Collect intelligence for decisions—not for volume
Define the question, preserve provenance and confidence, connect observations to the environment, and keep interoperability claims separate from product capability.
Four questions that make intelligence operational
Useful threat intelligence should explain what decision it supports, where the information came from, how current and confident it is, and what action follows.
Intelligence requirements
Start with decisions the organisation must make, then define the threat questions that would change those decisions, the assets and business services in scope, acceptable evidence sources, required timeliness, handling rules, owners and review triggers. Intelligence volume is not a substitute for clear requirements.
Open guide →Intelligence guideIndicator context
Retain the indicator value and type together with source, first/last observed time, confidence, related actor/campaign/malware where justified, affected assets, sightings, expiry or review date, handling restrictions and the action the indicator is expected to support. An indicator without context can become stale, ambiguous or operationally misleading.
Open guide →Intelligence guideSTIX & TAXII
STIX 2.1 defines a structured language and serialization for representing cyber threat intelligence, while TAXII 2.1 defines an application-layer protocol and RESTful API for communicating cyber threat information. Supporting a STIX object model does not by itself prove TAXII transport support, and supporting a TAXII endpoint does not prove semantic compatibility with every producer or consumer.
Open guide →Intelligence guideIntelligence quality
Judge intelligence by whether its provenance is understood, the underlying evidence can be distinguished from analysis, it is timely for the decision, sufficiently specific to the environment, appropriately caveated, corroborated where material and connected to an operational decision. A large feed or high confidence label is not proof of quality.
Open guide →Threat Hunting
Turn intelligence and adversary behaviours into bounded, testable investigations with reproducible evidence.
Threat huntingIntelligence & hunting methodology
See the Cybatar rules for provenance, confidence, interoperability boundaries, hypothesis quality and hunt evidence.
Read methodologyThreat Intelligence & Hunting
Review the current Cybatar workflow surfaces for threat feeds, intelligence, IOCs, actors, hunts, malware analysis and network-flow records.
Platform capability