Liberty91

Blog

Insights on cyber threat intelligence, AI-powered security, and staying ahead of emerging threats.

A vintage telephone exchange switchboard with two glowing orange patch cords plugged in from opposite sides and converging into a single illuminated socket, representing two threat intelligence platforms wired into one agent workflow
Education

Wiring OpenCTI and MISP into an AI Agent Workflow with MCP

Which MCP servers to use for OpenCTI and MISP, the exact configuration that works, and what agent-driven enrichment looks like once both are wired in.

A massive cargo vessel at dusk guided into a narrow harbour entrance by one small pilot boat under warm orange lights, representing a powerful model steered by human judgement
Education

LLMs in Cybersecurity: Where AI Helps in Threat Intelligence, and Where It Does Not

Where large language models genuinely help in threat intelligence, where they fail, and how to get the 80 per cent upside while humans keep the judgement.

The Claude Code logo centred on a dark navy wall with the words for Threat Intelligence beneath it, above a sleek desk silhouette lit by a warm orange terminal glow
Education

Claude Code for Threat Intelligence: Turning a Coding Agent into a CTI Workstation

How to use Claude Code for threat intelligence: load open CTI skills, run enrichment, tradecraft and reporting on your own keys, and keep the judgement human.

An editor's desk under a warm lamp with a red pencil resting on a stack of typeset proof pages, representing the analyst reviewing and signing off work produced by AI agents
Education

AI and the Security Analyst: What the Role Loses, and What It Keeps

AI is not replacing the security analyst, it is changing the job: agents take the mechanical work, analysts keep the judgement and cover far more ground.

An aircraft cockpit at night with the autopilot panel glowing amber and the pilot's hand resting lightly on the controls, representing agentic AI running the process while the analyst keeps the judgement
Education

Agentic AI in Threat Intelligence: How Analyst-in-the-Loop CTI Actually Works

What agentic AI means in threat intelligence: a stack of specialised agents runs collection, enrichment and tradecraft while the analyst keeps the judgement.

A stack of navy industrial shipping containers with one door open revealing a glowing orange network graph inside, with the OpenCTI by Filigran logo, representing a self-hosted threat intelligence platform running in Docker
Education

How to Set Up Your Own OpenCTI Server with Docker

Stand up your own OpenCTI community edition server with Docker: the setup sequence that works, plus the real gotchas, from Apple Silicon images to .env defaults.

A brushed-steel robotic arm sorting metallic document cards into a tray beside a single human notebook and fountain pen on a deep navy background with warm orange rim light, representing AI carrying the mechanical work while the analyst keeps the judgement
Education

AI for Threat Intelligence: How LLMs and Agents Change CTI

How AI is used in threat intelligence: LLMs and agents automate collection, enrichment and reporting, while the analyst keeps the judgement. Where AI helps, where it fails, and how agentic CTI works.

Machined metal jigsaw pieces in brushed steel and brass interlocking cleanly into one panel on a deep navy background with warm orange rim light, representing a shared standard that lets tools fit together
Education

What Is STIX? Structured Threat Intelligence Explained

STIX is the open standard for writing cyber threat intelligence in a structured, machine-readable form so tools can share it automatically. What STIX is, how it relates to TAXII, and what STIX 2.1 contains.

A closed ring of interlocking brass and steel gears meshing into one continuous loop on a deep navy background, lit with warm orange rim light, representing the threat intelligence lifecycle as a cycle
Education

The Threat Intelligence Lifecycle: Six Phases Explained

The threat intelligence lifecycle turns raw data into decisions through six phases: direction, collection, processing, analysis, dissemination and feedback. A clear definition of each.

A continuous paper tape spooling out of a vintage stock ticker into a neat coil, deep navy tones with warm orange light, suggesting a steady automated stream of incoming data
Education

What Is a Threat Intelligence Feed? Types, Examples and Limits

A threat intelligence feed is a continuously updated stream of threat data, usually indicators of compromise, that security tools can ingest automatically. Here is what a feed contains, the main types, real examples, and where a feed stops being intelligence.

A brass nautical telescope, binoculars, a magnifying glass and a jeweller's loupe arranged largest to smallest on dark cloth, deep navy tones with warm orange light, suggesting four levels of magnification from the broad view down to fine detail
Education

The Four Types of Threat Intelligence: Strategic, Operational, Tactical, Technical

The four types of threat intelligence are strategic, operational, tactical and technical. Here is what each one answers, who consumes it, how long it stays useful, and how they fit together.

A vintage telephone switchboard with many cables converging into one ordered hub, deep navy tones with warm orange light, suggesting many sources aggregated into one platform
Education

What Is a Threat Intelligence Platform (TIP)? A Clear Definition

A threat intelligence platform (TIP) collects, enriches and assesses threat data, then turns it into finished intelligence people and tools can act on. Here is what a TIP does, and how it differs from a feed or a service.

A tailor's tape measure, a spool of orange thread and fabric shears resting on dark cloth, deep navy tones with warm orange light, suggesting bespoke tailoring
Industry

Per-Customer Threat Intelligence vs Generic IOC Reports

Why a context-free IOC report underdelivers at a customer's desk, and what per-customer threat intelligence means: relevance, context, and detection content assessed per organisation.

