Cyber Threat Intelligence (CTI) is a specialized discipline within cybersecurity focused on identifying, analyzing, and interpreting information about potential or active threats to an organization's digital environment. It moves beyond raw security data by applying critical thinking and analytical frameworks to transform telemetry and logs into actionable intelligence. This domain involves monitoring the evolving landscape of threat actors, their tactics, techniques, and procedures (TTPs), and the specific campaigns they launch against various industries. By synthesizing information from diverse sources—including open-source intelligence, dark web monitoring, and internal security logs—CTI professionals provide security operations teams, management, and incident responders with the situational awareness needed to prioritize defenses. The discipline requires both technical expertise in threat analysis and a strong grasp of geopolitical or criminal motivations that drive digital attacks. Effective CTI programs are deeply integrated into the incident response lifecycle, ensuring that indicators of compromise are not merely stored but are used to proactively hunt for threats and harden systems against identified adversary behaviors.
The scope of this domain covers the lifecycle of intelligence production, including planning and direction, collection, processing, analysis, and dissemination. It encompasses the study of adversary infrastructure, malware analysis from an attribution perspective, and the strategic mapping of threats to frameworks like MITRE ATT&CK. It excludes general security monitoring, standard vulnerability management, and generic network administration tasks that do not involve the dedicated analysis of adversary intent or capability.