt for it this week'. It names a source, a confidence level, and what to do — and it changes a decision.
What suspicious looks like
A red flag is a giant list of indicators with no context, no source reliability, and no link to any decision — a feed masquerading as intelligence. Blocking or hunting on it wholesale generates false positives and busywork without reducing risk. Volume is not value.
How analysts investigate
Start from the question, not the feed. Ask what decision needs support, then pull and analyse only the data that answers it, note the source and confidence, and state the action. If an indicator or report changes no decision, it is not intelligence for you today — set it aside.
Common beginner mistakes
- Treating a raw indicator feed as intelligence and acting on it without context or a question.
- Measuring value by volume — more indicators, not better decisions.
- Ignoring source reliability and confidence, so weak and strong claims are treated alike.
What you will be able to do
- Distinguish data, information and intelligence, and say why it matters.
- Place an intelligence product at the strategic, operational or tactical level.
- Reject a raw feed that answers no decision.
In Module 5 you pulled indicators out of one detonation. That is data. The question this module answers is: so what? Whose indicators are these, is this actor a threat to us, and what should we do differently because of it? Turning indicators into that answer is the whole job of threat intelligence — and it starts by refusing to confuse a feed with a decision.
| Stage | Example | Usable alone? |
|---|---|---|
| Data | 45.9.148.200 | No — no meaning |
| Information | That IP is a known C2 server | Partly |
| Intelligence | A group using it targets our sector — hunt their technique | Yes — drives a decision |
Worked example — feed or intelligence?
ITEM A: a CSV of 40,000 IP addresses, no context, no source, 'block these'
ITEM B: report — 'actor FIN-native targets finance firms via invoice-lure
attachments; initial access = spearphishing attachment; medium confidence'The answer: Item B is intelligence; Item A is a raw feed. Item A has no context, no source reliability, and no link to a decision — blocking 40,000 IPs blindly guarantees false positives and outages while proving nothing. Item B names an actor, a targeted sector (yours), a specific technique, and a confidence level — it answers 'are we at risk and what do we do?' with 'hunt for spearphishing-attachment initial access this week'. One is volume; the other changes what the team does.
Recap
- Data → information → intelligence; only the last, analysed against a question, drives a decision.
- Intelligence comes at strategic, operational and tactical altitudes.
- A raw feed with no context or decision is not intelligence — volume is not value.
Sign in to save your progress on the server.