Share on social
September 23, 2026
Lorem ipsum
Cyberattacks rarely start where security teams are watching. By the time an attacker touches the network, they've usually spent weeks, months, or even years planning the operation, testing tools, buying access, and coordinating with other criminals - most of that activity happening in the open forums and marketplaces of the dark web. Cyber threat intelligence (CTI) is the discipline that closes that gap. It turns raw signals from the internal network, the open web, and the dark web into the context security teams need to stop an attack before it starts, rather than clean up after it lands.
What is Cyber Threat Intelligence (CTI)?
Cyber threat intelligence is the process of collecting, analyzing, and applying data about cyber threats, adversaries, and attack methods to strengthen an organization's security posture. Rather than simply reacting to alerts, CTI gives security teams context on who is likely to target them, why, and how - shifting the function from reactive defense to proactive threat mitigation.
That distinction matters. A list of malicious IP addresses tells you what to block. Threat intelligence tells you which adversaries are targeting your sector, what tools and techniques they favor, and where your organization is already exposed - so your team can act before those indicators ever show up in your logs.
The four types of threat intelligence
CTI isn't a single feed or report - it operates at four levels, each built for a different audience and a different time horizon.
Strategic intelligence helps CISOs and boards decide where to invest and which risks are trending upward. Tactical intelligence is machine-readable and short-lived, feeding straight into security tools to block active threats. Operational intelligence gives incident responders the who, why, and how behind a specific campaign. Technical intelligence feeds detection systems like EDR and IDS platforms with the granular signatures they need to catch malware and exploits in the act.
Read for more information on the six-phase CTI lifecycle.
Why Threat Intelligence Matters
CTI has grown from a niche security function. The core reframe that threat intelligence forces on security teams is this: a cyberattack doesn't start on the network. It starts weeks, months, or even years earlier, when a threat actor does their reconnaissance, plans the operation, and buys or trades the tools, credentials, and access they need - largely on the dark web, out of sight of traditional network monitoring.
That's precisely why threat intelligence is so valuable. It's the only discipline positioned to catch an attack at the earliest point in the Cyber Kill Chain, before a network is ever breached. Traditional defenses such as firewalls, antivirus, and SIEM are built to catch an attack once it's already underway. CTI, and dark web monitoring specifically, is built to catch it before it launches.
Read more about what the dark web is and why cyber threat intelligence matters.
How Cyber Threat Intelligence Works
The six-phase CTI lifecycle
Effective CTI doesn't happen in a single step, but it runs on a continuous, six-phase cycle that refines intelligence over time.
- Planning & Direction: Defining Priority Intelligence Requirements (PIRs): what assets need protecting, and which threats matter most to the organization.
- Collection: Gathering raw data from internal logs, OSINT, ISACs, and dark web sources to address those requirements.
- Processing: Normalizing collected data into a standard, machine-readable format (such as STIX/TAXII), deduplicating and enriching it along the way.
- Analysis: Identifying patterns and adversary TTPs (tactics, techniques, and procedures) in the processed data, then producing practical recommendations.
- Dissemination: Routing the finished intelligence to the right audience: tactical IOCs to security tools for automated blocking, strategic briefings to executives.
- Feedback: Evaluating whether the intelligence actually met the original requirement, and using that assessment to refine the next cycle.
Each cycle sharpens the next one, and the requirements defined in step one evolve as the threat landscape changes.
Where the data comes from
A mature CTI program pulls from four categories of source, each covering a different blind spot:
- Internal sources: SIEM and XDR logs, SOC observations, and customer or supply chain data that reveal an organization's actual exposure.
- OSINT: Security blogs, news, social media, and public forums, which often surface early indicators.
- ISACs and government agencies: Sector-specific intelligence shared through trusted, vetted channels.
- Dark web and deep web intelligence: Underground forums, paste sites, and closed communities where threat actors actually plan, coordinate, and trade..
What Threat Actors Do on the Dark Web
The dark web is often talked about as a single, shadowy entity, but it's really a loose collection of forums, marketplaces, and sites serving very different criminal purposes. Understanding what actually happens there is the first step to knowing what to monitor for.
Covert communication: Criminals use dark web forums and encrypted channels like Telegram to plan attacks, trade exploits, and share techniques with each other - effectively an open (if hidden) knowledge base for cybercrime.
Marketplaces: Illegal goods and services change hands here, including stolen personal and financial data, hacking tools, and access to already-compromised systems (initial access brokering).
Leak sites: Ransomware groups run dedicated sites to publish stolen data as extortion leverage - proof that an attack has already succeeded, used to pressure victims into paying.
Reconnaissance and targeting discussions: Threat actors openly name specific organizations, industries, or regions they're planning to target, well before an attack ever launches. This is arguably the single most valuable - and most overlooked - signal available to defenders.
