Managing Intelligence Lifecycle
When to Use
Use this skill when:
- Establishing a formal CTI program and defining its operational model
- Conducting quarterly intelligence requirements reviews with business stakeholders
- Evaluating CTI program maturity against established frameworks (FIRST CTI-SIG maturity model)
Do not use this skill for day-to-day IOC triage or incident-specific intelligence tasks — those use operational intelligence workflows, not lifecycle management.
Prerequisites
- Executive sponsorship and defined CTI team structure (1+ dedicated analysts)
- Stakeholder map identifying intelligence consumers (SOC, IR, executive team, vulnerability management)
- Existing feed subscriptions or ISAC memberships for collection baseline
- CTI platform (MISP, ThreatConnect, OpenCTI) for lifecycle management
Workflow
Step 1: Planning and Direction
Define Priority Intelligence Requirements (PIRs) with stakeholders:
- Interview SOC leads, IR team, CISO, risk management, and product security
- Document PIRs in structured format: "What is the current capability and intent of [threat actor] to attack [critical asset] using [technique]?"
- Prioritize 5–10 PIRs for the quarter, reviewed monthly
Example PIR: "Is ransomware group Cl0p currently targeting organizations in our sector using MoveIT or GoAnywhere vulnerabilities?"
Step 2: Collection Planning
Map PIRs to required collection sources:
- Technical sources: commercial feeds, TAXII, ISAC data, honeypot telemetry, darkweb monitoring
- Human sources: vendor threat briefings, industry working groups, law enforcement partnerships
- Internal sources: SIEM logs, EDR telemetry, phishing submission mailbox
Document collection gaps and associated costs to fill them.
Step 3: Processing and Normalization
Implement automated processing pipeline:
- Ingest → normalize to STIX 2.1 → deduplicate → enrich → score confidence
- Reject unverifiable or duplicate indicators before analysis
- Tag all processed data with source, collection date, and expiration
Step 4: Analysis and Production
Produce intelligence at three levels:
- Strategic: Quarterly threat landscape report for executives; sector trends, geopolitical context
- Operational: Weekly campaign reports for security leadership; active campaigns, adversary activity
- Tactical: Daily IOC bulletins for SOC; actionable indicators with block/monitor recommendations
Apply structured analytic techniques: Analysis of Competing Hypotheses (ACH), Key Assumptions Check, Devil's Advocacy.
Step 5: Dissemination
Match product format to audience:
- Executives: 1-page PDF with risk ratings, business impact, recommended decisions
- SOC analysts: SIEM-ready IOC list, Sigma rules, MISP events
- Vulnerability management: CVE lists with EPSS scores and exploitation likelihood
- IT/Security leadership: Full intelligence report with technical appendix
Apply TLP classifications and distribution lists per product type.
Step 6: Feedback and Evaluation
Collect feedback within 5 business days of dissemination:
- Did the product address the PIR?
- Was actionability sufficient?
- What data was missing?
Track metrics quarterly: PIR coverage rate, IOC true positive rate, time-to-disseminate, stakeholder satisfaction score (NPS or structured survey).
Key Concepts
| Term |
Definition |
| PIR |
Priority Intelligence Requirement — specific, actionable question driving intelligence collection and analysis |
| Intelligence Lifecycle |
Six-phase iterative process: Planning → Collection → Processing → Analysis → Dissemination → Feedback |
| Strategic Intelligence |
Long-term threat trend analysis for executive decision-making; time horizon 6–24 months |
| Operational Intelligence |
Campaign-level analysis for security program decisions; time horizon 1–6 months |
| Tactical Intelligence |
Specific IOCs and TTPs for immediate detection and blocking; time horizon hours to days |
| FIRST CTI-SIG |
Forum of Incident Response and Security Teams — CTI Special Interest Group maturity model |
Tools & Systems
- ThreatConnect: TIP with built-in intelligence lifecycle workflows, PIR tracking, and stakeholder reporting dashboards
- MISP: Open-source TIP supporting intelligence lifecycle from collection through sharing
- OpenCTI: Graph-based CTI platform with workflow management for intelligence products
- Recorded Future: Commercial platform with structured intelligence reports aligned to the intelligence lifecycle
Common Pitfalls
- Collection without direction: Ingesting every available feed without PIRs produces data overload and no actionable intelligence.
- Missing feedback loops: Without structured feedback, CTI teams produce reports that don't meet stakeholder needs and lose organizational relevance.
- Tactical-only focus: Overemphasis on IOC sharing neglects strategic intelligence that informs security investment and risk decisions.
- No metrics program: Cannot demonstrate CTI program value without tracking detection contributions, true positive rates, and stakeholder satisfaction.
- Underfunded collection: PIRs cannot be answered without appropriate collection sources; document and escalate gaps rather than producing low-confidence estimates.
