Get Your Free Report
Start for Free
Threat Intelligence 1 min read SOCRadar Research Team

What Are the Four Types of Threat Intelligence?

TL;DR

Threat intelligence is classified into four types: strategic, tactical, operational, and technical, serving distinct needs from executive decision-making to automated security tools.

Threat intelligence is not a monolithic concept; it must cater to diverse stakeholders within an organization, from the board of directors to automated security systems. The industry standardizes this by categorizing threat intelligence into four distinct types: strategic, tactical, operational, and technical. Each type is designed with a specific audience, timeframe, and objective in mind, and a mature threat intelligence program effectively integrates all four to ensure comprehensive security coverage and operational efficiency.

Understanding these distinctions allows organizations to tailor their intelligence consumption and production, ensuring that the right information reaches the right people or systems at the right time. This multi-faceted approach enables a more proactive and adaptive defense against evolving cyber threats.

How It Works

The four types of threat intelligence exist on a spectrum. Strategic intelligence is broad, long-term, and non-technical, while technical intelligence is narrow, short-term, and highly technical. Tactical and operational intelligence fall between these two extremes. Here’s a breakdown by type:

Type Audience Timeframe Focus Example content
Strategic CISOs, execs, board Long term (months–years) The “who” and “why” – trends, geopolitics, risk Report: “Ransomware groups increasingly target healthcare”
Operational Threat hunters, SOC leads, IR Medium term (weeks–months) Active campaigns and adversary behavior “This actor is running a phishing campaign against our sector now”
Tactical SOC analysts, defenders Short term (days–weeks) The “how” – TTPs and detection ATT&CK techniques, detection rules, IOC context
Technical Security tools, malware analysts Very short (hours–days) Raw artifacts Malicious IPs, hashes, domains, C2 addresses

Strategic intelligence addresses who is likely to attack and why, linking cyber threats to business risks, industry targeting, and geopolitical factors. It typically appears as written reports that inform budgets and long-term strategy rather than as data feeds.

Operational intelligence offers a deeper understanding of specific, active campaigns, focusing on the who, why, and how behind current or imminent attacks. It supports threat hunting and incident response by helping teams anticipate an adversary’s next moves over the medium term.

Tactical intelligence concentrates on the attacker’s Tactics, Techniques, and Procedures (TTPs) and how to detect them. It is aimed at front-line defenders and informs security tools, often mapped to frameworks like MITRE ATT&CK. Its shelf life is shorter than strategic intelligence but longer than raw indicators.

Technical intelligence is the most granular type, comprising the actual artifacts left by attackers, such as malicious IPs, domains, file hashes, and malware signatures. This intelligence is highly perishable, as attackers quickly rotate infrastructure, and is primarily consumed automatically by security tools rather than by human analysts.

Note: Some frameworks may present only three types (strategic, operational, tactical), incorporating technical intelligence into the tactical category. Both models are valid; the four-type model specifically separates raw artifacts into their own class.

Real-World Example

The SolarWinds/SUNBURST campaign illustrates all four types of threat intelligence in action:

  • STRATEGIC: “Nation-state actor APT29 (Cozy Bear, tied to Russia’s SVR) conducts long-term espionage via software supply chains.” This insight informs executive decisions, such as a board deciding to fund a supply-chain risk program.
  • OPERATIONAL: “The actor trojanizes signed software updates, stays dormant ~2 weeks, then beacons to C2 via a DGA.” This guides threat hunters to search for dormant backdoors and unusual DNS activity.
  • TACTICAL: MITRE ATT&CK T1195.002 (Supply Chain Compromise) and T1071 (Application Layer Protocol for C2). This detail allows detection engineers to create rules for these specific behaviors.
  • TECHNICAL: Indicators such as avsvmcloud[.]com and its DGA subdomains, and SUNBURST DLL hashes. These are automatically used by firewalls and EDR systems to block malicious activity.

In this single event, strategic intelligence shaped the budget, operational insight guided threat hunting, tactical details enabled detection rule creation, and technical indicators facilitated automated blocking by machines. Each of the four levels provided critical, distinct perspectives on the same attack.

Why It Matters

Relying on only one type of threat intelligence can create significant security gaps. For instance, an organization with only technical feeds might effectively block current malicious IPs but miss a strategic warning about a new actor targeting its industry. Conversely, an organization with only strategic reports might understand the broader threat landscape but lack the means to detect an active intrusion.

The four types of threat intelligence are complementary: strategic intelligence sets the overall direction, operational intelligence tracks live campaigns, tactical intelligence facilitates the development of detection mechanisms, and technical intelligence powers automated blocking. Platforms like SOCRadar play a vital role in integrating these disparate types of intelligence, ensuring that each is effectively routed to the appropriate consumer within the organization.

An analogy can be drawn to military operations: strategic intelligence involves the general’s decision on which country to defend. Operational intelligence is the commander tracking an enemy division’s movements. Tactical intelligence is the sergeant who understands the enemy’s patrol patterns. Technical intelligence is the sentry recognizing a specific enemy uniform at the gate. All four levels contribute to the defense of a base, albeit at different scales and with different focuses.

People Also Ask

Are there three or four types of threat intelligence? Both models exist. Some frameworks use three (strategic, operational, tactical); the four-type model adds technical as its own category for raw artifacts.

Which type is easiest to produce? Technical and tactical intelligence, because indicators can be collected and shared automatically. Strategic intelligence takes the most human analysis.

Which type lasts the longest? Strategic intelligence. Trends and actor motivations change slowly, while technical indicators can expire within hours.

Sources and Further Reading

What are the Types of Cyberthreat Intelligence? (Palo Alto Networks)

What is Tactical Cyber Threat Intelligence (SOCRadar)

SolarWinds/SUNBURST Analysis (Google Cloud / Mandiant)

Key points
  • Strategic intelligence focuses on the 'who' and 'why' of attacks, informing long-term business risk and decision-making.
  • Operational intelligence details active campaigns and adversary behavior, guiding threat hunting and incident response.
  • Tactical intelligence highlights the 'how' of attacks, providing TTPs for detection and defense.
  • Technical intelligence consists of raw, granular artifacts like IPs and hashes, primarily used by security tools for automated blocking.
  • A mature threat intelligence program integrates all four types to ensure comprehensive security.
Back to all questions