> For the complete documentation index, see [llms.txt](https://106-sam.gitbook.io/ejptv2-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://106-sam.gitbook.io/ejptv2-notes/crto/getting-started/adversary-emulation-vs-simulation/threat-intelligence.md).

# Threat Intelligence

> Evidence-based knowledge, including context, mechanisms, indicators, implications and actionable advice, about an existing or emerging menace or hazard to assets that can be used to inform decisions regarding the subject's response to that menace or hazard
>
> — Gartner

The consumption and contextualisation of threat intelligence helps an organization identify emerging threats and their possible mitigations; frame testing (e.g. red team) scenarios; and compare activity within their environments with known TTPs and indicators of compromise (IoCs).&#x20;

The standards have been made available in an effort to rationalise TI-related data into common format:

* Common Attack Pattern Enumeration and Classfication (CAPSEC).
* Cyber Observables (CybOX).
* Microsoft Interflow
* Structured Threat Information (STIX).
* Trusted Automated eXchange of Indicator Information (TAXII).
