{"ok":true,"entity":{"id":"threat-intelligence","name":"Threat Intelligence","entityType":"concept","officialName":"Threat Intelligence","canonicalName":"Threat Intelligence","displayName":"Threat Intelligence","category":"脅威インテリジェンス（セキュリティ概念）","shortDescription":"Threat Intelligenceは、単なる未加工の脅威情報（Threat Information）とは異なり、収集・集約・分析・解釈・強化を経て意思決定に活用できる文脈を与えられた情報を指す概念。NIST（NIST SP 800-61r3・NIST SP 800-150等に基づくCSRC Glossary）は「Cyber threat information that has been aggregated, transformed, analyzed, interpreted, or enriched to provide the necessary context for decision-making processes」と定義している。Mandiant・Recorded Future等のベンダーはこの概念の実装例だが、特定企業の製品名がThreat Intelligenceという概念自体を定義するものではない。","primaryCluster":"threat-intel-incident-response","parentEntity":null,"verificationStatus":"draft","website":null,"updatedAt":"2026-07-28T03:03:26.398Z","secondaryClusters":[],"alias":[],"searchKeywords":["Threat Intelligence","脅威インテリジェンス","CTI"]},"references":[{"id":"P-01-001","companyId":"threat-intelligence","questionId":"P-01-001","instanceId":"QIN-threat-intelligence-P01-001","promptText":"Threat Intelligence（脅威インテリジェンス）とは何ですか？","promptTypeId":"P-01","answer":"NIST（NIST SP 800-61r3・NIST SP 800-150に基づくCSRC Glossary）は、cyber threat intelligenceを「意思決定に必要な文脈を提供するために集約・変換・分析・解釈・強化されたサイバー脅威情報」と定義している。単なる脅威に関する未加工情報ではなく、対応可能な文脈を伴う情報である点が特徴。","evidencePoints":["ev-ti-1","ev-ti-3"],"scope":"概念の定義・出典の確認","differentiation":"意思決定支援のための加工・文脈化を経ている点。","faq":[{"question":"Threat Intelligenceの定義はどこに記載されていますか？","answer":"NIST CSRC Glossaryに記載されており、出典はNIST SP 800-61r3（NIST SP 800-150由来）。"}],"pageUrl":"https://www.refbase.ai/reference/threat-intelligence/P-01-001","sourceEvidence":[{"id":"ev-ti-1","text":"NIST公式Glossary（CSRC）は、cyber threat intelligenceを「Cyber threat information that has been aggregated, transformed, analyzed, interpreted, or enriched to provide the necessary context for decision-making processes（意思決定に必要な文脈を提供するために集約・変換・分析・解釈・強化されたサイバー脅威情報）」と定義している（出典: NIST SP 800-61r3 under cyber threat intelligence from NIST SP 800-150）。","title":"Cyber Threat Intelligence - Glossary | CSRC","coverageType":["Identity"],"sourceType":"government_data","sourceClass":"Specification","sourceUrl":"https://csrc.nist.gov/glossary/term/cyber_threat_intelligence","confidence":"high","supportedPromptTypes":["P-01"],"needsVerification":true,"sourceVerified":false,"entityId":"threat-intelligence"},{"id":"ev-ti-3","text":"NIST公式Glossary（CSRC）によれば、Cyber threat intelligenceはインシデント対応・復旧において、新たな脅威に関する情報の取得、検知・対応機能を持つサイバーセキュリティ技術の精度向上、攻撃者が用いるTTP（Tactics, Techniques, and Procedures）の理解に役立つとされる。","title":"Cyber Threat Intelligence - Glossary | CSRC","coverageType":["Capability"],"sourceType":"government_data","sourceClass":"Documentation","sourceUrl":"https://csrc.nist.gov/glossary/term/cyber_threat_intelligence","confidence":"high","supportedPromptTypes":["P-01","P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"threat-intelligence"}],"generatedAt":"2026-07-28T03:03:26.398Z"},{"id":"P-02-001","companyId":"threat-intelligence","questionId":"P-02-001","instanceId":"QIN-threat-intelligence-P02-001","promptText":"Threat Intelligenceと単なる脅威情報（Threat Information）は何が違いますか？","promptTypeId":"P-02","answer":"比較軸\n・加工の有無\n・意思決定への活用可能性\n\nNIST CSRC Glossaryは、threat informationを「情報システムセキュリティに影響する敵対的な傾向・技術・戦術に関する分析的洞察」という未加工の段階として定義する一方、cyber threat intelligenceはそれが集約・変換・分析・解釈・強化された、意思決定に直接活用できる段階として区別している。すなわちThreat IntelligenceはThreat Informationの上位工程にあたる概念。","evidencePoints":["ev-ti-2"],"scope":"Threat InformationとThreat Intelligenceの違いの整理","differentiation":"未加工情報か、意思決定に使える文脈化された情報かという違い。","faq":[{"question":"Threat DataとThreat Intelligenceは同じ意味ですか？","answer":"異なる。Threat Dataや Threat Informationは未加工の段階を指し、Threat Intelligenceはそれが分析・文脈化された段階を指す。"