To optimize threat data collection, an enterprise security operations team must classify different threat intelligence feed types. Pair each threat intelligence category on the left with its defining operational characteristic on the right.
- Open-Source Intelligence (OSINT)Publicly available security information compiled from code repositories, blogs, and advisory sites.
- Sector-Specific ISACNon-profit peer network for exchanging industry-specific cyber threat alerts among member organizations.
- Commercial Threat IntelligenceSubscription-based compiled feed offering high-confidence indicators and dedicated customer support.
- Dark Web IntelligenceData gathered from anonymized underground marketplaces and encrypted forums monitoring stolen access keys.
Answer
Open-Source Intelligence (OSINT) matches publicly available security information. Sector-Specific ISAC matches non-profit peer network for exchanging industry-specific cyber threat alerts. Commercial Threat Intelligence matches subscription-based compiled feed offering high-confidence indicators. Dark Web Intelligence matches data gathered from anonymized underground marketplaces.
Each threat intelligence source corresponds directly to its defined collection domain: OSINT uses public resources, ISACs facilitate industry peer sharing, commercial feeds offer subscription-based IoCs, and dark web intelligence targets restricted underground channels.
Step-by-Step Solution
Key Concept
Classification and operational traits of threat intelligence sources