External Watch & Intelligence

Cyber Threat Intelligence CTI

Information gathered about threat actors, campaigns and indicators (IPs, domains, file hashes) that target your organization, your industry or the technologies you use. Raw feeds, analyst reports and the Threat Intelligence Platform (TIP) that distributes them to your SIEM/EDR are all part of this family.

When you need it

  • You have a SOC team that triages alerts (someone has to consume the intelligence)
  • You are in an industry that faces targeted attacks, such as finance, government, defense or energy
  • Management wants a strategic answer to "who would attack us, and why?"
  • During incident response, knowing who the attacker is and what they will do next is critical

When you do not need it

  • Without a team to process it, a raw CTI feed is wasted money: nobody reads it and nobody writes rules from it.
  • For small and mid-sized organizations, your MDR provider's intelligence and the free malicious link list from USOM (Turkey's national CERT) are enough to start.

Intelligence does not protect anything on its own; it creates value when it is fed automatically into your SIEM, EDR, firewall and email security. Start by defining what questions you need answered (intelligence requirements).