Cyber Threat Intelligence Basics: Understanding CTI
Learn the fundamentals of Cyber Threat Intelligence (CTI). Understand the intelligence cycle, IOC types, TTPs, MITRE ATT&CK, and tools for CTI including Maltego, Shodan, and MISP.
# Cyber Threat Intelligence Basics: Understanding CTI
Cyber Threat Intelligence (CTI) is the practice of collecting, analyzing, and sharing information about cyber threats to improve defensive capabilities. What follows outlines CTI fundamentals, including the intelligence cycle, IOC types, TTPs, MITRE ATT&CK framework, and essential CTI tools including [Maltego](/tools/maltego).
Threat Intelligence Methodology
CTI is a methodology for collecting, analyzing, and operationalizing evidence-based knowledge about cyber threats. Rather than reacting to incidents after damage occurs, threat intelligence systematically gathers data on threats, actors, TTPs, IOCs, and vulnerabilities to enable proactive defense. This intelligence-driven approach transforms raw threat data into actionable security decisions.
The Intelligence Cycle
CTI follows a structured intelligence cycle:
1. Planning and Direction
Objective: Define intelligence requirements
Activities:
Questions:
2. Collection
Objective: Gather raw data from multiple sources
Sources:
Tools:
3. Processing
Objective: Convert raw data into usable format
Activities:
Output:
4. Analysis
Objective: Transform processed data into intelligence
Activities:
Output:
5. Dissemination
Objective: Share intelligence with stakeholders
Formats:
Audiences:
6. Feedback
Objective: Refine intelligence based on results
Activities:
IOC Types
Indicators of Compromise (IOCs) are technical artifacts indicating malicious activity.
Network-Based IOCs
| IOC Type | Example | Detection Method |
|----------|---------|------------------|
| IP Address | 192.168.1.100 | Firewall logs, IDS |
| Domain | malicious-domain.com | DNS logs, web proxy |
| URL | https://malicious.com/payload | Web proxy, endpoint |
| Email | attacker@malicious.com | Email gateway |
| Certificate | SHA256 hash | Network inspection |
Host-Based IOCs
| IOC Type | Example | Detection Method |
|----------|---------|------------------|
| File Hash | SHA256:abc123... | Endpoint detection |
| File Name | malware.exe | File integrity monitoring |
| Registry Key | HKLM\Software\Malware | Registry monitoring |
| Process | suspicious-process.exe | Process monitoring |
| Service | MaliciousService | Service monitoring |
Behavioral IOCs
| IOC Type | Example | Detection Method |
|----------|---------|------------------|
| Unusual Traffic | High volume outbound | Network monitoring |
| Authentication | Brute force attempts | Authentication logs |
| Data Access | Unusual file access | File access monitoring |
| Process Behavior | Unusual process tree | Process monitoring |
IOC Management
Effective IOC management requires:
TTPs (Tactics, Techniques, and Procedures)
TTPs describe how adversaries operate, providing context beyond technical indicators.
Tactics
High-level goals of adversaries:
| Tactic | Description | Example |
|--------|-------------|---------|
| Reconnaissance | Information gathering | Scanning, OSINT |
| Resource Development | Building capabilities | Infrastructure setup |
| Initial Access | Gaining foothold | Phishing, exploits |
| Execution | Running code | Command execution |
| Persistence | Maintaining access | Backdoors, scheduled tasks |
| Privilege Escalation | Gaining higher access | Exploiting vulnerabilities |
| Defense Evasion | Avoiding detection | Obfuscation, disabling tools |
| Credential Access | Stealing credentials | Password dumping |
| Discovery | Mapping environment | Network scanning |
| Lateral Movement | Moving through network | Pass-the-hash |
| Collection | Gathering data | File collection |
| Command and Control | Communicating with C2 | DNS, HTTP channels |
| Exfiltration | Stealing data | Data compression, encryption |
| Impact | Disrupting operations | Ransomware, data destruction |
Techniques
Specific methods used to achieve tactics:
| Technique | Tactic | Description |
|-----------|--------|-------------|
| Phishing | Initial Access | Social engineering via email |
| Drive-by Compromise | Initial Access | Exploiting web browsers |
| Supply Chain Compromise | Initial Access | Compromising trusted software |
| PowerShell | Execution | Script execution |
| Scheduled Tasks | Persistence | Automated execution |
| Account Manipulation | Persistence | Modifying accounts |
| Process Injection | Defense Evasion | Hiding in legitimate processes |
| Brute Force | Credential Access | Password guessing |
| OS Credential Dumping | Credential Access | Stealing password hashes |
| Network Service Discovery | Discovery | Scanning for services |
| Remote Services | Lateral Movement | Using remote access |
| Data from Cloud Storage | Collection | Accessing cloud data |
| DNS | Command and Control | Using DNS for C2 |
| Exfiltration Over Web Service | Exfiltration | Using web services for data theft |
Procedures
Specific implementations of techniques:
Example: Phishing Campaign
Example: Credential Theft
MITRE ATT&CK
MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques.
ATT&CK Matrix
The ATT&CK Matrix organizes techniques by tactic:
| Tactic | Techniques | Sub-Techniques |
|--------|------------|----------------|
| Reconnaissance | 10 | 31 |
| Resource Development | 7 | 18 |
| Initial Access | 9 | 24 |
| Execution | 14 | 27 |
| Persistence | 19 | 88 |
| Privilege Escalation | 13 | 28 |
| Defense Evasion | 42 | 159 |
| Credential Access | 17 | 47 |
| Discovery | 31 | 130 |
| Lateral Movement | 9 | 13 |
| Collection | 17 | 53 |
| Command and Control | 16 | 51 |
| Exfiltration | 9 | 9 |
| Impact | 13 | 14 |
Using ATT&CK for CTI
ATT&CK Resources
CTI Tools
Maltego
[Maltego](/tools/maltego) provides graph-based CTI analysis:
Capabilities:
CTI Use Cases:
Integrations:
Shodan
Shodan is a search engine for internet-connected devices:
Capabilities:
CTI Use Cases:
MISP (Malware Information Sharing Platform)
MISP is an open-source threat intelligence platform:
Capabilities:
CTI Use Cases:
Other CTI Tools
| Tool | Purpose | Type |
|------|---------|------|
| VirusTotal | Malware analysis | Commercial/Free |
| AlienVault OTX | Threat intelligence | Free/Open source |
| AbuseIPDB | IP reputation | Free/Commercial |
| PhishTank | Phishing detection | Free |
| URLhaus | Malware URL tracking | Free |
| GreyNoise | Internet scanning | Commercial/Free |
| SecurityTrails | DNS intelligence | Commercial/Free |
Tool Integration
Integrate CTI tools for comprehensive coverage:
Practical CTI Applications
Threat Intelligence Report
Create comprehensive threat intelligence reports:
Incident Response CTI
Apply CTI during incident response:
Threat Hunting
Use CTI to guide threat hunting:
CTI Best Practices
Data Quality
Operational Security
Process Improvement
Legal and Ethical
Conclusion
Cyber Threat Intelligence is essential for modern security operations. By understanding the intelligence cycle, IOC types, TTPs, and MITRE ATT&CK, organizations can build proactive defense capabilities.
Tools like [Maltego](/tools/maltego), Shodan, and MISP provide powerful capabilities for CTI collection, analysis, and sharing. Combine these tools with sound methodology and analytical skills to produce actionable threat intelligence.
For related topics, explore [OSINT for Blue Team](/learn/osint-for-blue-team) for defensive intelligence and [OSINT Investigation Workflow](/learn/osint-investigation-workflow) for structured investigation methodology.