7.1 Cyber Threat Intelligence (CTI) Lifecycle and Intelligence Types
Key Takeaways
- Cyber Threat Intelligence (CTI) is evidence-based knowledge—incorporating context, mechanisms, indicators, implications, and actionable advice—regarding existing or emerging hazards to digital assets.
- The 6-phase CTI lifecycle (Direction, Collection, Processing, Analysis, Dissemination, Feedback) operationalizes intelligence by aligning collection with Priority Intelligence Requirements (PIRs) and refining outputs iteratively.
- Threat intelligence is categorized into four operational tiers: Strategic (executive risk governance), Tactical (adversary TTPs and detection engineering), Operational (imminent campaigns and actor tracking), and Technical (atomic IoCs for perimeter automation).
- FIRST Traffic Light Protocol (TLP 2.0) standardizes information sharing boundaries across five designations: TLP:RED (named recipients only), TLP:AMBER (organization and trusted clients), TLP:AMBER+STRICT (organization only), TLP:GREEN (peer community), and TLP:CLEAR (public).
- Raw security telemetry becomes actionable intelligence only after normalization, deduplication, enrichment, and rigorous analytical evaluation through structured frameworks like the Diamond Model and MITRE ATT&CK.
Foundations of Cyber Threat Intelligence (CTI)
In modern Security Operations Centers (SOCs), defending an enterprise strictly through reactive, signature-based detection is insufficient against advanced persistent threats (APTs) and sophisticated cybercrime syndicates. Cyber Threat Intelligence (CTI) transforms security operations from a reactive posture into an active, proactive, and predictive defense. CTI is defined as evidence-based knowledge—including context, mechanisms, indicators, implications, and actionable advice—about an existing or emerging menace or hazard to assets. It bridges the gap between raw data generated by IT systems and strategic decisions made by business leaders.
The Hierarchy: Data, Information, and Intelligence
A common pitfall in SOC engineering is treating high-volume indicator feeds as intelligence. Security leaders differentiate these concepts through a three-tier hierarchy:
- Raw Threat Data: Unprocessed, discrete elements stripped of operational context. Examples include an isolated IPv4 address (
198.51.100.44), an unindexed SHA-256 cryptographic hash (e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855), or a raw Snort alert string. Data lacks meaning, relevance, and intent. - Threat Information: Aggregated, structured, and contextualized data points that describe an event. For example, correlating the IP address
198.51.100.44with firewall logs revealing 450 inbound connection attempts targeting TCP port 445 (SMB) across twenty internal endpoints within ten minutes. Information answers what happened and when. - Threat Intelligence: Information that has undergone rigorous analytical processing, evaluation against adversary capabilities, intent, and opportunity, and synthesis into an actionable assessment. For example, identifying that
198.51.100.44belongs to a known Command and Control (C2) node associated with the Lazarus Group, utilized in an active campaign targeting the financial sector using CVE-2024-1709, accompanied by recommended Snort rules, Sigma detection patterns, and host-based YARA rules. Intelligence answers who, why, how, and what action must be taken.
[Evolution from Telemetry to Actionable Intelligence]
Data: 198.51.100.44 (Raw observable string)
│
▼ (Aggregation, Parsing, GeoIP, Port Mapping)
Information: 198.51.100.44 scanned Port 445 on 20 internal hosts at 03:14 UTC
│
▼ (Enrichment, Attribution, Diamond Model Analysis, TTP Mapping)
Intelligence: 198.51.100.44 is an active C2 node of FIN7 conducting pre-ransomware
reconnaissance against VMware Horizon; apply Sigma Rule #8412 and block ASN 64496.
The Six-Phase CTI Lifecycle
To ensure intelligence remains purposeful, accurate, and actionable, military and intelligence communities established the intelligence cycle, adapted specifically for cyber defense. The CTI lifecycle consists of six interconnected, iterative phases.
1. Direction and Planning
The lifecycle begins with establishing objectives aligned with organizational risk. Without clear direction, CTI teams succumb to feed fatigue. The core output of this phase is the establishment of Priority Intelligence Requirements (PIRs) and Specific Intelligence Requirements (SIRs):
- Priority Intelligence Requirements (PIRs): High-level questions mandated by organizational leadership, CISOs, or SOC managers (e.g., "Which ransomware groups are actively targeting healthcare supply chains in North America, and what initial access vectors do they exploit?").
- Specific Intelligence Requirements (SIRs): Granular, technical questions derived from PIRs to guide collection (e.g., "What external-facing VPN vulnerabilities are exploited by BlackCat/ALPHV, and what IP ranges host their leak sites?").
- Scope & Resource Allocation: Determining which threat vectors to monitor, compliance mandates, and operational service level agreements (SLAs).
2. Collection
Once requirements are established, analysts collect raw data and information from diverse sources across internal and external perimeters:
- Internal Sources: SIEM telemetry, EDR sensor events, firewall/proxy logs, honeypots, honeytokens, previous incident response forensic disk images, and user phishing submissions.
- External Sources: Commercial intelligence feeds (Recorded Future, Mandiant, CrowdStrike Falcon X), open-source intelligence (OSINT), vulnerability databases (NVD/CVE), dark web actor forums, and Information Sharing and Analysis Centers (ISACs).
