| description | Cyber threat intelligence and OSINT resources for indicators, threat data, enrichment, source evaluation, and intelligence workflows. |
|---|
Cyber intelligence turns public and private security data into decisions: what matters, why it matters, who needs to know, and what action should follow. This section covers CTI concepts, feed management, indicator enrichment, and OSINT workflows.
- Collect actionable intelligence - Gather reporting, advisories, technical indicators, campaign details, vulnerabilities, and public-source evidence.
- Manage indicators - Evaluate source quality, indicator fidelity, decay, false positives, and how feeds integrate with security tools.
- Enrich indicators - Add context such as ASN, domain age, passive DNS, actor reporting, campaign links, observed malware, infrastructure relationships, and blacklist/reputation results.
- Produce and disseminate intelligence - Turn findings into useful outputs for defenders, leaders, incident responders, vulnerability teams, or investigators.
{% content-ref url="intel-feeds-and-sources.md" %} intel-feeds-and-sources.md {% endcontent-ref %}
{% content-ref url="threat-data.md" %} threat-data.md {% endcontent-ref %}
{% content-ref url="osint/" %} osint {% endcontent-ref %}
- Cyber Threat Intelligence (CTI) - Analysis of adversary capabilities, intent, infrastructure, targets, tooling, TTPs, indicators, and operational impact.
- Open-Source Intelligence (OSINT) - Publicly available information collected and analyzed to answer an intelligence requirement.
- Geospatial Intelligence (GEOINT) - Location-focused analysis using maps, imagery, satellite data, terrain, and geospatial context.
- Imagery Intelligence (IMINT) - Image and media analysis, including visual verification and metadata review.
{% content-ref url="osint/files-media-breach-paste-code.md" %} files-media-breach-paste-code.md {% endcontent-ref %}
- Signals Intelligence (SIGINT) - Intelligence derived from communications or electronic signals. This guide treats public SIGINT-like resources cautiously and keeps practical workflows inside OSINT.
- Human Intelligence (HUMINT) - Intelligence from human sources. In this guide, authorized public-source interviews, debriefs, and community reporting are more relevant than espionage-style HUMINT.
- Measurement and Signature Intelligence (MASINT) - Technical signatures derived from physical or measurable characteristics. This is mostly outside the practical scope of the guide.
The intelligence cycle is the process for turning requirements into useful products:
- Planning and direction - Define the question and decision the intelligence must support.
- Collection - Gather relevant data from sources that can answer the requirement.
- Processing - Normalize, deduplicate, index, translate, enrich, and prepare the data for analysis.
- Analysis and production - Assess the evidence, identify confidence levels, and produce the intelligence output.
- Dissemination - Deliver the output to the people or systems that can act on it.
- Feedback and evaluation - Learn whether the output helped and refine the next requirement.
The cycle is iterative. Analysis often exposes new collection gaps, and feedback can change the original requirement.
- Intelligence.gov: How Intelligence Works
- Sergio Caltagirone: Intelligence Cycle
- Sergio Caltagirone: F3EAD
- Joint Publication 2-0: Joint Intelligence
- Psychology of Intelligence Analysis
- Getting Started with ATT&CK: Threat Intelligence
- Using ATT&CK to Advance Cyber Threat Intelligence - Part 1
- Using ATT&CK to Advance Cyber Threat Intelligence - Part 2
- SANS: ATT&CKing the Status Quo
CTI and OSINT training resources have been moved to Training.
{% content-ref url="../training/" %} training {% endcontent-ref %}
.png)