Threat Intelligence

Articles about threat intelligence from security operations practitioners.

Threat Intelligence

Open source threat intelligence: what's usable, what's noise

Open-source threat intelligence is worth using when it produces measurable incremental value. It's noise when it adds stale, duplicated, low-confidence indicators that raise alert volume without changing an outcome. Here's the six-measure test I run before renewing, adding, or automating any feed.

DCDaniel C. · Aug 17, 2026
Threat Intelligence

Which threat intelligence feeds actually earn their keep

Renewal prep, last quarter: four feed subscriptions, six figures across the set. I ran the test I run on every vendor line and named one decision each feed changed in ninety days. Two cleared the bar; I cut the other two.

DCDaniel C. · Aug 3, 2026
Threat Intelligence

Dark Web monitoring: A definition for SOC teams

Dark web monitoring sounds like one capability but bundles three: credential monitoring, forum crawling, and actor tracking, each sourced and operated differently. Buyers conflate them, then discover they bought a credential feed when they expected adversary context.

THTheo H. · Jun 26, 2026
Threat Intelligence

Cyber threat intelligence analysts: What the role should cover

Most CTI programs quietly collapse into IOC feed management with a weekly report attached, running one of the role's three horizons and calling it the whole function. Scope the analyst across tactical, operational, and strategic work, and judge it on whether it changes a detection or a decision inside the SOC.

THTheo H. · Jun 19, 2026
Threat Intelligence

Most threat intelligence sits unread

Most threat intelligence never reaches a detection rule. The cause is structural: a format mismatch between TI delivery and detection workflows.

THTheo H. · May 26, 2026

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Threat Intelligence | Future of SecOps