GO KALI FREE
BeginnerThreat Intelligence

Cyber Threat Intelligence Basics: Understanding CTI

Learn the fundamentals of Cyber Threat Intelligence (CTI). Understand the intelligence cycle, IOC types, TTPs, MITRE ATT&CK, and tools for CTI including Maltego, Shodan, and MISP.

#cyber-threat-intelligence#cti#mitre-attack#ioc#ttp#maltego#shodan#misp

# Cyber Threat Intelligence Basics: Understanding CTI

Cyber Threat Intelligence (CTI) is the practice of collecting, analyzing, and sharing information about cyber threats to improve defensive capabilities. What follows outlines CTI fundamentals, including the intelligence cycle, IOC types, TTPs, MITRE ATT&CK framework, and essential CTI tools including [Maltego](/tools/maltego).

Threat Intelligence Methodology

CTI is a methodology for collecting, analyzing, and operationalizing evidence-based knowledge about cyber threats. Rather than reacting to incidents after damage occurs, threat intelligence systematically gathers data on threats, actors, TTPs, IOCs, and vulnerabilities to enable proactive defense. This intelligence-driven approach transforms raw threat data into actionable security decisions.

The Intelligence Cycle

CTI follows a structured intelligence cycle:

1. Planning and Direction

Objective: Define intelligence requirements

Activities:

  • Identify information gaps
  • Prioritize intelligence needs
  • Define collection requirements
  • Establish processing priorities
  • Questions:

  • What threats are most relevant?
  • What information do we need?
  • How will we use the intelligence?
  • What are the priorities?
  • 2. Collection

    Objective: Gather raw data from multiple sources

    Sources:

  • Open source intelligence (OSINT)
  • Technical intelligence (network data, logs)
  • Human intelligence (HUMINT)
  • Signals intelligence (SIGINT)
  • Tools:

  • [Maltego](/tools/maltego) for OSINT collection
  • Shodan for service discovery
  • VirusTotal for malware analysis
  • AlienVault OTX for threat feeds
  • 3. Processing

    Objective: Convert raw data into usable format

    Activities:

  • Data normalization
  • Deduplication
  • Format conversion
  • Data validation
  • Output:

  • Cleaned datasets
  • Structured IOC lists
  • Enriched threat data
  • 4. Analysis

    Objective: Transform processed data into intelligence

    Activities:

  • Pattern recognition
  • Correlation analysis
  • Attribution analysis
  • Trend identification
  • Output:

  • Threat assessments
  • Actor profiles
  • Attack campaign analysis
  • Risk recommendations
  • 5. Dissemination

    Objective: Share intelligence with stakeholders

    Formats:

  • Executive summaries
  • Technical reports
  • IOC feeds
  • Briefings
  • Audiences:

  • Security operations
  • Incident response
  • Management
  • Partners
  • 6. Feedback

    Objective: Refine intelligence based on results

    Activities:

  • Evaluate intelligence quality
  • Assess effectiveness
  • Update requirements
  • Improve collection
  • IOC Types

    Indicators of Compromise (IOCs) are technical artifacts indicating malicious activity.

    Network-Based IOCs

    | IOC Type | Example | Detection Method |

    |----------|---------|------------------|

    | IP Address | 192.168.1.100 | Firewall logs, IDS |

    | Domain | malicious-domain.com | DNS logs, web proxy |

    | URL | https://malicious.com/payload | Web proxy, endpoint |

    | Email | attacker@malicious.com | Email gateway |

    | Certificate | SHA256 hash | Network inspection |

    Host-Based IOCs

    | IOC Type | Example | Detection Method |

    |----------|---------|------------------|

    | File Hash | SHA256:abc123... | Endpoint detection |

    | File Name | malware.exe | File integrity monitoring |

    | Registry Key | HKLM\Software\Malware | Registry monitoring |

    | Process | suspicious-process.exe | Process monitoring |

    | Service | MaliciousService | Service monitoring |

    Behavioral IOCs

    | IOC Type | Example | Detection Method |

    |----------|---------|------------------|

    | Unusual Traffic | High volume outbound | Network monitoring |

    | Authentication | Brute force attempts | Authentication logs |

    | Data Access | Unusual file access | File access monitoring |

    | Process Behavior | Unusual process tree | Process monitoring |

    IOC Management

    Effective IOC management requires:

