Building a Security Operations Centre (SOC)
Pages
Page 13 of 14
Threat Intelligence
An introduction to the basic components of delivering TI that has an impact on the detection capabilities of a SOC.
This page is by no means the codex of TI, instead provides you with an introduction to the basic components of delivering TI that has an impact on the detection capabilities of a SOC. The Home Office produced a useful guide that explores the complexities of TI in far more detail.
The role of threat intelligence (TI)
Threat intelligence refers to knowledge of attacker’s activities. This can range from a simple narrative around a threat actors’ motivations, through to in-depth technical descriptions of an attacker's tactics, techniques and procedures.
The value of threat intelligence depends on your detection approach:
- If you are utilising commercial tools to detect attacks, then threat intelligence will typically be conducted by the vendor and you might not need your own TI function.
- If you're implementing your own use-cases and alerts, TI is a key part of attempting to staying ahead, or at least, on par with attackers.
TI also provides valuable insights that can be useful when onboarding.
Intelligence sharing
Staying informed about the evolving threat landscape is essential. One of the most effective ways to do this is by actively engaging with intelligence-sharing communities, forums, and collaborative platforms. These spaces can allow organisations to exchange insights, discuss emerging threats, and learn from real-world incidents in a timely and confidential manner.
Participating in these networks can help to ensure you're not operating in isolation. Staying connected means staying ahead.
TI formats
The Pyramid of Pain is valuable when thinking about TI. It refers to the amount of extra work (pain) an attacker will have to do if you can detect part of their attack, highlighting the importance of TI in a SOC.

The Pyramid of Pain
TI comes in multiple formats but you can group it into three broad categories. The actual extent of its use depends on available tools and resources in the SOC. In an ideal situation, a SOC will make use of all types of TI.
Indicator of Compromise (IoC) - At the lowest level, there are open source TI feeds that will provide indicators of compromise. This will include things like known bad IP addresses, domains, hashes and strings, all of which can compared with your logs. If you get match would indicate the system is interacting with a known bad IoC. There are many IoC feeds that can be used and ingested into monitoring solutions.
Tactics Techniques and Procedures (TTPs) - Slightly more abstract than IoCs, Qualitative TI will often refer to attacker TTPs, which can be invaluable in creating behavioural analytics. For example, a certain threat actor that is relevant to your organisation has been taking advantage of a couple of specific system tools to perform privilege escalation. This kind of information, when used correctly, can be turned into detection use-cases.
Situational - Far more abstract information that might be useful in directing R&D, or the refinement of SOC strategies. This would typically include information on trends and geopolitical situations.
Threat Intelligence Platform (TIP)
Careful, here be dragons and snake oil! A TIP is a place for your SOC to store, correlate and manage TI. They are configured to ingest TI feeds (typically IoC) from TI providers and linked to your SIEM tool to enable automated detection of IOCs.
There are a multitude of TIPs available on the market, so it's important that you find a tool that works for you. Commercial tools can be invaluable if you need TI without much hassle but may lack some of the freedoms that come with open source tools. (MISP is one of the most widely used platforms, worth considering)
Once you have a TIP, you’ll need to find TI feeds that provide your SOC will the most value. Open source feeds provide your organisation with a range of intel (OSINT). There are commercial feeds to that may provide a slightly more bespoke service.
The key parts of implementing a TIP are:
- Make sure that you don't drown in low confidence, out of date IoCs - Remember, it is very easy for attackers to change an IP address. Be wary that some threat feeds may not include “best before” dates and over time this could lead to the SOC inadvertently flagging legitimate addresses as malicious.
- Don't underestimate the value of triaging qualitative intelligence (whitepapers, reports, news articles) - ensuring that analysts have time to read and digest intel reports will lead to better understanding and better use-cases.
- Score intelligence according to value - If it constantly produces false positives, then perhaps review the sources you're using.
- Make sure that your TI sources are providing value. It is a very competitive market, so there’s no need to put all your eggs in one basket.