All Posts
Cyber Threat Intelligence
Operationalized Threat Intelligence
1
min read

When the Advisory Was Right, but Nobody Enforced It

Published on
August 7, 2026
Table of Contents

On March 7, 2017, Apache published a patch for a critical flaw in Struts. The next day, US-CERT notified Equifax directly that it needed to apply it. An internal order went out to staff, a scan meant to confirm the fix missed the exposed system, and the vulnerable application stayed unpatched until July 29. By then attackers had been inside for 76 days and had exposed data on more than 143 million people. The US House Oversight Committee's report lays out the timeline in full.

Every element of the intelligence Equifax needed existed and arrived on time. A named vulnerability, a direct government warning, a patch. What failed was operationalization: the distance between knowing and enforcing, measured here by months.

That distance is the CTI team's real adversary, and most days it's quieter than Equifax. A team identifies a threat, scores it, writes the advisory, and the recommended controls are sound. Then the advisory waits. In the common setup, context gets applied only when an alert fires and an analyst has a moment to query the threat intelligence platform for it, one case at a time. The intelligence was ready long before the environment acted on it.

The Intelligence Is Decaying While It Waits

Waiting carries a cost that's easy to underestimate, because adversary infrastructure doesn't sit still. Research compiled by Netresec found that most botnet command-and-control servers had a lifespan of two weeks or less. An indicator parked in a queue for manual handling can point at infrastructure that's already gone by the time anyone acts on it. Being right in a report and being right in the environment are separated by a latency that erases the indicator's value.

Feeds can’t rescue you from this on their own. When the researcher Xander Bouwman and colleagues compared two leading commercial threat intelligence feeds against each other, they found an average overlap of just 2.5% to 4% even for the threat actors both vendors claimed to track. Any single source captures a sliver of what's out there, so coverage can be  less about buying another feed than operationalizing what you already have, quickly.

What the CTI Team is Now Being Asked to Do

In the SANS 2025 CTI Survey, threat hunting was the top use case for cyber threat intelligence for the second year running, cited by 71% of respondents. Intelligence is being pulled toward operations, toward the question of what to do right now, and away from the report as the finished product.

The shift that makes that possible is to stop treating a CTI team's judgment as output and start treating it as infrastructure. The feed relationships, confidence thresholds, and curation standards a team has built can be fused into events as they land, so intelligence governs detection and response directly.

The shift that makes that possible is to stop treating a CTI team's judgment as output and start treating it as infrastructure. The feed relationships, confidence thresholds, and curation standards a team has built can be fused into events as they land, so intelligence governs detection and response directly.  

How Anomali Operationalizes It

This describes a change in where a CTI team's judgment lives. Managed Intelligence as a Service, powered by ThreatStream Next-Gen, is built to make that change concrete. The feed relationships, confidence thresholds, and curation standards a team has built become the governing intelligence fused into every event as it lands, rather than a service line an analyst queries after an alert fires. The judgment stops being output and starts being infrastructure.

  1. An organization's own intelligence goes first: its incident history, its past adversary encounters, its behavioral baselines, operationalized ahead of any external feed and then compounded with a curated threat repository.  
  1. High-confidence indicators are applied as controls the moment they arrive, so a vetted block lands in minutes instead of waiting on alert-by-alert enrichment.  
  1. Sharing community intelligence runs on Trusted Circles, bi-directional groups where a trusted peer's early warning becomes your early defense, distributed only to the recipients each circle's TLP setting allows, and free for ISAC and ISAO members.

None of this changes what a good CTI team already does, but it changes how quickly and how consistently it gets acted on; think fewer incidents where the team already had the intelligence to stop something and it didn't reach the environment in time.

The traditional measure of a CTI program has largely been what it produces: feeds curated, advisories published, questions answered. A future-looking measure is what it prevents. That only becomes possible when the team's judgment stops living in documents and starts living in the data every detection runs on.  

The advisory was already right. Now the work is making sure something acts on it while it still matters.

Find out more about operationalized, actionable threat intelligence here.  

FEATURED RESOURCES

September 16, 2026
No items found.

Ransomware's New Hire: Why Criminal Groups Are Recruiting Your Employees Instead of Hacking Them

Read More
September 15, 2026
Anomali Cyber Watch

Anomali Cyber Watch: Blob URL Phishing, Attackers Probing GitLab, WeChat Worm, Hackers Abused Claude, Rogue ScreenConnect Clients, Cisco Vulnerabilities

Blob URL Phishing Builds Login Pages Inside the Browser, Limiting URL-Based Detection. GitLab Patches Maximum-Severity File-Read Flaw, Attackers Probing Within a Day. Researchers Demonstrate Zero-Click WeChat Worm Capable of Autonomous Spread Across iOS and Android via Calls. Hackers Abused Claude to Extract Secrets from 1.8M Android Apps. Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts. Active Exploitation of Cisco Secure Firewall Management Center Vulnerabilities.
Read More
September 9, 2026
No items found.

Shadow AI in the Enterprise: Why Unapproved AI Tool Adoption Is Becoming a Systemic Data Governance Crisis

Most employees already paste company data into AI tools they were never approved to use. See what shadow AI exposes and where DLP and policy fall short.
Read More
Explore All