Operational Intelligence

Operational intelligence is the middle level of cyber threat intelligence. It focuses on specific campaigns, threat actors, and incidents, answering questions about how an adversary operates, what infrastructure and methods they favor, and what they appear to be targeting now. It supports short-term decisions by teams that must act within days or weeks, such as incident responders, threat hunters, and security managers coordinating a response.

Positioned between strategic and tactical work, operational intelligence turns raw observations into a coherent picture of adversary activity. It tracks the tactics, techniques, and procedures associated with a campaign and connects scattered events into a recognizable pattern. Analysts often describe this behavior using structured models such as the Diamond Model and the MITRE ATT&CK framework, which give a shared vocabulary for comparing intrusions.

This level matters because it bridges long-term context and immediate defense. It helps teams anticipate an adversary's next move, prioritize alerts, and brief leadership during an active situation. Its sources include incident data, threat actor tracking, shared community reporting, and infrastructure analysis. Because operational intelligence is time-sensitive and depends on partial visibility, its value decays as campaigns evolve, so it requires continuous updating and validation against trusted reporting.

References#

  • MITRE ATT&CK framework documentation
  • The Diamond Model of Intrusion Analysis

Cookie Consent

We use cookies to enhance your experience. Learn more