CTI Types
Explore the 4 main types of Cyber Threat Intelligence and discover how each serves specific objectives in your security strategy.
Classification of Threat Intelligence types
Each type of CTI responds to specific needs and targets different organizational levels with varying time horizons.
Strategic CTI
High-level intelligence for strategic decision-making
Executive leadership, strategic decision-makers, CISO
Long-term (6-12 months)
Characteristics
Threat landscape overview and trends
Analysis of adversary motivations and capabilities
Long-term risk assessment
Support for strategic decision-making
Concrete examples
Benefits
- Security and business alignment
- Justification of security investments
- Anticipation of emerging threats
- Executive communication
Typical deliverables
Primary sources
Tactical CTI
Information on adversary tactics, techniques, and procedures (TTPs)
SOC teams, security analysts, threat hunters
Medium-term (1-6 months)
Characteristics
Analysis of attack methods
Identification of attack patterns
Detection of ongoing campaigns
Improvement of detection capabilities
Concrete examples
Benefits
- Improved detection
- SIEM rule optimization
- More effective threat hunting
- Understanding of adversaries
Typical deliverables
Primary sources
Technical CTI
Technical details on attacker tools, malware, and infrastructure
Technical analysts, response teams, DFIR
Short-term (days-weeks)
Characteristics
Indicators of compromise (IOCs)
Malware analysis
Infrastructure mapping
Attack signatures
Concrete examples
Benefits
- Automated blocking
- Immediate detection
- Alert enrichment
- Reduction of false positives
Typical deliverables
Primary sources
Operational CTI
Information on ongoing or imminent attack campaigns
Response teams, 24/7 SOC, CSIRT
Real-time (minutes-hours)
Characteristics
Real-time alerts
Detection of active attacks
Incident response
Defense coordination
Concrete examples
Benefits
- Ultra-fast response
- Prevention of incidents
- Multi-team coordination
- Reduced detection time
Typical deliverables
Primary sources
Comparative table of CTI types
Quickly understand the differences and choose the right type of CTI based on your needs.
| Type | Primary objective | Target audience | Time horizon | Typical format |
|---|---|---|---|---|
Strategic | Business and budgetary decisions | Leadership, CISO | 6-12 months | Executive briefings |
Tactical | Improved detection | SOC, Analysts | 1-6 months | TTP reports |
Technical | Blocking and detection | Technical analysts | Days-weeks | IOC feeds |
Operational | Immediate response | Response teams | Real-time | Emergency alerts |
How to choose the right CTI type?
Select the type of CTI based on your objectives, your audience, and your time horizon.
For leadership
Executive reports, sector trends, business risks
For the SOC
Adversary TTPs, detection improvements, threat hunting
For analysts
IOCs, malware signatures, YARA/Snort rules
For response
Real-time alerts, active campaigns, fresh IOCs
💡 Expert tip
A mature organization uses all types of CTI in a complementary way: strategic CTI to guide, tactical to optimize, technical to block, and operational to respond quickly.
Ready to deepen your CTI knowledge?
Explore the models and frameworks to structure your threat intelligence program.