Signals Intelligence (SIGINT) is intelligence derived from signals: network traffic, communications, and the telemetry that systems emit as they operate. In a cyber threat intelligence context, SIGINT is interpreted broadly to include the analysis of flow records, protocol metadata, sensor output, and other machine-generated signals that reveal how systems and adversaries behave. It describes activity through the traces that movement across networks leaves behind.
As a collection discipline, SIGINT is defined by the kind of source it draws on rather than the question it answers. Analysts use it to observe patterns in traffic, to detect anomalies, and to corroborate indicators seen elsewhere. In most enterprise settings this means working with telemetry an organization is lawfully entitled to collect from its own environment, where network and endpoint data provide a detailed record of activity. Interception of third-party communications is heavily restricted by law and is the domain of authorized government bodies.
SIGINT matters because signals are continuous, timely, and difficult for adversaries to suppress entirely. It supports detection, correlation, and situational awareness. Its typical inputs include network flow data, protocol metadata, and security telemetry. Its limits include encryption, high data volume, and the legal and privacy boundaries that govern collection, all of which shape what analysts may observe and how they interpret it.
References#
- SANS network monitoring and Cyber Threat Intelligence resources
- MITRE ATT&CK data source and detection documentation