Cybatar Security Hub
Resources / Threat Intelligence
Threat intelligence

Collect intelligence for decisions—not for volume

Define the question, preserve provenance and confidence, connect observations to the environment, and keep interoperability claims separate from product capability.

Intelligence lifecycle

Four questions that make intelligence operational

Useful threat intelligence should explain what decision it supports, where the information came from, how current and confident it is, and what action follows.

Intelligence guide

Intelligence requirements

Start with decisions the organisation must make, then define the threat questions that would change those decisions, the assets and business services in scope, acceptable evidence sources, required timeliness, handling rules, owners and review triggers. Intelligence volume is not a substitute for clear requirements.

Open guide →
Intelligence guide

Indicator context

Retain the indicator value and type together with source, first/last observed time, confidence, related actor/campaign/malware where justified, affected assets, sightings, expiry or review date, handling restrictions and the action the indicator is expected to support. An indicator without context can become stale, ambiguous or operationally misleading.

Open guide →
Intelligence guide

STIX & TAXII

STIX 2.1 defines a structured language and serialization for representing cyber threat intelligence, while TAXII 2.1 defines an application-layer protocol and RESTful API for communicating cyber threat information. Supporting a STIX object model does not by itself prove TAXII transport support, and supporting a TAXII endpoint does not prove semantic compatibility with every producer or consumer.

Open guide →
Intelligence guide

Intelligence quality

Judge intelligence by whether its provenance is understood, the underlying evidence can be distinguished from analysis, it is timely for the decision, sufficiently specific to the environment, appropriately caveated, corroborated where material and connected to an operational decision. A large feed or high confidence label is not proof of quality.

Open guide →
Hunting

Threat Hunting

Turn intelligence and adversary behaviours into bounded, testable investigations with reproducible evidence.

Threat hunting
Methodology

Intelligence & hunting methodology

See the Cybatar rules for provenance, confidence, interoperability boundaries, hypothesis quality and hunt evidence.

Read methodology
Platform

Threat Intelligence & Hunting

Review the current Cybatar workflow surfaces for threat feeds, intelligence, IOCs, actors, hunts, malware analysis and network-flow records.

Platform capability