Sources and collection disciplines

Collection is where the intelligence function begins. Before any analysis can happen, a cyber threat intelligence team has to gather raw material about adversaries, their infrastructure, and their behavior. Collection disciplines describe the distinct channels through which that material arrives, each with its own strengths, access requirements, and reliability considerations. Mature programs blend several disciplines so that gaps in one are covered by another, and so that a single finding can be corroborated across independent sources. Understanding where data comes from is also the first step in judging how much to trust it.

The main collection disciplines a CTI team draws on include the following.

  • OSINT: open source intelligence gathered from publicly available material such as websites, forums, social media, code repositories, domain registration records, and vendor research.
  • HUMINT: human intelligence derived from people, including analyst engagement with underground communities, informants, and direct contact with threat actors.
  • SIGINT: signals intelligence drawn from intercepted communications and network signals, more common in government and defense contexts.
  • Technical collection: evidence pulled from malware samples, endpoint and network telemetry, honeypots, and sandbox detonations that reveal adversary tooling and behavior.
  • Commercial and community feeds: curated indicators and reporting from paid vendors, sharing communities, and nonprofit threat exchanges.

References#

  • MITRE ATT&CK, attack.mitre.org
  • Gartner, Market Guide for Security Threat Intelligence Products and Services

Cookie Consent

We use cookies to enhance your experience. Learn more