Get Your Free Report
Start for Free
Threat Intelligence 1 min read SOCRadar Research Team

What Are the Four Types of Threat Intelligence (Strategic, Tactical, Operational, Technical)?

TL;DR

Threat intelligence comprises four types: strategic, tactical, operational, and technical, each with unique audiences and timeframes.

Threat intelligence is not a one-size-fits-all concept; different stakeholders require different levels of detail and focus. The industry commonly categorizes threat intelligence into four distinct types, forming a spectrum from broad, high-level insights to granular, actionable data.

Understanding these differences is crucial for building a mature security program that effectively leverages intelligence across all levels, from executive decision-making to automated security tool operations. Each type plays a vital role in anticipating, detecting, and responding to cyber threats.

How It Works

The four types of threat intelligence exist on a spectrum, with strategic intelligence being broad, long-term, and non-technical at one end, and technical intelligence being narrow, short-term, and highly technical at the other. Tactical and operational intelligence fall between these two extremes.

Type Audience Timeframe Focus Example content
Strategic CISOs, execs, board Long term (months–years) The “who” and “why” – trends, geopolitics, risk Report: “Ransomware groups increasingly target healthcare”
Operational Threat hunters, SOC leads, IR Medium term (weeks–months) Active campaigns and adversary behavior “This actor is running a phishing campaign against our sector now”
Tactical SOC analysts, defenders Short term (days–weeks) The “how” – TTPs and detection ATT&CK techniques, detection rules, IOC context
Technical Security tools, malware analysts Very short (hours–days) Raw artifacts Malicious IPs, hashes, domains, C2 addresses

Strategic intelligence articulates the likely attackers and their motivations, linking cyber threats to business risks, industry targeting, and geopolitical factors. It typically takes the form of written reports that inform budgets and long-term strategy.

Operational intelligence provides a deeper understanding of specific, active campaigns—the who, why, and how behind current or imminent attacks. It supports threat hunting and incident response by helping teams anticipate adversary actions over the medium term.

Tactical intelligence concentrates on the attacker’s TTPs and methods for their detection. It is intended for front-line defenders and informs security tools, often aligning with the MITRE ATT&CK framework. While its shelf life is shorter than strategic intelligence, it is longer than that of raw indicators.

Technical intelligence is the most granular level, comprising the actual artifacts left by attackers, such as malicious IPs, domains, file hashes, and malware signatures. This type is highly perishable due to rapid infrastructure rotation by adversaries and is primarily consumed automatically by security tools rather than human analysis.

It is worth noting that some frameworks consolidate technical intelligence into the tactical category, recognizing only three types: strategic, operational, and tactical. The four-type model simply differentiates raw artifacts into their own distinct category.

Real-World Example

The SolarWinds/SUNBURST campaign effectively illustrates the application of all four types of threat intelligence from a single event:

  • STRATEGIC: “Nation-state actor APT29 (Cozy Bear, tied to Russia’s SVR) conducts long-term espionage via software supply chains.” This insight led to the board deciding to fund a supply-chain risk program.
  • OPERATIONAL: “The actor trojanizes signed software updates, stays dormant ~2 weeks, then beacons to C2 via a DGA.” This informed threat hunters to search for dormant backdoors and unusual DNS activity.
  • TACTICAL: MITRE ATT&CK T1195.002 (Supply Chain Compromise) and T1071 (Application Layer Protocol for C2). This guided detection engineers to write rules for these specific behaviors.
  • TECHNICAL: avsvmcloud[.]com and its DGA subdomains; SUNBURST DLL hashes. These indicators were automatically blocked by firewalls and EDR systems.

In this instance, the strategic report shaped the budget, operational intelligence guided threat hunting efforts, tactical details informed detection rule creation, and technical indicators enabled automated blocking by security machines, demonstrating how the same attack can be understood and managed at four different altitudes.

Why It Matters

Relying on only one type of threat intelligence can leave critical gaps in an organization’s defense. For example, a team focused solely on technical feeds might block current malicious IPs but miss strategic warnings that a new actor is targeting its industry. Conversely, a team consuming only strategic reports might understand the threat landscape broadly but lack the means to detect an ongoing intrusion effectively.

The four types of threat intelligence work in synergy: strategic intelligence provides direction, operational intelligence tracks live campaigns, tactical intelligence enables the development of detection capabilities, and technical intelligence powers automated blocking mechanisms. Platforms like SOCRadar can integrate these different types of intelligence, ensuring that each is routed to the appropriate consumer within the organization.

An analogy for understanding this integration is a military operation: Strategic intelligence guides the general’s decision on which country to defend. Operational intelligence assists the commander in tracking an enemy division’s movements. Tactical intelligence helps the sergeant identify enemy patrol patterns. Technical intelligence allows the sentry to recognize a specific enemy uniform at the gate. All four levels collectively protect the same base, albeit at different scales.

People Also Ask

Are there three or four types of threat intelligence? Both models exist. Some frameworks use three (strategic, operational, tactical); the four-type model adds technical as its own category for raw artifacts.

Which type is easiest to produce? Technical and tactical intelligence, because indicators can be collected and shared automatically. Strategic intelligence takes the most human analysis.

Which type lasts the longest? Strategic intelligence. Trends and actor motivations change slowly, while technical indicators can expire within hours.

Key points
  • Strategic intelligence informs high-level decisions on risk and long-term planning.
  • Operational intelligence guides active threat hunting and incident response.
  • Tactical intelligence focuses on adversary TTPs for detection rules and security tool configuration.
  • Technical intelligence provides raw indicators for automated blocking and immediate defense.
  • A mature threat intelligence program integrates all four types for comprehensive security.
  • The four types of threat intelligence cater to different audiences, timeframes, and levels of detail.
Back to all questions