1---2name: managing-intelligence-lifecycle3description: Guides the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to establish or mature a CTI program.4license: Apache-2.05---6# Managing Intelligence Lifecycle78## When to Use910Use this skill when:11- Establishing a formal CTI program and defining its operational model12- Conducting quarterly intelligence requirements reviews with business stakeholders13- Evaluating CTI program maturity against established frameworks (FIRST CTI-SIG maturity model)1415**Do not use** this skill for day-to-day IOC triage or incident-specific intelligence tasks — those use operational intelligence workflows, not lifecycle management.1617## Prerequisites1819- Executive sponsorship and defined CTI team structure (1+ dedicated analysts)20- Stakeholder map identifying intelligence consumers (SOC, IR, executive team, vulnerability management)21- Existing feed subscriptions or ISAC memberships for collection baseline22- CTI platform (MISP, ThreatConnect, OpenCTI) for lifecycle management2324## Workflow2526### Step 1: Planning and Direction2728Define Priority Intelligence Requirements (PIRs) with stakeholders:29- Interview SOC leads, IR team, CISO, risk management, and product security30- Document PIRs in structured format: "What is the current capability and intent of [threat actor] to attack [critical asset] using [technique]?"31- Prioritize 5–10 PIRs for the quarter, reviewed monthly3233Example PIR: "Is ransomware group Cl0p currently targeting organizations in our sector using MoveIT or GoAnywhere vulnerabilities?"3435### Step 2: Collection Planning3637Map PIRs to required collection sources:38- Technical sources: commercial feeds, TAXII, ISAC data, honeypot telemetry, darkweb monitoring39- Human sources: vendor threat briefings, industry working groups, law enforcement partnerships40- Internal sources: SIEM logs, EDR telemetry, phishing submission mailbox4142Document collection gaps and associated costs to fill them.4344### Step 3: Processing and Normalization4546Implement automated processing pipeline:47- Ingest → normalize to STIX 2.1 → deduplicate → enrich → score confidence48- Reject unverifiable or duplicate indicators before analysis49- Tag all processed data with source, collection date, and expiration5051### Step 4: Analysis and Production5253Produce intelligence at three levels:54- **Strategic**: Quarterly threat landscape report for executives; sector trends, geopolitical context55- **Operational**: Weekly campaign reports for security leadership; active campaigns, adversary activity56- **Tactical**: Daily IOC bulletins for SOC; actionable indicators with block/monitor recommendations5758Apply structured analytic techniques: Analysis of Competing Hypotheses (ACH), Key Assumptions Check, Devil's Advocacy.5960### Step 5: Dissemination6162Match product format to audience:63- Executives: 1-page PDF with risk ratings, business impact, recommended decisions64- SOC analysts: SIEM-ready IOC list, Sigma rules, MISP events65- Vulnerability management: CVE lists with EPSS scores and exploitation likelihood66- IT/Security leadership: Full intelligence report with technical appendix6768Apply TLP classifications and distribution lists per product type.6970### Step 6: Feedback and Evaluation7172Collect feedback within 5 business days of dissemination:73- Did the product address the PIR?74- Was actionability sufficient?75- What data was missing?7677Track metrics quarterly: PIR coverage rate, IOC true positive rate, time-to-disseminate, stakeholder satisfaction score (NPS or structured survey).7879## Key Concepts8081| Term | Definition |82|------|-----------|83| **PIR** | Priority Intelligence Requirement — specific, actionable question driving intelligence collection and analysis |84| **Intelligence Lifecycle** | Six-phase iterative process: Planning → Collection → Processing → Analysis → Dissemination → Feedback |85| **Strategic Intelligence** | Long-term threat trend analysis for executive decision-making; time horizon 6–24 months |86| **Operational Intelligence** | Campaign-level analysis for security program decisions; time horizon 1–6 months |87| **Tactical Intelligence** | Specific IOCs and TTPs for immediate detection and blocking; time horizon hours to days |88| **FIRST CTI-SIG** | Forum of Incident Response and Security Teams — CTI Special Interest Group maturity model |8990## Tools & Systems9192- **ThreatConnect**: TIP with built-in intelligence lifecycle workflows, PIR tracking, and stakeholder reporting dashboards93- **MISP**: Open-source TIP supporting intelligence lifecycle from collection through sharing94- **OpenCTI**: Graph-based CTI platform with workflow management for intelligence products95- **Recorded Future**: Commercial platform with structured intelligence reports aligned to the intelligence lifecycle9697## Common Pitfalls9899- **Collection without direction**: Ingesting every available feed without PIRs produces data overload and no actionable intelligence.100- **Missing feedback loops**: Without structured feedback, CTI teams produce reports that don't meet stakeholder needs and lose organizational relevance.101- **Tactical-only focus**: Overemphasis on IOC sharing neglects strategic intelligence that informs security investment and risk decisions.102- **No metrics program**: Cannot demonstrate CTI program value without tracking detection contributions, true positive rates, and stakeholder satisfaction.103- **Underfunded collection**: PIRs cannot be answered without appropriate collection sources; document and escalate gaps rather than producing low-confidence estimates.