Tell us what you need to know, and we keep finding out.
Intelligence Requirements are the questions your organisation needs answered about threats. You write them in plain language, and Liberty91 gives each one its own agent that reads every new piece of threat reporting, day and night, and tells you what it means for you.
What is an Intelligence Requirement?
An Intelligence Requirement is a specific question about threats that your organisation needs answered. It is where threat intelligence work starts: the question decides what you go looking for, what gets analysed, and what you report back.
A good requirement looks like: “What threat actors are actively targeting financial services in the Gulf region, and what initial compromise techniques are they using?” A weak one looks like: “Keep us updated on threats.”
Priority Intelligence Requirements (PIRs)
You will also hear people say Priority Intelligence Requirement (PIR). It means the same thing: an Intelligence Requirement that has been prioritised. On Liberty91 you write the requirements and the platform does the prioritising for you, continuously, based on what is happening in the real world and how much of it applies to you. That is why we just call them Intelligence Requirements.
Read the longer piece on what threat intelligence is and how the work flows →
Three types of Intelligence Requirements.
Most organisations need all three. Liberty91 runs them at the same time and joins up what it finds across them.
Threats to you
Watch the technology you actually run: your servers, your platforms, the software in your stack. You get the new vulnerabilities (CVEs), the exploits, the patch advisories, and any active attack aimed at the versions you have, tied back to the specific systems you care about.
Threats from adversaries
Follow the groups that concern you: named threat actors, ransomware crews, and the industries being hit right now. Liberty91 tracks how they break in and what they do next (their attacker behaviour) for your region and your industry, and reads every new report about them against your own profile so you get something you can act on.
Concerns specific to your organisation
Cover the things only you would think to ask about: your executives being targeted, someone impersonating your brand, staff passwords turning up in a leak, chatter about a deal you are working on, or one of your suppliers being breached. A general threat feed will never go looking for these, because they are specific to you.
What Intelligence Requirements give you.
Five things you get from the moment your Intelligence Requirements are switched on.
Always-current knowledge
Liberty91 runs and maintains its own Intelligence Requirements covering industries, countries, malware families, threat actors, and supply-chain risks. They keep learning from everything that comes in, so what they know grows instead of going stale.
Yours stays yours
Write your own Intelligence Requirements for the topics that only matter to your team. Anything you create, and any data you give it, stays private to your organisation.
Context on every event
Everything arriving on the platform is read against each Intelligence Requirement it touches. So a new report never lands cold: it comes with everything the platform has already learned on that subject, and your analysts start with the full background instead of rebuilding it every time.
Not just threats
Intelligence Requirements are not only about attackers. They also cover your own side: the suppliers you depend on, the systems and technology you run, your executives, and confidential interests like an acquisition in progress. You get the whole picture rather than half of it.
They work together
Intelligence Requirements talk to each other. Ask a question and the answer is pulled from every requirement that touches it, in one place, with links back to the sources it came from.
How the agents work a requirement.
Each Intelligence Requirement gets its own agent, working only for you. That agent keeps a store of everything it has already read on the subject, and draws on it the next time something new comes in.
When new reporting arrives, the agents work together. Say a vulnerability turns up in a product you run, and the company behind that product is also one of your suppliers: both requirements analyse it, and each writes it up for its own audience.
What the agents produce feeds everything else on the platform: your daily morning report, answers to the questions your stakeholders send in, Sigma detection rules for the SOC, fix-it steps for the people running the systems, and short briefs for the board.

Why this is easier than doing it by hand.
Set it up in plain language
Add, remove, or adjust a requirement without writing code or building rules. Describe what you care about in your own words and the agents reorganise around it.
The agents work together
When something matters to two of your requirements, both of them look at it. A vulnerability in software one of your suppliers runs shows up under the supplier requirement and under the requirement covering your own technology, written the right way for each.
Self-updating knowledge
Each requirement builds up its own knowledge and refreshes it every time something relevant arrives. The agent does not start from scratch on Monday morning; it carries on from everything it has already read.
One requirement, many outputs
The same Intelligence Requirement can produce a short summary for the board, indicators of compromise and Sigma detection rules the SOC can load straight into its tools, a briefing for your analysts, and a report for anyone else who needs one. You pick the audience and ask for it when you need it.
Built for everyone who uses the intelligence.
Intelligence Requirements work the same way underneath, but what comes out is written for whoever is reading it.
Frequently Asked Questions.
Want to see this on your own organisation?
Request a demo or start your free trial, and you will be looking at threat intelligence built around your own organisation rather than a generic one.