A neat row of identical branded report folders fanning out across a desk, deep navy with warm orange light, suggesting a service that scales per customer
Industry

Threat Intelligence as an MSSP Revenue Stream, Not a Cost Centre

Why threat intelligence usually lands as an MSSP cost, and what makes it a value-added service line that grows margin: per-customer relevance, branded delivery, and a provable audit trail.

A wooden rubber stamp pressing a clean brand mark onto a crisp report cover, deep navy with warm orange light
Industry

White-Label Threat Intelligence: What to Look For

A practical buyer's guide for MSSPs and resellers evaluating a white-label threat intelligence platform: the five questions to ask before you put your brand on someone else's intelligence.

A wall of labelled wooden mail pigeonhole sorting slots, deep navy tones with warm orange light, suggesting tailored dispatch to many recipients
Industry

How MSSPs Deliver Threat Intelligence as a Service

What a real managed threat intelligence service has to deliver for every customer, and how an MSSP can offer it without hiring analysts or building a platform.

Abstract geometric spotlight cutting through scattered noise particles to create a clear path from source to destination, deep navy background with warm orange and amber light
Industry

PIRs in Practice: How to Make Your Intelligence Impossible to Ignore

A practitioner's how-to for building Priority Intelligence Requirements, writing CTI that gets read, and managing stakeholders who act on reports.

Abstract geometric checklist or evaluation matrix on a deep navy background, with grid cells illuminated in warm orange and amber suggesting selection and evaluation
Industry

How to Evaluate a TIP: A Practitioner's Checklist

A six-step practitioner's checklist for evaluating threat intelligence platforms, operating model, market map, workflow scenarios, and build-vs-buy in 2026.

Abstract pipeline refining raw geometric ore into precise structured components, deep navy background with orange and amber light accents
Industry

From Intelligence to Detection: Operationalising MITRE ATT&CK

MITRE ATT&CK, the Diamond Model, and the Pyramid of Pain: how to operationalise CTI frameworks instead of just referencing them in reports.

Abstract dossier or profile card with structured data visualisations and directional arrows on a deep navy background with orange accents
Industry

Threat Actor Profiling for Defenders: A Practical Framework

A practical framework for threat actor profiling that prioritises operational value over attribution: categories, profiles, and tying CTI to defence.

Clean modular grid of glowing card-like knowledge objects on deep-navy background, with warm orange and amber light beams threading between adjacent cards, suggesting cross-references and continuous updates
Product

Intelligence Requirements: Self-Maintaining Knowledge for CTI Teams

Liberty91's new Intelligence Requirements turn the questions a CTI team needs answered on an ongoing basis into self-maintaining knowledge bases.

Abstract optical illusion with geometric shapes that appear different from different angles, deep navy background with orange and amber light
Industry

Cognitive Biases in CTI: Structured Techniques for Sharper Analysis

How confirmation bias, anchoring, and the availability heuristic distort threat intelligence, and the techniques analysts use to counteract them.

Abstract decision tree with multiple branching pathways diverging from a single point, deep navy background with orange and amber illuminated paths
Industry

Analysis of Competing Hypotheses: A Step-by-Step Guide for CTI

A step-by-step guide to Analysis of Competing Hypotheses (ACH) for cyber threat intelligence, with a worked example and matrix template.

Abstract architectural blueprint rendered in 3D, showing a structured framework being assembled from geometric components on a deep navy background
Industry

How to Build a Collection Plan in 5 Steps

Most CTI teams collect intelligence the way people grocery shop, without a list. A collection plan connects your needs to your sources.

Abstract geometric landscape with layered terrain, each layer representing a stage of refinement from raw textures to clean precise forms
Industry

A Practitioner’s Guide to the Intelligence Lifecycle

What cyber threat intelligence actually is, why most teams confuse it with information management, and what the intelligence lifecycle looks like in practice.

Abstract data streams flowing from collection nodes into analytical patterns, representing the shift from rote monitoring to true intelligence analysis
Industry

Rewriting the News Is Not Intelligence, But Someone Still Has to Do It

A CTI veteran responds to the viral Hard Cyber Threat Intel Pills image. Some pills are spot-on. Some need nuance. And one misses the real problem entirely.

Stack of open editorial reference books and hardcover volumes with orange-ink article layouts, the top book embossed with a geometric Liberty91 bull head, dramatically lit on a deep navy surface
Guide

The Top Cybersecurity and Threat Intelligence Blogs (2025 Edition)

A practitioner's guide to the cybersecurity and CTI blogs, research labs, national CERTs, and vulnerability feeds worth reading in 2025.

Cinematic hourglass on a navy desk with warm orange sand almost fully collected in the bottom chamber, a small amount still falling, a geometric Liberty91 bull head embossed on the wooden frame, dramatic side lighting
Industry

The 80/20 Problem in Cyber Threat Intelligence (and Why It’s Structural)

CTI analysts spend ~80% of their time on collection and report assembly, 20% on actual analysis. It’s a structural challenge, not a skills gap.

Leather-bound intelligence dossier with a geometric Liberty91 bull head embossed as an official seal on the cover, structured chart and matrix pages protruding from the side, dramatically side-lit on a deep navy surface
Guide

How to Build a Threat Profile: A Worked Example for Mid-Market Security Teams

A walkthrough of building a threat profile for a fictional mid-market fintech, from PIRs to TTP-level detection coverage with a one-page artefact.

Ready to do more with less?

Request a demo or start your free trial today. Get instant access to AI-powered threat intelligence tailored to your organisation.