Threat IntelligenceIntermediateProgram5 validated evidence records

Cyber Threat Intelligence (CTI)

30 sec

Evidence-based knowledge about threats and adversaries that helps an organization make better security decisions.

Know

What is Cyber Threat Intelligence?

Threat intelligence turns collected information into assessed knowledge that is relevant to a decision. It may describe threat actors, campaigns, behaviors, infrastructure, vulnerabilities, malware, targeting, or trends and should communicate context, confidence, relevance, and timeliness.

Why it matters

Raw indicators age quickly. Intelligence helps defenders decide what matters to their organization, what to look for, and what action is justified.

Evidence, not hype

Validated in the real world

Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.

Technical ValidationResearch / emerging practice

Invisible Unicode characters appear in phishing keyword evasion

2026-09-03Microsoft Security Research

Microsoft describes invisible Unicode characters inserted into phishing text to obstruct keyword parsing. Signature activity increased from February 9 and remained elevated on weekdays for roughly three months. Layered protections flagged most of the messages.

Why this is evidence

This illustrates the difference between visible text and machine-processed content. It is newly published analysis of older activity, not evidence that all email protections are defeated or that every invisible character is malicious.

See the source — Microsoft Security Research: ASCII smuggling crosses over from AI prompt injection to phishing evasion
Government / AuthoritativeGovernment advisory

Scattered Spider targeted enterprise help desks and identity controls

2025-07-29FBI, CISA and international partnersCommercial facilities and other sectors

A joint advisory describes Scattered Spider tactics obtained through investigations, including targeting IT help desks, social engineering, identity abuse, and the need for phishing-resistant MFA.

Why this is evidence

The advisory validates how modern intrusions can begin with human and identity-control failures and maps observed behavior to MITRE ATT&CK techniques.

See the source — CISA / FBI / International Partners: Scattered Spider Joint Cybersecurity Advisory AA23-320A
Government / AuthoritativeGovernment advisory

ALPHV/BlackCat ransomware activity documented through FBI investigations

2024-02-27FBI, CISA and HHSHealthcare and cross-sector

A joint advisory publishes indicators and tactics associated with ALPHV/BlackCat ransomware based on FBI investigations and notes that healthcare was the most commonly victimized sector among recent leaked victims.

Why this is evidence

The advisory connects ransomware terminology to observed campaigns, indicators, tactics, victim impact, and recommended defensive actions.

See the source — CISA / FBI / HHS: #StopRansomware: ALPHV BlackCat Update
Primary / ConfirmedConfirmed incident

SolarWinds confirmed malicious code was inserted into Orion software builds

2020-12-14SolarWindsSoftware supply chain

SolarWinds disclosed to the SEC that a compromise of its software build system inserted a vulnerability into Orion product updates released between March and June 2020.

Why this is evidence

This primary-source disclosure is direct evidence of software supply-chain compromise and the downstream risk created by trusted updates.

See the source — U.S. Securities and Exchange Commission: SolarWinds Form 8-K — December 14, 2020
Technical ValidationStandard / framework

ATT&CK connects techniques to documented adversary procedures

Continuously maintainedMITRECross-sector

MITRE ATT&CK is a public knowledge base of adversary tactics and techniques that includes procedure examples showing how real threat groups and software have used those behaviors.

Why this is evidence

It gives the encyclopedia a neutral behavioral language for connecting definitions to observed adversary activity without relying on one vendor's taxonomy.

See the source — MITRE: MITRE ATT&CK

Understand the mechanics

How it works

  1. 1

    Define intelligence requirements.

  2. 2

    Collect relevant information from appropriate sources.

  3. 3

    Process and normalize the data.

  4. 4

    Analyze it against the requirement and organizational context.

  5. 5

    Disseminate an assessment to the people or systems that can act.

  6. 6

    Use feedback to improve future collection and analysis.

Practice

What to watch for

  • Threat activity targeting the organization’s sector or technology
  • Infrastructure or behaviors matching current incidents
  • New exploitation affecting exposed assets
  • Intelligence feeds with little relevance or context

Perform

What to do

  1. 1

    Assess source reliability and confidence.

  2. 2

    Determine relevance to your environment.

  3. 3

    Translate intelligence into detection, hunting, hardening, or executive decisions.

  4. 4

    Avoid treating an indicator match as proof without investigation.

How to reduce the risk

  • Intelligence requirements
  • Asset/context enrichment
  • Threat-informed defense
  • Detection engineering
  • Feedback loops

Business impact

  • Better prioritization
  • Earlier awareness of relevant threats
  • More focused hunting and detection
  • Noise and cost if collection lacks requirements

What different roles should do

Threat Intelligence

  • Tie collection to explicit decisions and requirements

SOC

  • Use intelligence as context and detection input, not unquestioned truth

Framework & standards context

  • MITRE ATT&CK
  • STIX/TAXII where applicable

Keep learning

Threat ActorCampaignTTPIOCMITRE ATT&CKThreat Hunting

Source transparency

Authoritative sources

Last reviewed: 2026-09-02