Blog
Insights on cyber threat intelligence, AI-powered security, and staying ahead of emerging threats.

Wiring OpenCTI and MISP into an AI Agent Workflow with MCP
Which MCP servers to use for OpenCTI and MISP, the exact configuration that works, and what agent-driven enrichment looks like once both are wired in.

LLMs in Cybersecurity: Where AI Helps in Threat Intelligence, and Where It Does Not
Where large language models genuinely help in threat intelligence, where they fail, and how to get the 80 per cent upside while humans keep the judgement.

Claude Code for Threat Intelligence: Turning a Coding Agent into a CTI Workstation
How to use Claude Code for threat intelligence: load open CTI skills, run enrichment, tradecraft and reporting on your own keys, and keep the judgement human.

AI and the Security Analyst: What the Role Loses, and What It Keeps
AI is not replacing the security analyst, it is changing the job: agents take the mechanical work, analysts keep the judgement and cover far more ground.

Agentic AI in Threat Intelligence: How Analyst-in-the-Loop CTI Actually Works
What agentic AI means in threat intelligence: a stack of specialised agents runs collection, enrichment and tradecraft while the analyst keeps the judgement.

How to Set Up Your Own OpenCTI Server with Docker
Stand up your own OpenCTI community edition server with Docker: the setup sequence that works, plus the real gotchas, from Apple Silicon images to .env defaults.

AI for Threat Intelligence: How LLMs and Agents Change CTI
How AI is used in threat intelligence: LLMs and agents automate collection, enrichment and reporting, while the analyst keeps the judgement. Where AI helps, where it fails, and how agentic CTI works.

What Is STIX? Structured Threat Intelligence Explained
STIX is the open standard for writing cyber threat intelligence in a structured, machine-readable form so tools can share it automatically. What STIX is, how it relates to TAXII, and what STIX 2.1 contains.

The Threat Intelligence Lifecycle: Six Phases Explained
The threat intelligence lifecycle turns raw data into decisions through six phases: direction, collection, processing, analysis, dissemination and feedback. A clear definition of each.

What Is a Threat Intelligence Feed? Types, Examples and Limits
A threat intelligence feed is a continuously updated stream of threat data, usually indicators of compromise, that security tools can ingest automatically. Here is what a feed contains, the main types, real examples, and where a feed stops being intelligence.

The Four Types of Threat Intelligence: Strategic, Operational, Tactical, Technical
The four types of threat intelligence are strategic, operational, tactical and technical. Here is what each one answers, who consumes it, how long it stays useful, and how they fit together.

What Is a Threat Intelligence Platform (TIP)? A Clear Definition
A threat intelligence platform (TIP) collects, enriches and assesses threat data, then turns it into finished intelligence people and tools can act on. Here is what a TIP does, and how it differs from a feed or a service.

Per-Customer Threat Intelligence vs Generic IOC Reports
Why a context-free IOC report underdelivers at a customer's desk, and what per-customer threat intelligence means: relevance, context, and detection content assessed per organisation.

Threat Intelligence as an MSSP Revenue Stream, Not a Cost Centre
Why threat intelligence usually lands as an MSSP cost, and what makes it a value-added service line that grows margin: per-customer relevance, branded delivery, and a provable audit trail.

White-Label Threat Intelligence: What to Look For
A practical buyer's guide for MSSPs and resellers evaluating a white-label threat intelligence platform: the five questions to ask before you put your brand on someone else's intelligence.

How MSSPs Deliver Threat Intelligence as a Service
What a real managed threat intelligence service has to deliver for every customer, and how an MSSP can offer it without hiring analysts or building a platform.

PIRs in Practice: How to Make Your Intelligence Impossible to Ignore
A practitioner's how-to for building Priority Intelligence Requirements, writing CTI that gets read, and managing stakeholders who act on reports.

How to Evaluate a TIP: A Practitioner's Checklist
A six-step practitioner's checklist for evaluating threat intelligence platforms, operating model, market map, workflow scenarios, and build-vs-buy in 2026.

From Intelligence to Detection: Operationalising MITRE ATT&CK
MITRE ATT&CK, the Diamond Model, and the Pyramid of Pain: how to operationalise CTI frameworks instead of just referencing them in reports.

Threat Actor Profiling for Defenders: A Practical Framework
A practical framework for threat actor profiling that prioritises operational value over attribution: categories, profiles, and tying CTI to defence.

Intelligence Requirements: Self-Maintaining Knowledge for CTI Teams
Liberty91's new Intelligence Requirements turn the questions a CTI team needs answered on an ongoing basis into self-maintaining knowledge bases.

Cognitive Biases in CTI: Structured Techniques for Sharper Analysis
How confirmation bias, anchoring, and the availability heuristic distort threat intelligence, and the techniques analysts use to counteract them.

Analysis of Competing Hypotheses: A Step-by-Step Guide for CTI
A step-by-step guide to Analysis of Competing Hypotheses (ACH) for cyber threat intelligence, with a worked example and matrix template.

How to Build a Collection Plan in 5 Steps
Most CTI teams collect intelligence the way people grocery shop, without a list. A collection plan connects your needs to your sources.

A Practitioner’s Guide to the Intelligence Lifecycle
What cyber threat intelligence actually is, why most teams confuse it with information management, and what the intelligence lifecycle looks like in practice.

Rewriting the News Is Not Intelligence, But Someone Still Has to Do It
A CTI veteran responds to the viral Hard Cyber Threat Intel Pills image. Some pills are spot-on. Some need nuance. And one misses the real problem entirely.

The Top Cybersecurity and Threat Intelligence Blogs (2025 Edition)
A practitioner's guide to the cybersecurity and CTI blogs, research labs, national CERTs, and vulnerability feeds worth reading in 2025.

The 80/20 Problem in Cyber Threat Intelligence (and Why It’s Structural)
CTI analysts spend ~80% of their time on collection and report assembly, 20% on actual analysis. It’s a structural challenge, not a skills gap.

How to Build a Threat Profile: A Worked Example for Mid-Market Security Teams
A walkthrough of building a threat profile for a fictional mid-market fintech, from PIRs to TTP-level detection coverage with a one-page artefact.
Ready to do more with less?
Request a demo or start your free trial today. Get instant access to AI-powered threat intelligence tailored to your organisation.
