Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
What Cyber Threat Intelligence Is
TheoryBeginner13 minThreat Intelligence

Data, Information, Intelligence

What is it?

Data is a raw fact (an IP address). Information is data with context (that IP contacted a finance server at 3am). Intelligence is analyzed, assessed information that answers a decision-maker's question (that IP is likely this actor's C2, so block it and hunt for the technique). CTI is the discipline of climbing that ladder.

Why it matters

Most 'threat intel' delivered in practice is just data — indicator lists. Knowing the difference is what turns an analyst into an intelligence producer, not a feed forwarder.

Where you see it

Every CTI product, feed, and report — judged by where on the ladder it sits.

What normal looks like

A product that states an assessment, its confidence, and a recommended action — not just a list of artifacts.

What suspicious looks like

Not applicable directly — this is a conceptual distinction, not a finding.

How analysts investigate

By asking of any product: does it answer a decision-maker's question with an assessment, or does it just hand over facts to be interpreted?

Common beginner mistakes

  • Calling an indicator feed 'intelligence' — a list of IPs with no assessment is data, and treating it as a finished product skips the analysis that makes it useful.

Sahab Telecom's SOC receives a feed of 5,000 malicious IPs daily. That is data. The CTI team's job is to turn the relevant fraction into intelligence: which of these actually target telecoms, what technique they precede, and what Sahab should do about it.

Quick check

Which of these is intelligence, not merely data or information?

A quick self-check — it doesn't affect your XP or progress.

Sign in to save your progress on the server.