Blog
Insights on cyber threat intelligence, AI-powered security, and staying ahead of emerging threats.

Wiring OpenCTI and MISP into an AI Agent Workflow with MCP
Which MCP servers to use for OpenCTI and MISP, the exact configuration that works, and what agent-driven enrichment looks like once both are wired in.

LLMs in Cybersecurity: Where AI Helps in Threat Intelligence, and Where It Does Not
Where large language models genuinely help in threat intelligence, where they fail, and how to get the 80 per cent upside while humans keep the judgement.

Claude Code for Threat Intelligence: Turning a Coding Agent into a CTI Workstation
How to use Claude Code for threat intelligence: load open CTI skills, run enrichment, tradecraft and reporting on your own keys, and keep the judgement human.

AI and the Security Analyst: What the Role Loses, and What It Keeps
AI is changing the security analyst's job rather than removing it: agents take the mechanical work, analysts keep the judgement and cover far more ground.

Agentic AI in Threat Intelligence: How Analyst-in-the-Loop CTI Actually Works
What agentic AI means in threat intelligence: a stack of specialised agents runs collection, enrichment and tradecraft while the analyst keeps the judgement.

How to Set Up Your Own OpenCTI Server with Docker
Stand up your own OpenCTI community edition server with Docker: the setup sequence that works, plus real gotchas from Apple Silicon images to .env defaults.

AI for Threat Intelligence: How LLMs and Agents Change CTI
How AI is used in threat intelligence: LLMs and agents automate collection, enrichment and reporting, while the analyst keeps the judgement.

What Is STIX? Structured Threat Intelligence Explained
STIX is the open standard for structured, machine-readable cyber threat intelligence. What STIX is, how it relates to TAXII, and what STIX 2.1 contains.

The Threat Intelligence Lifecycle: Six Phases Explained
The threat intelligence lifecycle turns raw data into decisions through six phases: direction, collection, processing, analysis, dissemination and feedback.

What Is a Threat Intelligence Feed? Types, Examples and Limits
A threat intelligence feed is a continuously updated stream of threat data, usually indicators of compromise, that tools ingest automatically. Types and limits.

The Four Types of Threat Intelligence: Strategic, Operational, Tactical, Technical
The four types of threat intelligence are strategic, operational, tactical and technical. What each one answers, who consumes it, and how they fit together.

What Is a Threat Intelligence Platform (TIP)? A Clear Definition
A threat intelligence platform (TIP) collects, enriches and assesses threat data, turning it into finished intelligence. How a TIP differs from a feed.

Per-Customer Threat Intelligence vs Generic IOC Reports
Why a context-free IOC report underdelivers at a customer's desk, and what per-customer threat intelligence means: relevance, context, and detection content.

Threat Intelligence as an MSSP Revenue Stream, Not a Cost Centre
Why threat intelligence usually lands as an MSSP cost, and what makes it a service line that grows margin: per-customer relevance and branded delivery.

White-Label Threat Intelligence: What to Look For
A buyer's guide for MSSPs evaluating a white-label threat intelligence platform: five questions to ask before you put your brand on someone else's intel.

How MSSPs Deliver Threat Intelligence as a Service
What a real managed threat intelligence service has to deliver for every customer, and how an MSSP can offer it without hiring analysts or building a platform.

PIRs in Practice: How to Make Your Intelligence Impossible to Ignore
A practitioner's how-to for building Priority Intelligence Requirements, writing CTI that gets read, and managing stakeholders who act on reports.

How to Evaluate a TIP: A Practitioner's Checklist
A six-step practitioner's checklist for evaluating threat intelligence platforms, operating model, market map, workflow scenarios, and build-vs-buy in 2026.

From Intelligence to Detection: Operationalising MITRE ATT&CK
MITRE ATT&CK, the Diamond Model, and the Pyramid of Pain: how to operationalise CTI frameworks instead of just referencing them in reports.

Threat Actor Profiling for Defenders: A Practical Framework
A practical framework for threat actor profiling that prioritises operational value over attribution: categories, profiles, and tying CTI to defence.

Intelligence Requirements: Self-Maintaining Knowledge for CTI Teams
Liberty91's new Intelligence Requirements turn the questions a CTI team needs answered on an ongoing basis into self-maintaining knowledge bases.

Cognitive Biases in CTI: Structured Techniques for Sharper Analysis
How confirmation bias, anchoring, and the availability heuristic distort threat intelligence, and the techniques analysts use to counteract them.

Analysis of Competing Hypotheses: A Step-by-Step Guide for CTI
A step-by-step guide to Analysis of Competing Hypotheses (ACH) for cyber threat intelligence, with a step-by-step example and matrix template.

How to Build a Collection Plan in 5 Steps
Most CTI teams collect intelligence the way people grocery shop, without a list. A collection plan connects your needs to your sources.

A Practitioner’s Guide to the Intelligence Lifecycle
What cyber threat intelligence actually is, why most teams confuse it with information management, and what the intelligence lifecycle looks like in practice.

Rewriting the News Is Not Intelligence, But Someone Still Has to Do It
A CTI veteran responds to the viral Hard Cyber Threat Intel Pills image. Some pills are spot-on. Some need nuance. And one misses the real problem entirely.

The Top Cybersecurity and Threat Intelligence Blogs (2025 Edition)
A practitioner's guide to the cybersecurity and CTI blogs, research labs, national CERTs, and vulnerability feeds worth reading in 2025.

The 80/20 Problem in Cyber Threat Intelligence (and Why It’s Structural)
CTI analysts spend ~80% of their time on collection and report assembly, 20% on actual analysis. It’s a structural challenge, not a skills gap.

How to Build a Threat Profile: A Step-by-Step Walkthrough for Mid-Market Security Teams
A walkthrough of building a threat profile for a fictional mid-market fintech, from PIRs to TTP-level detection coverage with a one-page artefact.
Want to see this on your own organisation?
Request a demo or start your free trial, and you will be looking at threat intelligence built around your own organisation rather than a generic one.
