SER-005 — Threat Intelligence
**Threat intelligence as decision support**—how organizations interpret external threat knowledge to prioritize action, scope investigation, and communicate urgency. **Not** feed ingestion mechanics, TI platform tours, or MITRE encyclopedias.
SER-005 — Threat Intelligence
Series: SER-005
Volume: VOL-002 Intelligence
Version: 1.0
Fundamental question: How should organizations transform threat intelligence into actionable security decisions?
Pillar: PIL-THREAT-INTEL
Season: SEA-003
Status: ✅ Complete — FROZEN (D1 drafts)
Review: Every 6 months (next: 2027-01-03)
Expansion: SER-005 v2.0 only — no new articles in v1.0
Learning path: LP-005
Prerequisite: Volume 1 (minimum: KID-CON-0030, KID-CON-0049)
Purpose
Threat intelligence as decision support—how organizations interpret external threat knowledge to prioritize action, scope investigation, and communicate urgency. Not feed ingestion mechanics, TI platform tours, or MITRE encyclopedias.
Educational flow: Volume 1 analytical foundations → External knowledge → decisions
Authority anchors: KID-GLS-0005, KID-TIN-0001
Foundation for: SER-006 Operational Intelligence · SER-007 Security Intelligence
Reading order
| Order | KID | Article | Difficulty | Time |
|---|---|---|---|---|
| — | — | Prerequisite: Volume 1 | — | — |
| 1 | KID-GLS-0005 | Threat Intelligence (term) | — | 3 min |
| 2 | KID-CON-0050 | Understanding Threat Intelligence | Introductory | 9 min |
| 3 | KID-CON-0051 | Threat Intelligence vs Detection | Introductory | 8 min |
| 4 | KID-CON-0054 | Common Misconceptions About Threat Intelligence | Introductory | 10 min |
| 5 | KID-CON-0052 | Why Threat Intelligence Changes Priorities | Intermediate | 8 min |
| 6 | KID-CON-0053 | Context Matters in Threat Intelligence | Intermediate | 8 min |
| 7 | KID-CON-0055 | Using Threat Intelligence for Security Decisions | Intermediate | 9 min |
| 8 | KID-CON-0056 | Threat Intelligence in Investigation | Intermediate | 9 min |
| 9 | KID-GLS-0024 | Intelligence Confidence (term) | — | 3 min |
| 10 | KID-GLS-0025 | Threat Indicator (term) | — | 3 min |
| 11 | KID-CON-0057 | When Threat Intelligence Is Not Enough | Intermediate | 8 min |
| 12 | KID-CON-0058 | Threat Intelligence as Decision Support | Intermediate | 10 min |
Practitioner questions answered
| Question | Primary KID |
|---|---|
| What is threat intelligence? | KID-CON-0050, KID-GLS-0005 |
| Is TI the same as detection? | KID-CON-0051 |
| Why did priority change after TI? | KID-CON-0052 |
| How much should I trust this report? | KID-CON-0053, KID-GLS-0024 |
| What mistakes do teams make? | KID-CON-0054 |
| What decisions should TI drive? | KID-CON-0055 |
| How use TI in investigation? | KID-CON-0056 |
| When is TI insufficient? | KID-CON-0057 |
| What is the core thesis? | KID-CON-0058 |
Glossary (series terms)
| KID | Term | Status |
|---|---|---|
| KID-GLS-0005 | Threat Intelligence | ✅ shared |
| KID-GLS-0024 | Intelligence Confidence | ✅ |
| KID-GLS-0025 | Threat Indicator | ✅ |
FAQs (attached)
| KID | Question | Primary parent |
|---|---|---|
| KID-FAQ-0026 | What is threat intelligence? | KID-CON-0050 |
| KID-FAQ-0027 | Does TI replace detection? | KID-CON-0051 |
| KID-FAQ-0028 | How does TI help prioritization? | KID-CON-0052 |
| KID-FAQ-0029 | When ignore threat intelligence? | KID-CON-0057 |
| KID-FAQ-0030 | Does TI prove an attack? | KID-CON-0056 |
Not in scope (v1.0)
- Feed ingestion and platform configuration
- STIX/TAXII protocol tutorials
- Standalone MITRE ATT&CK technique encyclopedia
- ISAC membership or sharing agreements
Publishable bundle (debt)
| ID | Component | Status |
|---|---|---|
| DEBT-S5-001 | Pillar hub PIL-THREAT-INTEL | ⏳ |
| DEBT-S5-002 | Concept map MAP-TI-DECISIONS | ⏳ |
| DEBT-S5-003 | Learning path LP-005 formal INDEX | ⏳ |
| DEBT-S5-004 | D2 human review batch | ⏳ |
Collection statistics
| Asset type | Count |
|---|---|
| Educational articles | 9 |
| Glossary terms (series) | 3 |
| FAQ attachments | 5 |
| New KIDs this collection | 14 |
| Cumulative registered KIDs | 120 |