Cybersecurity Technologies

Threat Intelligence

Threat intelligence is curated, contextual information about current and emerging threats, which vulnerabilities are being exploited and what techniques attackers use, so a team can prioritize and defend against what is actually happening, not just what is theoretically possible.

What is threat intelligence?

Threat intelligence is curated, contextual information about active and emerging threats, which vulnerabilities are being exploited, which techniques attackers are using, and which of them are relevant to your systems, that a team uses to prioritize and defend. It is the difference between knowing a weakness exists and knowing whether anyone is actually attacking it.

Why threat intelligence matters

Attackers increasingly go through known, unpatched weaknesses rather than novel ones. In Verizon's 2025 Data Breach Investigations Report, exploitation of vulnerabilities was the initial access vector in 20% of breaches, up 34% year over year, and internet-exposed edge devices were a growing target. Threat intelligence is how a team separates the flaws attackers are actually using from the thousands that are merely theoretical, so limited time goes to what is live.

The four levels of threat intelligence

Practitioners split threat intelligence into levels by audience and time horizon.

  • Strategic. High-level trends and risk, for leadership and budget decisions.
  • Operational. The who and how of specific campaigns and adversaries.
  • Tactical. Attacker techniques and behaviors, mapped to frameworks like MITRE ATT&CK.
  • Technical. The concrete indicators, malicious IPs, domains, and file hashes, that feed detection.

Indicators, techniques, and the Pyramid of Pain

Not all intelligence is equally useful. Technical indicators of compromise (IOCs) like IP addresses and file hashes are easy to act on but trivial for an attacker to change. Techniques and behaviors are much harder to alter, so intelligence built on them, the idea behind the Pyramid of Pain, imposes far more cost on the adversary and stays useful longer. Mature programs weight attacker behavior over raw indicators.

Vulnerability intelligence: EPSS and CISA KEV

For a software team, the most actionable slice of threat intelligence is vulnerability intelligence: which disclosed CVEs are actually being exploited. Two sources anchor it. EPSS, maintained by FIRST, gives each CVE a probability of exploitation in the next 30 days, and the CISA KEV catalog lists vulnerabilities confirmed to be under active attack. Feeding these into prioritization is what turns a scanner's raw list into a ranking by real risk.

How threat intelligence is shared: STIX and TAXII

Intelligence is only useful if it moves. STIX and TAXII, open standards from OASIS, are the common language and transport for sharing structured threat intelligence between tools and organizations, so a feed from one source can be consumed automatically by another.

Threat intelligence vs SIEM vs vulnerability management

These three get conflated. A SIEM detects suspicious activity inside your environment. Threat intelligence is the external context about what attackers are doing that makes that detection, and your vulnerability prioritization, sharper. Vulnerability management is the loop of finding and fixing weaknesses; threat intelligence is a signal that feeds its prioritization rather than a replacement for it.

Common mistakes with threat intelligence

  • Drowning in raw indicator feeds. Volume is not value; unfiltered IOC feeds create noise, not insight.
  • Not operationalizing it. Intelligence that does not feed detection or prioritization is just reading.
  • Ignoring relevance to your stack. A campaign against hardware you do not run is not your threat; context is what makes intelligence actionable.

How Fencer uses threat intelligence

Fencer includes a threat feed of advisories relevant to your stack, each with an analysis of how it could be exploited in your specific environment rather than a generic bulletin. It also builds exploitation signals directly into prioritization: every finding's Priority accounts for exploit likelihood (describable as EPSS) alongside asset criticality and internet exposure, so the threats that are actually being used rise to the top of the queue automatically, and Fencer can fix what it finds and re-scan to confirm.

Frequently asked questions

No items found.

Take Fencer for a spin

See what security handled from code to cloud looks like.
Start a free trial in minutes, or book a demo for a guided tour.