Terminology Index

Glossary

1801 terms

Open concept maps

Showing 865-896 of 1801 terms

I
32

Incident Intelligence

Using and producing intelligence around an incident, applying threat intelligence to understand the adversary and extracting intelligence from the incident itself, so response is informed and the organization learns from what happened.

In the SOC capstone, incident intelligence is the two-way flow between intelligence and incident handling: bringing threat intelligence to bear (who the adversary likely is, their TTPs, related campaigns) to guide response, and harvesting intelligence from the incident (new indicators, techniques, lessons) to feed detection and future readiness. It treats each incident as both informed by and a source of intelligence, integrating the two disciplines in practice.

Introduced in: SOC Analyst Capstone

Examples

  • Using threat intelligence to identify the adversary's likely TTPs during response.
  • Extracting new indicators from an incident to feed detection.
  • Turning incident lessons into intelligence for future readiness.

No related terms linked yet.