Module
What Threat Intelligence Is
Threat intelligence does not arrive in an invoice. It starts with the artifacts your own incidents already produced, and it ends when somebody makes a different decision. Four lessons on what counts, what does not, and who it is for.
40 min · Beginner
Start What Threat Intelligence Is
What you will learn
- Take an artifact off your own incident and turn it into a question worth answering
- Place an artifact on the data, information or intelligence rung and say what is missing
- Name the single step that promotes information to intelligence
- Place an intel product at the tactical, operational or strategic level and name its consumer
- State the decision a product is meant to change before you write it
Lessons
The Phish That Was Not One Phish
A closed case leaves artifacts behind. What they are, why none of them is intelligence yet, and how to turn one into a question.
Data, Information, Intelligence
Three words the industry uses interchangeably and doctrine does not. Which rung an artifact is on, and the single step that promotes it.
Tactical, Operational, Strategic
The same campaign described three ways for three readers. Which altitude a product belongs at, who consumes it, and how long it stays true.
Intelligence That Changes a Decision
The test that separates an intel product from a newsletter. Name the decision and the consumer before you write a word.