The intelligence cycle applied to cyber
Planning & Direction (what does the business need to know?) → Collection (feeds, OSINT, dark-web monitoring, honeypots, internal telemetry) → Processing (normalize, dedupe, enrich) → Analysis & Production (the analyst's judgment: so-what?) → Dissemination (right product to right consumer) → Feedback.
The three intel levels
- Strategic (board/CISO): adversary motivations, campaign trends, geopolitical drivers, budget priorities. Product: quarterly briefs.
- Operational (IR/SOC leads): specific campaigns targeting our sector, TTPs, infrastructure patterns. Product: threat reports.
- Tactical (SOC/EDR): IOCs — IPs, domains, hashes, URLs. Product: feeds & blocklists.
Pyramid of Pain
Hashes (trivially re-compiled) → IPs (VPNs/proxies rotate) → Domains (cheap DGA) → Network artifacts (patterns, C2 protocols) → Host artifacts (registry, mutexes) → TTPs (behavior — the hardest for adversaries to change). Push analysis UP the pyramid: blocking hashes is janitorial work; mapping behavior to ATT&CK is intelligence.
Pakistan threat landscape (what our CTI desk tracks)
Scam-call-center infrastructure (Islamabad raids 2026), smishing waves around 8171/BISP lures, WhatsApp-hijack campaigns via fake courier calls, Indian/regional APT activity against government (sidecopy/CVT-style lures), ransomware hitting textiles & hospitals, and deepfake investment solicitations impersonating Pakistani business figures. CTI graduates feed our Scam Gallery and national advisories.
