Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
What Cyber Threat Intelligence Is
TheoryBeginner14 minThreat Intelligence

Strategic, Operational, Tactical

What is it?

CTI is produced at three levels. Strategic intelligence informs long-term decisions (who threatens us and why) for executives. Operational intelligence describes campaigns and adversary intent for defenders planning response. Tactical intelligence is the technical detail (IOCs, TTPs) for the SOC and hunters. Each has a different audience, timescale, and shelf life.

Why it matters

Delivering tactical IOCs to an executive, or strategic prose to a SOC analyst, wastes both — matching level to audience is what makes intelligence land.

Where you see it

The header of every CTI product, declaring who it is for.

What normal looks like

A product whose depth, language and timescale fit its stated audience.

What suspicious looks like

Not applicable directly.

How analysts investigate

By identifying the decision the product must support, then choosing the level whose audience makes that decision.

Common beginner mistakes

  • Writing one report for everyone — a single document cannot serve an executive's strategic need and a SOC analyst's tactical one at once.

The same Sahab threat produces three products: a board briefing on rising nation-state interest in regional telecoms (strategic), a defender note on the campaign's phases and intent (operational), and an IOC/TTP package for the SOC to detect on (tactical).

Quick check

A CISO needs to justify next year's security budget to the board. Which level of intelligence fits?

A quick self-check — it doesn't affect your XP or progress.

Sign in to save your progress on the server.