  • **Validation**: Verify IOC accuracy and relevance
  • **Enrichment**: Add context to IOCs
  • **Prioritization**: Rank IOCs by importance
  • **Distribution**: Share IOCs with stakeholders
  • **Monitoring**: Track IOC activity
  • **Retirement**: Remove outdated IOCs
  • TTPs (Tactics, Techniques, and Procedures)

    TTPs describe how adversaries operate, providing context beyond technical indicators.

    Tactics

    High-level goals of adversaries:

    | Tactic | Description | Example |

    |--------|-------------|---------|

    | Reconnaissance | Information gathering | Scanning, OSINT |

    | Resource Development | Building capabilities | Infrastructure setup |

    | Initial Access | Gaining foothold | Phishing, exploits |

    | Execution | Running code | Command execution |

    | Persistence | Maintaining access | Backdoors, scheduled tasks |

    | Privilege Escalation | Gaining higher access | Exploiting vulnerabilities |

    | Defense Evasion | Avoiding detection | Obfuscation, disabling tools |

    | Credential Access | Stealing credentials | Password dumping |

    | Discovery | Mapping environment | Network scanning |

    | Lateral Movement | Moving through network | Pass-the-hash |

    | Collection | Gathering data | File collection |

    | Command and Control | Communicating with C2 | DNS, HTTP channels |

    | Exfiltration | Stealing data | Data compression, encryption |

    | Impact | Disrupting operations | Ransomware, data destruction |

    Techniques

    Specific methods used to achieve tactics:

    | Technique | Tactic | Description |

    |-----------|--------|-------------|

    | Phishing | Initial Access | Social engineering via email |

    | Drive-by Compromise | Initial Access | Exploiting web browsers |

    | Supply Chain Compromise | Initial Access | Compromising trusted software |

    | PowerShell | Execution | Script execution |

    | Scheduled Tasks | Persistence | Automated execution |

    | Account Manipulation | Persistence | Modifying accounts |

    | Process Injection | Defense Evasion | Hiding in legitimate processes |

    | Brute Force | Credential Access | Password guessing |

    | OS Credential Dumping | Credential Access | Stealing password hashes |

    | Network Service Discovery | Discovery | Scanning for services |

    | Remote Services | Lateral Movement | Using remote access |

    | Data from Cloud Storage | Collection | Accessing cloud data |

    | DNS | Command and Control | Using DNS for C2 |

    | Exfiltration Over Web Service | Exfiltration | Using web services for data theft |

    Procedures

    Specific implementations of techniques:

    Example: Phishing Campaign

  • **Tactic**: Initial Access
  • **Technique**: Phishing
  • **Procedure**: Spearphishing email with malicious Office document
  • Example: Credential Theft

  • **Tactic**: Credential Access
  • **Technique**: OS Credential Dumping
  • **Procedure**: Mimikatz to extract credentials from LSASS
  • MITRE ATT&CK

    MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques.

    ATT&CK Matrix

    The ATT&CK Matrix organizes techniques by tactic:

    | Tactic | Techniques | Sub-Techniques |

    |--------|------------|----------------|

    | Reconnaissance | 10 | 31 |

    | Resource Development | 7 | 18 |

    | Initial Access | 9 | 24 |

    | Execution | 14 | 27 |

    | Persistence | 19 | 88 |

    | Privilege Escalation | 13 | 28 |

    | Defense Evasion | 42 | 159 |

    | Credential Access | 17 | 47 |

    | Discovery | 31 | 130 |

    | Lateral Movement | 9 | 13 |

    | Collection | 17 | 53 |

    | Command and Control | 16 | 51 |

    | Exfiltration | 9 | 9 |

    | Impact | 13 | 14 |

    Using ATT&CK for CTI

  • **Threat Profiling**: Map adversary behavior to ATT&CK
  • **Gap Analysis**: Identify defensive gaps
  • **Detection Engineering**: Develop detection rules
  • **Red Teaming**: Plan realistic attack scenarios
  • **Purple Teaming**: Collaborative security improvement
  • ATT&CK Resources