3. Processing and Exploitation
Raw collection data arrives in incompatible formats (unstructured text, JSON, XML, PDF, PCAP). Processing normalizes this data into structured, machine-consumable schemas:
- Data Normalization & Deduplication: Eliminating redundant indicators across multiple commercial feeds and standardizing timestamps to UTC (ISO 8601).
- Enrichment: Augmenting IP addresses with Autonomous System Numbers (ASN), BGP routing prefixes, geolocation, and WHOIS registration metadata.
- Translation & Parsing: Parsing PDF threat reports using natural language processing (NLP) to extract Indicators of Compromise (IoCs) and converting them into STIX 2.1 JSON.
4. Analysis and Production
Analysis is the intellectual core where processed information is converted into genuine intelligence. Analysts synthesize disparate indicators to deduce adversary intent, capability, and attack progression:
- Structured Analytic Techniques: Employing methods like Analysis of Competing Hypotheses (ACH) to eliminate cognitive bias when attributing attacks.
- Intrusion Frameworks: Mapping observations against the Diamond Model of Intrusion Analysis (Adversary, Capability, Infrastructure, Victim) and the MITRE ATT&CK matrix to identify gaps in enterprise visibility.
- Production: Generating tailored deliverables ranging from machine-readable threat feeds to finished tactical advisories and executive briefings.
5. Dissemination and Integration
Delivering the produced intelligence to the appropriate stakeholders in the required format at the right time. Dissemination must be tailored to consumer needs:
- Machine-to-Machine: Automated TAXII feeds pushing IoCs directly to firewalls, EDR blocklists, and SIEM lookup tables.
- Human-to-Human: Detailed technical advisories to Tier 2/3 incident responders, detection engineers, and high-level briefing slide decks to the C-suite.
6. Feedback and Evaluation
The lifecycle is continuous. In the feedback phase, consumers evaluate whether the intelligence addressed the initial PIRs:
- Did the intelligence prevent an intrusion or accelerate alert triage?
- Did an ingested indicator list trigger excessive false positives in the SIEM?
- Feedback directly informs the next iteration of the Direction and Planning phase, refining PIRs and retiring obsolete intelligence feeds.
The Four Intelligence Types
CTI is categorized into four tiers based on audience, purpose, technical granularity, and operational lifespan: Strategic, Tactical, Operational, and Technical.
Strategic Threat Intelligence
- Target Audience: Board of Directors, Chief Executive Officer (CEO), Chief Information Security Officer (CISO), and enterprise risk executives.
- Core Purpose: Informs high-level corporate risk governance, capital allocation, security policy formulation, and multi-year defense investments.
- Characteristics: High-level, non-technical executive summaries. Analyzes geopolitical dynamics, nation-state cyber capabilities, industry-specific threat landscapes, and regulatory compliance risks.
- Example: A 15-page quarterly report assessing how geopolitical tensions in the Asia-Pacific region heighten the risk of state-sponsored destructive wiper malware targeting commercial maritime logistics.
Tactical Threat Intelligence
- Target Audience: SOC analysts (Tier 1-3), detection engineers, security architects, and system administrators.
- Core Purpose: Informs detection engineering, threat hunting playbooks, and perimeter defense tuning.
- Characteristics: Focuses on adversary Tactics, Techniques, and Procedures (TTPs), attack methodologies, tool usage, and evasion strategies. Typically mapped to the MITRE ATT&CK framework.
- Example: A technical bulletin detailing how threat actor APT29 utilizes PowerShell command obfuscation (
-enc), scheduled task persistence (schtasks /create), and LSASS memory dumping viacomsvcs.dllto harvest enterprise credentials, complete with corresponding Sigma and YARA detection rules.
Operational Threat Intelligence
- Target Audience: Incident Response (IR) teams, threat hunt leads, and SOC managers.
- Core Purpose: Provides immediate actionable context on specific, imminent, or ongoing adversary campaigns targeting the organization or its direct sector.
- Characteristics: Covers adversary infrastructure, attack staging, command-and-control communication schedules, specialized toolsets, and campaign timing. Answers who is attacking us right now, how are they organized, and what are their staging servers?
- Example: An emergency bulletin tracking an active FIN7 campaign utilizing newly registered lookalike domains imitating the enterprise's corporate HR portal to execute spear-phishing attacks delivering a customized Carbanak backdoor payload.
Technical Threat Intelligence
- Target Audience: Automated security appliances, firewalls, Web Application Firewalls (WAFs), Intrusion Detection/Prevention Systems (IDS/IPS), EDR, and SIEM correlation engines.
- Core Purpose: Powers automated, real-time perimeter blocking, endpoint process termination, and event correlation.
- Characteristics: Composed of atomic Indicators of Compromise (IoCs). High volume, highly perishable (lifespan often measured in days or hours). Trivial for adversaries to alter.
- Example: A real-time STIX/TAXII feed containing 5,000 SHA-256 hashes of DarkSide ransomware binaries, 250 malicious C2 IPv4 addresses, and 45 phishing domain URLs ingested directly into firewall ACLs and SIEM lookup tables.
