Terminology Index

Glossary

1801 terms

Open concept maps

Showing 897-928 of 1801 terms

I
32

Intelligence in Detection

Applying threat intelligence to detection, using knowledge of adversary indicators and techniques to build, prioritize, and enrich detections, so the SOC catches what intelligence says is actually threatening it.

Intelligence in detection feeds threat knowledge into detection engineering: turning indicators into detections, prioritizing coverage toward the techniques of adversaries likely to target the organization, and enriching alerts with intelligence context. It makes detection threat-informed rather than generic, focusing effort where it matters. It is one of several ways intelligence integrates into SOC functions, alongside its use in triage, hunting, and incident response.

Introduced in: Threat Intelligence for SOC Analysts

Examples

  • Turning intelligence indicators into SIEM detections.
  • Prioritizing detection coverage toward a relevant adversary's techniques.
  • Enriching alerts with threat-intelligence context.

No related terms linked yet.