Terminology Index
Glossary
2953 terms
Internal Intelligence
Threat intelligence derived from an organization's own data, its incidents, alerts, logs, and observed attacks, which is highly relevant because it reflects the threats actually targeting that specific environment.
Internal intelligence is generated from the organization itself: indicators and TTPs seen in its own incidents, patterns in its telemetry, and lessons from past attacks. Because it reflects threats that have actually reached the organization, it is often the most relevant intelligence of all, complementing external sources. A SOC harvests internal intelligence from its operations and feeds it back into detection, hunting, and response, closing the loop between what it experiences and how it defends.
Introduced in: Threat Intelligence for SOC Analysts
Examples
- Deriving indicators from the organization's own past incidents.
- Using patterns in internal telemetry as threat intelligence.
- Feeding lessons from a handled attack back into detection.
