Information for a decision
Cyber threat intelligence is evaluated information about threats that supports a defined decision. It can describe adversaries, intent, capability, infrastructure, tactics, techniques, procedures, vulnerabilities, targets, campaigns, observables, and recommended action.
A feed entry is data. It becomes useful intelligence only when it has context, confidence, relevance, timing, and an owner who can act.
Requirements and sources
Start with a priority question: which identity attacks threaten our administrative routes, which exposed products are being exploited, or which behavior should detection cover? Select internal incidents, telemetry, vendors, public sources, peers, researchers, and government reports based on that need.
Record source, collection time, confidence, handling, scope, affected assets, assumptions, and expiry. Separate observed fact, analytic judgment, and unverified report.
Operational use
Map intelligence to owned assets, identities, controls, detections, hunts, patch decisions, containment, and exercises. Test proposed indicators against local data before blocking. Convert behavior into robust analytic hypotheses. Track whether the action found, prevented, or reduced relevant harm.
Share only the data and confidence needed by recipients. Remove unnecessary personal, customer, or victim data and respect handling restrictions.
Failure and residual risk
Indicators expire and can be spoofed. Vendors can repeat one source and create false corroboration. Actor attribution can distract from behavior. Large feeds create cost and alert noise. A threat can matter even without a named group, and a named group can change infrastructure and procedure.
Intelligence reflects observed and reported activity. It does not enumerate every threat or prove absence.
Pomerium boundary
Pomerium can provide route, identity, policy, and access evidence for protected requests. Operators must correlate that evidence with identity-provider, endpoint, application, network, and external intelligence. Pomerium does not evaluate external feeds or attribute threat actors.
Evaluation checklist
- Which explicit prevention, detection, hunt, patch, response, or risk decision needs this information?
- What is observed fact, analytic judgment, confidence, scope, source, handling rule, and expiry?
- Does the intelligence map to a real owned asset, identity, route, control, and response?
- Can the indicator be spoofed, shared by benign systems, or already obsolete?
- Did the resulting action improve coverage or outcome without excessive noise or data sharing?
