Precursor Security
Glossary

Threat Intelligence

Threat intelligence is evidence-based knowledge about adversaries (their tools, techniques, infrastructure and targets) used to inform security decisions. Operational threat intelligence maps indicators and TTPs to frameworks like MITRE ATT&CK so defenders can detect and pre-empt attacks.

Threat intelligence spans strategic (who and why), operational (how, mapped to ATT&CK) and tactical (indicators of compromise) levels. Its value depends on relevance and freshness, not volume.

Much of the market resells the same commercial feeds with little differentiation. What separates platforms is the exploitation signal they fuse in and how they turn it into a defensible priority order.

Threat intelligence is commonly described in three layers. Strategic intelligence informs executive and risk decisions with a high-level view of the threat landscape. Operational intelligence describes the campaigns and techniques of specific adversaries. Tactical intelligence provides the concrete indicators, such as malicious addresses and file hashes, that feed detection tools. A complete programme uses all three for different audiences and purposes.

The value of threat intelligence lies in making it relevant and actionable. Raw feeds of indicators are abundant and cheap, but volume without context creates noise. Useful intelligence is filtered to an organisation’s sector and technology, enriched with context about who is behind a threat and why it matters, and delivered where it can drive a decision or a detection rather than sitting in a report.

A durable theme in the field is the shift from indicators to behaviour. Indicators such as IP addresses and hashes change constantly as attackers rotate infrastructure, so intelligence built only on them is always chasing the last attack. Mapping adversary behaviour to frameworks like MITRE ATT&CK produces intelligence that ages more slowly, because techniques are harder for an attacker to change than a single address.

Threat intelligence connects to the wider security programme by informing prioritisation, detection and response. It tells a vulnerability programme which flaws are being exploited, tells a detection team which techniques to watch for, and tells responders who they may be dealing with. Its purpose is not knowledge for its own sake but better decisions across the whole of defence.

Threat intelligence is gathered from a wide range of sources. These include open-source intelligence from public reporting and research, commercial and community feeds of indicators, telemetry such as honeypot and sensor data that observes real attacks, and monitoring of criminal forums and marketplaces. The breadth of sourcing matters because no single one gives a complete picture, and combining them produces intelligence that is both broad and corroborated.

Sharing is central to the discipline, and standards such as STIX and TAXII exist so that intelligence can be exchanged in a consistent, machine-readable form between organisations and tools. When one organisation analyses an attack and shares the resulting intelligence, others can detect the same threat proactively, which is the basis of collective defence. Communities and information-sharing partnerships formalise this exchange within sectors and regions.

Precursor Intelligence ingests Shadowserver honeypot exploitation data as a live input signal alongside EPSS, CISA KEV and threat-actor attribution, delivered over a bearer-token REST API and a production MCP server.