  • **ATT&CK Navigator**: Visual exploration of techniques
  • **Threat Actor Profiles**: Adversary behavior mapping
  • **Detection Rules**: Sigma rules for detection
  • **Mitigations**: Defensive recommendations
  • CTI Tools

    Maltego

    [Maltego](/tools/maltego) provides graph-based CTI analysis:

    Capabilities:

  • Visual relationship mapping
  • Automated IOC enrichment
  • Threat intelligence integration
  • Investigation documentation
  • CTI Use Cases:

  • Threat actor profiling
  • Infrastructure mapping
  • IOC correlation
  • Campaign tracking
  • Integrations:

  • VirusTotal
  • Shodan
  • AlienVault OTX
  • MISP
  • Shodan

    Shodan is a search engine for internet-connected devices:

    Capabilities:

  • Service discovery
  • Banner grabbing
  • Vulnerability identification
  • Infrastructure mapping
  • CTI Use Cases:

  • Adversary infrastructure discovery
  • Vulnerability assessment
  • Service monitoring
  • Threat hunting
  • MISP (Malware Information Sharing Platform)

    MISP is an open-source threat intelligence platform:

    Capabilities:

  • IOC management
  • Threat sharing
  • Correlation
  • Automation
  • CTI Use Cases:

  • IOC collection and distribution
  • Threat feed management
  • Intelligence sharing
  • Detection rule generation
  • Other CTI Tools

    | Tool | Purpose | Type |

    |------|---------|------|

    | VirusTotal | Malware analysis | Commercial/Free |

    | AlienVault OTX | Threat intelligence | Free/Open source |

    | AbuseIPDB | IP reputation | Free/Commercial |

    | PhishTank | Phishing detection | Free |

    | URLhaus | Malware URL tracking | Free |

    | GreyNoise | Internet scanning | Commercial/Free |

    | SecurityTrails | DNS intelligence | Commercial/Free |

    Tool Integration

    Integrate CTI tools for comprehensive coverage:

  • **Maltego + Shodan**: Visual infrastructure mapping
  • **Maltego + VirusTotal**: IOC enrichment and analysis
  • **Maltego + MISP**: Threat intelligence correlation
  • **Maltego + AlienVault OTX**: Threat feed integration
  • Practical CTI Applications

    Threat Intelligence Report

    Create comprehensive threat intelligence reports:

  • **Executive Summary**: Key findings and recommendations
  • **Threat Profile**: Adversary TTPs and motivations
  • **IOC List**: Technical indicators
  • **Analysis**: Detailed investigation findings
  • **Recommendations**: Defensive actions
  • Incident Response CTI

    Apply CTI during incident response:

  • **IOC Collection**: Gather indicators from the incident
  • **Enrichment**: Research IOCs using CTI tools
  • **Attribution**: Identify threat actor and campaign
  • **Containment**: Use intelligence to contain threats
  • **Recovery**: Apply lessons learned
  • Threat Hunting

    Use CTI to guide threat hunting:

  • **Hypothesis Development**: Create hunting hypotheses
  • **Data Collection**: Gather relevant data
  • **Analysis**: Search for threat indicators
  • **Investigation**: Analyze findings
  • **Response**: Take action on discoveries
  • CTI Best Practices

    Data Quality

  • **Validate Sources**: Confirm intelligence reliability
  • **Cross-Reference**: Verify findings through multiple sources
  • **Timestamp Data**: Record collection dates
  • **Rate Confidence**: Assess intelligence reliability
  • Operational Security

