All Posts
Cyber Threat Intelligence
1
min read

What is Tactical Threat Intelligence?

Published on
July 26, 2018
Table of Contents

This is the fourth blog in a series called, “What is Threat Intelligence?”. Continue with the series at the bottom of this page.

Tactical Intelligence

Tactical intelligence is the on-the-ground view, which describes granular, atomic indicators that are associated with known attacks. This is the most basic form of threat intelligence and is often used for machine-to-machine detection of threats, and for incident responders to search for specific known-bad artifacts in enterprise networks. These are your common “IOCs.”

Tactical Intel for APT29

  • 628d4f33bd604203d25dbc6a5bb35b90
  • 2aabd78ef11926d7b562fd0d91e68ad3
  • 3d3363598f87c78826c859077606e514
  • meek-reflect.appspot.com
  • portal.sbn.co.th
  • 202.28.231.44
  • hxxps://files.counseling[.]org/eFax/incoming/150721/5442.zip
  • googleService.exe
  • GoogleUpdate.exe
  • acrotray.exe
  • PCIVEN_80EE&DEV_CAF

Tactical Intel for Education Sector

  • d9b7b0eda8bd28e8934c5929834e5006
  • support@securitygrade[.]org
  • 46.244.4.37
  • Fish love water!!!!!!!!
  • Fish not love cat!!!!!!!
  • parol

Using Tactical Intelligence

Tactical intelligence and IOCs are meant to historically document cyber attacks, serving both as a corpus of evidence (for compliance, law enforcement, investigations, legal purposes, and CYA’s for executives who need to withstand scrutiny on why their company got pwned) and also as reference material for analysts to interpret and extract context for use in defensive operations.

IOCs come from bona fide incidents and malware and are provided to analysts at a tactical level to serve as examples of a particular threat, such as a particular malware sample, malware family, intrusion campaign, or threat actor. IOCs represent a small sample of known-bad things -- not all known-bad things -- and obviously, IOCs cannot find any unknown-bad things.

Think of an IOC as a biological specimen in a laboratory. An invasive plant in the United States is captured and brought back to the lab. It is meant to be studied carefully, weighed and measured, dissected, classified and so forth. From this study, we may glean insights on where it came from, who created it, its role in the ecosystem, what makes it healthy, and what kills it. We may be able to figure out its perfect environment and use that knowledge to find other plants like it. We may be able to cut it apart and find out how it spreads so quickly. We might be able to use attributes of the plant to find other invasive plants. IOCs require the same study for application in cyber defense.

Check out the other blogs in our series for a deeper look into the types of threat intelligence and how they are used.

What is Threat Intelligence?
What is Strategic Threat Intelligence?
What is Operational Threat Intelligence?

FEATURED RESOURCES

August 18, 2026
Anomali Cyber Watch

Anomali Cyber Watch: AmnesiaStealer - Credential Theft Meets Live Browser Hijacking on macOS, Akira Ransomware Deploys Safe Mode to Evade Detection, but Encryption Fails, and more

AmnesiaStealer: Credential Theft Meets Live Browser Hijacking on macOS, Akira Ransomware Deploys Safe Mode to Evade Detection, but Encryption Fails, DeadLock Ransomware Uses Decentralized Infrastructure to Evade Takedown Efforts, ShieldBreak: Researcher Publishes Patch Bypass Claim for Microsoft Defender Zero-Day CVE-2026-50656, Zoom Patches High-Severity Annotation Vulnerabilities Enabling Remote Code Execution Across Multiple Product Lines, Autonomous Multi-Agent AI Framework Achieves Confirmed Compromises Against Taiwanese Government Networks
Read More
August 11, 2026
Operationalized Threat Intelligence
Agentic SOC

OCSF, Explained: Why a Common Schema Changes How Security Teams Work

How a vendor-neutral schema turns fragmented telemetry into data your analysts, detections, and AI agents can all read.
Read More
August 11, 2026
Anomali Cyber Watch

Anomali Cyber Watch: Your AI Clicked Something, Your Dev Tools Have Worms, and the Hotel Wi-Fi Was Literally a Spy

Midnight Blizzard's CaptiveCrunch Campaign Turns Hotel Wi-Fi Into an Espionage Tool. AI Cyber Testing Incidents Multiply as Frontier Models Reach Real Systems and People. ChainDrop Worm Turns Developer Tools Into a Self-Spreading Supply Chain Threat. N-able N-central Authentication Bypass Under Active Exploitation. DOUBLECUP ClickFix Loader-as-a-Service Delivers CountLoader and DeviceManager RATs. Zero-Click Indirect Prompt Injection Attacks Target AI Agentic Browsers, Enabling Account Takeover and Unauthorized Actions.
Read More
Explore All