Core Concepts

Mastering the Intelligence Cycle

A practitioner's guide to analysis

Process is as important as data in threat intelligence. Without a structured workflow, analysts risk falling into "data chasing," collecting endlessly without delivering actual value. The Intelligence Cycle is the professional standard for turning raw information into finished intelligence.

The Six Stages

01. Direction & Planning

The most critical and often skipped step is defining your Prioritized Intelligence Requirements (PIRs): what specific questions are you trying to answer, and who is the customer? Answering both prevents "scope creep" and keeps the output actionable.

02. Collection

This stage gathers the raw data needed to answer the PIRs: OSINT, technical feeds, internal logs, and dark web monitoring. Quality matters more than volume.

03. Processing & Exploitation

This stage converts raw data into a format that can be analyzed, normalizing IOCs, translating foreign language reports, and de-duplicating entries.

04. Analysis & Production

This stage applies Structured Analytic Techniques (SATs) to find patterns, identify TTPs, and weigh the "so what?" factor. Good analysis provides context along with facts.

05. Dissemination

This stage gets the finished intelligence to the right person, in the right format, at the right time. A tactical report for the SOC looks very different from a strategic brief for the CISO.

06. Feedback & Evaluation

Was the intelligence useful? Did it answer the PIR? Feedback closes the loop, guides the "Direction" for the next cycle, and keeps the process improving.

Pro-Tip for Analysts

Avoid Confirmation Bias by actively seeking information that disproves your current hypothesis. Use "Analysis of Competing Hypotheses" (ACH) for high-stakes assessments.

Next Steps

Mastering the cycle transforms you from a "searcher" into a "professional analyst." See how to automate the processing stage or learn how to apply MITRE ATT&CK during analysis.