  • **Protect Sources**: Safeguard intelligence sources
  • **Share Responsibly**: Share intelligence appropriately
  • **Anonymize Data**: Protect sensitive information
  • **Document Activities**: Record all CTI activities
  • Process Improvement

  • **Document Methodology**: Record investigation processes
  • **Capture Lessons Learned**: Improve based on experience
  • **Update Procedures**: Refine processes regularly
  • **Train Team Members**: Ensure team competency
  • Legal and Ethical

  • **Authorization**: Ensure proper authorization
  • **Privacy**: Respect privacy regulations
  • **Compliance**: Follow legal requirements
  • **Ethics**: Maintain ethical standards
  • Conclusion

    Cyber Threat Intelligence is essential for modern security operations. By understanding the intelligence cycle, IOC types, TTPs, and MITRE ATT&CK, organizations can build proactive defense capabilities.

    Tools like [Maltego](/tools/maltego), Shodan, and MISP provide powerful capabilities for CTI collection, analysis, and sharing. Combine these tools with sound methodology and analytical skills to produce actionable threat intelligence.

    For related topics, explore [OSINT for Blue Team](/learn/osint-for-blue-team) for defensive intelligence and [OSINT Investigation Workflow](/learn/osint-investigation-workflow) for structured investigation methodology.

    Frequently Asked Questions

    What is Cyber Threat Intelligence (CTI)?

    CTI is the practice of collecting, analyzing, and sharing information about cyber threats to improve defensive capabilities. It provides evidence-based knowledge about threats, threat actors, TTPs, IOCs, and vulnerabilities that enables proactive security decisions.

    What is the intelligence cycle in CTI?

    The intelligence cycle includes Planning (define requirements), Collection (gather threat data), Processing (normalize data), Analysis (identify patterns), Dissemination (share intelligence), and Feedback (refine approach). This structured process ensures actionable threat intelligence.

    What are IOCs in threat intelligence?

    Indicators of Compromise (IOCs) are technical artifacts indicating malicious activity: IP addresses, domains, file hashes, email addresses, and URLs. IOCs are used to detect and block known threats through automated security tools.

    What are TTPs in cyber threat intelligence?

    Tactics, Techniques, and Procedures describe how threat actors operate. Tactics are the goals (initial access, lateral movement), techniques are the methods (phishing, exploitation), and procedures are the specific implementations. TTPs are mapped in the MITRE ATT&CK framework.

    What is the MITRE ATT&CK framework?

    MITRE ATT&CK is a knowledge base of adversary tactics, techniques, and procedures observed in real-world attacks. It provides a common language for describing threats and helps organizations map defenses to known attack patterns across the entire attack lifecycle.

    What tools are used for CTI?

    Essential CTI tools include Maltego for threat visualization, Shodan for infrastructure scanning, MISP for threat intelligence sharing, VirusTotal for malware analysis, AlienVault OTX for threat feeds, and STIX/TAXII for standardized intelligence exchange.

    What is threat intelligence sharing?

    Threat intelligence sharing involves exchanging IOCs, TTPs, and threat context between organizations through platforms like MISP, using standards like STIX/TAXII, and participating in ISACs (Information Sharing and Analysis Centers) to improve collective defense.

    How does CTI differ from traditional security?

    Traditional security focuses on compliance and prevention with reactive approaches. CTI-driven security is proactive, using external threat data and intelligence-driven decisions to anticipate attacks, prioritize defenses based on actual threats, and improve effectiveness.

    What are the types of threat intelligence?

    Strategic intelligence covers long-term trends for executives. Tactical intelligence describes adversary capabilities for security teams. Operational intelligence details specific campaigns. Technical intelligence provides IOCs for automated defense tools.

    How do you start with CTI?

    Begin by understanding the MITRE ATT&CK framework, subscribe to free threat feeds (AlienVault OTX), learn STIX/TAXII standards, practice with Maltego for threat visualization, and join threat intelligence communities to learn from experienced analysts.