The value of this activity to a CTI team is that it's first-hand: rather than inferring intent after the fact, monitoring these spaces reveals how criminals actually operate, what tools they're using, and - critically - who they're currently targeting.
Learn more about the value of dark web data to cyber threat intelligence teams and the difference between deep versus dark web investigations.
The Risk of Not Monitoring the Dark Web
Ignoring the dark web doesn't just mean missing intelligence, it measurably increases the likelihood of a cyberattack. Research from Searchlight Cyber and Marsh McLennan quantified exactly how much:
Ultimately your organization shows up in any of these places and nobody's watching, you're significantly more likely to be breached - and you'll find out about it later than you should.
The business impact of getting this wrong
The consequences compound well beyond the initial breach:
- Financial losses: Cyber-incident losses have quadrupled since 2017, and the average ransomware payment reached roughly $1 million in 2024. In most cases, a single breach costs far more than proactive monitoring would have.
- Operational disruption: Attacks that start with compromised credentials often cause significant downtime, diverting security resources from prevention into firefighting.
- Reputational damage: Industry research has found that a large share of breached organizations subsequently find it harder to attract new customers, lose existing ones, or face negative publicity.
- Regulatory penalties: Under regulations like GDPR, fines for failing to adequately protect data can reach into the millions - and a lack of dark web visibility can compound compliance liability if a breach isn't caught quickly.
Case study: catching a breach before it escalated
In January 2024, a professional services firm used Searchlight Cyber's dark web monitoring tool to map its external attack surface and inventory its digital assets - IPs, domains, and subdomains. The tool surfaced a previously undetected breach: credentials tied to one regional branch were already being sold on a dark web forum.
Acting immediately, the firm reset passwords, applied additional security controls, and removed malware from infected devices before the compromise could spread further. The visibility didn't just stop that incident - it drove broader improvements across the organization, from employee security training to a centralized, trusted software repository. Without that intelligence, the infostealer malware behind the leak could have quietly kept harvesting credentials indefinitely.
Read more about how ignoring the dark web impacts an organization and the risks of not keeping an eye on the dark web
How Data Ends Up on the Dark Web
Data doesn't appear on dark web marketplaces by accident - it gets there through a handful of well-worn routes, almost always with financial motive behind it.
Phishing attacks: Scam emails designed to look like they come from a trusted source, built around urgency, trick recipients into handing over credentials or downloading malicious software that exfiltrates data.
Ransomware: Beyond encrypting a victim's systems, modern ransomware groups increasingly use double extortion - stealing data before encrypting it, then selling or leaking it on the dark web if the ransom goes unpaid.
Insider threats: Employees with legitimate access to sensitive data sometimes exfiltrate and sell it themselves, whether for financial gain or after being approached directly by criminals on the dark web.
Third-party and supply chain leaks: A single compromised supplier can expose data belonging to hundreds of downstream organizations, often without the ultimate victim ever being notified by the party that was breached.
How can you check if your data is on the dark web?
How to Monitor the Dark Web
Once an organization accepts that dark web visibility is necessary, the next question is how to actually get it. Most teams try one of two approaches before realizing they need a dedicated partner.
Why some approaches fall short
Point-in-time manual investigation: Analysts try to manually find and access relevant dark web sites - but these sites aren't indexed, addresses are effectively random strings, and some forums demand a cryptocurrency deposit or a referral just to gain entry. Even once access is secured, continuous human monitoring of dozens or hundreds of sites simply isn't sustainable, and posts that are later deleted or edited can be missed entirely if nobody happened to be watching at the right moment.
Automated scraping: Building your own scrapers seems like the logical next step, but dark web marketplaces and forums actively defend against it. Many use custom, purpose-built CAPTCHAs and anti-crawling mechanisms specifically designed to keep security teams and automated tools out.
What a mature monitoring capability looks like
The organizations that get real value from dark web intelligence typically partner with a vendor built entirely around this problem. Look for:
- Established, comprehensive coverage: years of experience and continuously updated visibility across marketplaces, forums, leak sites, and Telegram channels.
- Historic and archived data: not just a current-state snapshot, since posts can be deleted or edited after the fact.
- Automated categorization and enrichment: turning raw, unstructured mentions into structured intelligence analysts can actually act on.
- Asset discovery paired with continuous monitoring: knowing exactly what to monitor for (domains, IPs, credentials, executives) is a prerequisite, not an afterthought.
Questions to ask a dark web monitoring or CTI vendor
Before signing with a vendor, work through these questions:
- Can the vendor fulfil your specific intelligence gaps? Start with your actual requirement - are you trying to protect IP and brand reputation, or stop attacks before they start? - and evaluate vendors against that, not a generic feature list.
- How frequently is data collected? Hourly or daily collection matters enormously if you're trying to catch breached credentials before they're exploited; periodic collection introduces dangerous delay.
- Does coverage extend to your specific focus areas, industry, or region? No single dataset is universally best - a manufacturer in India has very different needs from a software company in the US.
