# What is Cyber Threat Intelligence (CTI)?

> Cyber threat intelligence is evidence-based knowledge about threats that is collected, analyzed, and placed in context to support a decision.

- Canonical URL: https://yellowcube.eu/glossary/cyber-threat-intelligence/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Useful intelligence explains not only what has been observed, but why it matters to a particular organization, how confident the assessment is, and what action the recipient can take.

CTI may be strategic for leaders, operational for campaign and incident planning, tactical for understanding attacker behavior, or technical for identifying specific infrastructure and artifacts. A raw feed of addresses, domains, or file hashes is data; it becomes intelligence only after analysis and contextualization.

Sharing formats such as STIX and transports such as TAXII let communities exchange structured intelligence at machine speed, but the deciding factor is the intelligence requirement: what the organization needs to know, for which decision, and by when. A program that cannot name its requirements collects noise, not intelligence.

### Key points

- **Primary purpose:** Reduce uncertainty in security, risk, and response decisions.
- **Common inputs:** Internal incidents, telemetry, trusted sharing communities, public reporting, research, and commercial feeds.
- **Quality tests:** Relevance, timeliness, source reliability, analytic confidence, actionability, and lawful handling.
- **Important limitation:** Threat intelligence can be incomplete, stale, deliberately deceptive, or irrelevant to the recipient’s environment.

### Related terms

[Indicator of compromise (IoC)](<https://yellowcube.eu/glossary/indicator-of-compromise/>) · [Tactics, techniques, and procedures (TTPs)](<https://yellowcube.eu/glossary/tactics-techniques-and-procedures/>) · [Threat hunting](<https://yellowcube.eu/glossary/threat-hunting/>) · [Threat intelligence platform (TIP)](<https://yellowcube.eu/glossary/threat-intelligence-platform/>) · [Threat intelligence feed](<https://yellowcube.eu/glossary/threat-intelligence-feed/>) · [Threat actor](<https://yellowcube.eu/glossary/threat-actor/>) · [Open-source intelligence (OSINT)](<https://yellowcube.eu/glossary/open-source-intelligence/>) · [STIX and TAXII](<https://yellowcube.eu/glossary/stix-and-taxii/>)

### Sources

[NIST glossary: Cyber Threat Intelligence](https://csrc.nist.gov/glossary/term/cyber_threat_intelligence) · [OASIS: STIX Version 2.1](https://docs.oasis-open.org/cti/stix/v2.1/stix-v2.1.html)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

