Human Intelligence (HUMINT) is intelligence derived from people rather than systems. In cyber threat intelligence it covers information gathered through direct human interaction and reporting: insights from industry peers, insider knowledge, analyst engagement with underground communities, interviews, and trust-based information sharing. HUMINT contributes the motivations, relationships, and intentions that technical data alone rarely reveals.
As a collection discipline, HUMINT is distinguished by its reliance on human sources and judgment. Analysts use it to understand how threat actor groups organize, how services are bought and sold in criminal ecosystems, and what adversaries plan or claim. It frequently adds context to technical findings, explaining the who and why behind observed activity. This work is governed by legal and ethical boundaries and by professional practices that protect sources and the analyst.
HUMINT matters because intentions and relationships are difficult to infer from telemetry. It can provide early warning and attribution context that other disciplines cannot. Its typical inputs include trusted sharing groups, vetted informants, community observation, and professional networks. Its limits are significant: human sources may be biased, mistaken, or deliberately deceptive, access can be narrow, and claims require careful corroboration. Rigorous HUMINT practice weighs source reliability and information credibility separately before acting on any report.
References#
- SANS Cyber Threat Intelligence program materials
- FIRST information sharing and trust group guidance