CTI Types Comparison Matrix
| Attribute | Strategic Intelligence | Tactical Intelligence | Operational Intelligence | Technical Intelligence |
|---|---|---|---|---|
| Primary Audience | Board, CISO, CIO, Risk Officers | SOC Analysts, Detection Engineers | Incident Responders, Threat Hunters | Automated Tools, SIEM, Firewalls, EDR |
| Core Purpose | Long-term strategy & risk posture | Detection rules & defensive hardening | Incident scoping & campaign disruption | Automated blocking & atomic matching |
| Time Horizon | Months to years | Weeks to months | Days to weeks | Hours to days |
| Technical Detail | Very Low (business language) | High (TTPs, MITRE ATT&CK mappings) | Medium-High (campaign infrastructure) | Extreme (raw hashes, IPs, domains) |
| Lifespan / Durability | Highly durable | Moderate-High durability | Low-Moderate durability | Extremely perishable (Pyramid base) |
| Primary Formats | Executive PDFs, presentations, whitepapers | Sigma rules, YARA rules, ATT&CK Navigator | Campaign reports, actor dossiers, IOC sets | STIX 2.1, TAXII feeds, CSV, JSON feeds |
| Operational Example | Geopolitical risk report on ransomware | Cobalt Strike Malleable C2 detection logic | Active phishing campaign infrastructure dossier | Blacklisted IP list ingested into perimeter WAF |
Traffic Light Protocol (TLP 2.0)
Information sharing across security communities, ISACs, and trusted peer organizations requires clear, unambiguous boundaries governing who may access the intelligence and how it may be shared. The Traffic Light Protocol (TLP) was established by the Forum of Incident Response and Security Teams (FIRST) to standardize these sharing designations.
In August 2022, FIRST officially released TLP 2.0, superseding TLP 1.0. TLP 2.0 introduced two critical updates:
- TLP:WHITE was replaced by TLP:CLEAR to avoid racialized connotations and align with open-source terminology.
- TLP:AMBER+STRICT was introduced to provide an explicit distinction between sharing strictly within an organization versus sharing with trusted clients and supply-chain partners.
TLP 2.0 Sharing Protocol Matrix
| TLP Level | Color Hex Code | Sharing Permitted Scope | Handling & Disclosure Restrictions | Operational Example |
|---|---|---|---|---|
| TLP:RED | #FF0000 | Strictly individual recipients only | Non-releasable. In the context of a meeting, restricted strictly to attendees. Cannot be shared with anyone else in the organization. | Sensitive zero-day exploit details disclosed under strict NDA during an emergency closed-door task force meeting. |
| TLP:AMBER | #FFC000 | Recipient organization and trusted clients | Limited disclosure. Information may be shared within the recipient's organization and with its clients who need the information to protect their infrastructure. | An ISAC bulletin detailing an ongoing credential-stuffing attack targeting financial portals, shared with member banks and their IT vendors. |
| TLP:AMBER+STRICT | #FFC000 | Recipient organization ONLY | Restricted disclosure. Information is strictly confined to the recipient's home organization; no third-party clients, contractors, or partners may see it. | Threat intelligence regarding an active insider threat investigation or proprietary supply-chain vulnerability affecting internal systems only. |
| TLP:GREEN | #00FF00 | Community and sector peer partners | Community disclosure. May be shared within the wider cybersecurity community, peer enterprises, and sector partners. Not for public release. | An advisory shared across Health-ISAC members documenting medical device firmware scanning patterns observed in peer hospitals. |
| TLP:CLEAR | #FFFFFF | World-at-large (Public) | Unrestricted. May be distributed freely to the public, published on websites, and posted to social media, subject to standard copyright laws. | Public CISA Cybersecurity Advisories (CSAs) and published vendor blogs regarding patched vulnerabilities (e.g., Log4j). |
[TLP 2.0 Sharing Boundary Enforcement]
TLP:RED ──────────► Individual Recipients Only (No internal / external forwarding)
TLP:AMBER+STRICT ─► Home Organization Only (Internal SOC / IT; NO clients/vendors)
TLP:AMBER ────────► Home Organization + Trusted Direct Clients / Partners
TLP:GREEN ────────► Industry Community Peers / ISAC Sharing Group (No public web)
TLP:CLEAR ────────► World-at-Large (Unrestricted public dissemination)
During which phase of the Cyber Threat Intelligence (CTI) lifecycle does security leadership establish Priority Intelligence Requirements (PIRs) to align threat data collection with enterprise business risks?
A senior SOC engineer develops a detection package containing Sigma rules to flag Cobalt Strike malleable C2 profiles, process hollowing techniques, and PowerShell execution arguments. Under which CTI classification tier does this intelligence fall?
A financial institution receives a threat advisory from an ISAC marked TLP:AMBER+STRICT regarding an active exploitation campaign targeting banking core APIs. How must the recipient organization handle this advisory?
Which CTI classification tier is specifically developed for the Board of Directors and Chief Information Security Officer (CISO) to guide multi-year cybersecurity capital investments and evaluate macroeconomic cyber risk?