# What is a Threat Intelligence Platform (TIP)?

> A threat intelligence platform is a system used to manage the lifecycle of cyber threat information and intelligence from multiple internal and external sources.

- Canonical URL: https://yellowcube.eu/glossary/threat-intelligence-platform/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Typical capabilities include ingesting data, normalizing formats, removing duplicates, enriching and relating records, recording confidence and provenance, supporting analyst curation, and distributing selected outputs to people or security controls.

A TIP can help connect indicators, observed activity, adversary behaviors, vulnerabilities and defensive context, but the product category has no single mandatory feature set. Structured Threat Information Expression (STIX) can represent threat information, while Trusted Automated Exchange of Intelligence Information (TAXII) can transport it. Supporting those standards can improve interoperability, but neither standard by itself makes a system a TIP or makes its contents useful intelligence.

### Key points

- **Common inputs:** Intelligence reports and feeds, incident findings, malware analysis, vulnerability information, sharing communities and an organization’s own observations.
- **Core governance:** Preserve source and handling restrictions, track timestamps and confidence, manage conflicts, expire stale records and control what may be redistributed.
- **Useful outputs:** Prioritized analyst context, investigation pivots, defensive hypotheses, partner sharing and carefully governed updates to monitoring or blocking systems.
- **Important limitation:** Aggregating more indicators does not automatically create intelligence. Low-quality, stale or context-free data can waste analyst time and cause unsafe automated decisions.

### Related terms

[Cyber threat intelligence (CTI)](<https://yellowcube.eu/glossary/cyber-threat-intelligence/>) · [Threat intelligence feed](<https://yellowcube.eu/glossary/threat-intelligence-feed/>) · [Indicator of compromise (IoC)](<https://yellowcube.eu/glossary/indicator-of-compromise/>) · [Open-source intelligence (OSINT)](<https://yellowcube.eu/glossary/open-source-intelligence/>) · [STIX and TAXII](<https://yellowcube.eu/glossary/stix-and-taxii/>)

### Sources

[NIST glossary: cyber threat intelligence](https://csrc.nist.gov/glossary/term/cyber_threat_intelligence) · [OASIS STIX Version 2.1](https://www.oasis-open.org/standard/stix-version-2-1/) · [OASIS TAXII Version 2.1](https://www.oasis-open.org/standard/taxii-version-2-1/) · [CISA AIS 2.0 submission guidance](https://www.cisa.gov/resources-tools/resources/ais-20-submission-guidance-v10)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