- Is the vendor legally and compliance-aligned with your jurisdiction? Where the vendor hosts its content and services matters for regulatory and legal reasons.
- Does the platform support collaboration and structured (not just raw) intelligence? The difference between unstructured information and structured intelligence determines how much manual processing your own team has to do.
- How open is the vendor to accepting new data source requests? Intelligence is only as good as what feeds it - a vendor unwilling to expand collection based on your needs will eventually leave gaps.
Read more about what dark web monitoring is.
Understanding Threat Actor TTPs
Tactics, techniques, and procedures (TTPs) describe adversary behavior at three levels of granularity:
- Tactics: the stage of the attack, such as reconnaissance, delivery, or exploitation, mapped to the broader kill chain.
- Techniques: the specific methods used to achieve a tactic, like infiltrating a network, establishing command and control, or moving laterally without detection.
- Procedures: the granular, highly specific actions used to carry out a technique - often documented and reused by the same actor across multiple campaigns.
Why TTPs matter more than static indicators
Because threat actors reuse successful TTPs across different targets and industries, understanding them lets defenders do three things static indicator feeds can't:
- Hunt proactively: TTPs give blue teams a guide for identifying hidden threats and abnormal behavior tied to known attacker methods, rather than waiting for a signature match.
- Respond faster: Recognizing a known TTP mid-incident speeds up detection, containment, and recovery.
- Anticipate the next attack: Because attackers reuse what works, studying TTPs lets organizations close gaps before a known adversary tries the same approach on them.
TTP mapping and the MITRE ATT&CK framework
MITRE ATT&CK is the standardized language the security industry uses to describe adversary behavior across the full attack lifecycle. Mapping observed activity - say, a piece of phishing infrastructure - to a specific ATT&CK technique ID contextualizes the risk in operational terms and lets defenders simulate, prioritize, and mitigate with precision.
For continuous threat exposure management (CTEM) programs specifically, TTP mapping is what turns unstructured threat data into structured intelligence that feeds exposure validation and prioritization - bridging the gap between strategic risk understanding and tactical defense.
Read more about the power of TTP mapping for external cyber risk.
Using Threat Intelligence Against Ransomware
Early detection: Dark web monitoring surfaces the precursors to a ransomware attack: compromised credentials being traded, software vulnerabilities being discussed, and - most valuably - targeted-attack chatter that names specific organizations before an attack ever launches.
Data leak monitoring: Modern ransomware groups favor double extortion: stealing data before encrypting it, then threatening to leak or sell it if the ransom isn't paid. Monitoring ransomware leak sites and dark web marketplaces means an organization can detect a listing - and start incident response, stakeholder notification, and containment - before the leak becomes public.
Incident response support: Once an attack is underway or has occurred, dark web activity offers insight into a specific group's negotiation tactics, typical demands, and how they've handled other victims - intelligence that directly informs whether and how to engage in negotiations, and how to plan post-incident remediation.
Learn how organizations can combat ransomware groups with dark web monitoring
CTI is the process of collecting, analyzing, and applying data about cyber threats, adversaries, and attack methods to strengthen an organization's security posture - shifting security from reactive defense to proactive threat mitigation. It operates at four levels (strategic, tactical, operational, and technical) and runs on a continuous six-phase lifecycle: planning, collection, processing, analysis, dissemination, and feedback.
Dark web monitoring is a specific, critical input into CTI. While threat intelligence draws on internal logs, OSINT, and trusted sharing communities as well, dark web monitoring focuses on the underground forums, marketplaces, and leak sites where threat actors actually plan and coordinate attacks - giving visibility into the earliest, pre-attack stage of the Cyber Kill Chain that other sources typically can't reach.
The deep web is simply everything not indexed by search engines - online banking portals, academic databases, and company intranets are all part of it, and the vast majority of it is entirely legitimate. The dark web is a much smaller subset, accessible only through tools like Tor, deliberately hidden to provide anonymity, and disproportionately associated with illegal marketplaces, hacking forums, and leak sites.
Threat intelligence - and TTP mapping in particular - feeds structured intelligence into proactive threat exposure management (PTEM) by translating unstructured dark web and OSINT data into a standardized framework (like MITRE ATT&CK) that supports exposure validation, risk prioritization, and targeted remediation.
TTPs (tactics, techniques, and procedures) describe how a threat actor operates, from the stage of the attack down to the specific, repeated steps they take. Because indicators like IP addresses and file hashes can be changed in minutes, but a TTP represents an adversary's core strategy, tracking TTPs gives defenders a far more durable way to detect, anticipate, and disrupt an attack.
It depends on the requirement, but for anything time-sensitive - like breached credentials that could enable unauthorized access - data needs to reach the security team on an hourly or daily basis. Any longer, and the probability of malicious activity occurring before the organization can respond increases substantially.