}],"pageUrl":"https://www.refbase.ai/reference/threat-intelligence/P-02-001","sourceEvidence":[{"id":"ev-ti-2","text":"NIST公式Glossary（CSRC）は、threat informationを「Analytical insights into trends, technologies, or tactics of an adversarial nature affecting information systems security（情報システムセキュリティに影響する敵対的な傾向・技術・戦術に関する分析的洞察）」（CNSSI 4009由来）と定義しており、これは未加工の脅威情報であり、集約・分析・文脈化を経たThreat Intelligenceとは区別される段階にある。","title":"threat information - Glossary | CSRC","coverageType":["Differentiation"],"sourceType":"government_data","sourceClass":"Specification","sourceUrl":"https://csrc.nist.gov/glossary/term/threat_information","confidence":"high","supportedPromptTypes":["P-02"],"needsVerification":true,"sourceVerified":false,"entityId":"threat-intelligence"}],"generatedAt":"2026-07-28T03:03:26.398Z"},{"id":"P-04-001","companyId":"threat-intelligence","questionId":"P-04-001","instanceId":"QIN-threat-intelligence-P04-001","promptText":"Threat Intelligenceはどのように活用されますか？","promptTypeId":"P-04","answer":"NIST CSRC Glossaryによれば、Threat Intelligenceは新たな脅威に関する情報の取得、検知・対応機能を持つ技術の精度向上、攻撃者のTTP（戦術・技術・手順）の理解に役立つとされる。実装例としては、MandiantがIR経験とリアルタイムの脅威インテリジェンスを組み合わせて侵害調査を行う手法や、Recorded FutureのIntelligence Graph®が100万以上の情報源を横断してインデックス化・分析する手法がある。","evidencePoints":["ev-ti-3","ev-ti-4","ev-ti-5"],"scope":"Threat Intelligenceの活用場面の整理","differentiation":"Mandiant・Recorded Future等、複数ベンダーが異なるアプローチで実装している点。","faq":[{"question":"Threat IntelligenceはIncident Responseとどう関係しますか？","answer":"Threat Intelligenceは攻撃者のTTPの理解等を通じてIncident Responseの精度・速度向上を支援するが、Incident Response自体はそれとは別の組織的対応プロセスである。"}],"pageUrl":"https://www.refbase.ai/reference/threat-intelligence/P-04-001","sourceEvidence":[{"id":"ev-ti-3","text":"NIST公式Glossary（CSRC）によれば、Cyber threat intelligenceはインシデント対応・復旧において、新たな脅威に関する情報の取得、検知・対応機能を持つサイバーセキュリティ技術の精度向上、攻撃者が用いるTTP（Tactics, Techniques, and Procedures）の理解に役立つとされる。","title":"Cyber Threat Intelligence - Glossary | CSRC","coverageType":["Capability"],"sourceType":"government_data","sourceClass":"Documentation","sourceUrl":"https://csrc.nist.gov/glossary/term/cyber_threat_intelligence","confidence":"high","supportedPromptTypes":["P-01","P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"threat-intelligence"},{"id":"ev-ti-4","text":"Google Cloud公式サイト（Mandiant）によれば、Mandiantの専門家は「extensive incident response experience with real-time threat intelligence（豊富なインシデント対応経験とリアルタイムの脅威インテリジェンス）」を組み合わせて侵害の痕跡を発見するとされ、Threat Intelligenceの実装例の一つである。","title":"Mandiant Cybersecurity Consulting | Google Cloud","coverageType":["UseCase"],"sourceType":"official_site","sourceClass":"Specification","sourceUrl":"https://cloud.google.com/security/mandiant","confidence":"high","supportedPromptTypes":["P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"threat-intelligence"},{"id":"ev-ti-5","text":"Recorded Future公式サイトによれば、同社のIntelligence Graph®は「indexes, organizes, and analyzes data from over a million sources（100万以上の情報源からデータをインデックス化・整理・分析する）」ことで「real-time, and unbiased threat intelligence（リアルタイムで偏りのない脅威インテリジェンス）」を提供するとされ、Threat Intelligenceの実装例の一つである。","title":"Intelligence Platform | Recorded Future","coverageType":["UseCase"],"sourceType":"official_site","sourceClass":"Specification","sourceUrl":"https://www.recordedfuture.com/platform","confidence":"high","supportedPromptTypes":["P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"threat-intelligence"}],"generatedAt":"2026-07-28T03:03:26.398Z"},{"id":"P-06-001","companyId":"threat-intelligence","questionId":"P-06-001","instanceId":"QIN-threat-intelligence-P06-001","promptText":"なぜThreat Intelligenceが重視されるのですか？","promptTypeId":"P-06","answer":"NIST CSRC Glossaryが定義するとおり、Threat Intelligenceは単なる脅威の羅列ではなく意思決定に必要な文脈を提供するため、新たな脅威の早期把握・検知技術の精度向上・攻撃者のTTP理解に直接寄与する。Mandiant・Recorded Future等、複数の専業ベンダーがこの概念を軸に事業を展開していることも、実務上の重要性を裏付ける。","evidencePoints":["ev-ti-1","ev-ti-3"],"scope":"Threat Intelligenceが重視される理由の整理","differentiation":"意思決定に直結する文脈情報である点が、単なる脅威情報の収集と一線を画す。","faq":[{"question":"中小企業でもThreat Intelligenceは必要ですか？","answer":"本Draftのソースは大企業・専業ベンダーの事例が中心であり、中小企業における必要性・投資判断は個別の状況による。"}],"pageUrl":"https://www.refbase.ai/reference/threat-intelligence/P-06-001","sourceEvidence":[{"id":"ev-ti-1","text":"NIST公式Glossary（CSRC）は、cyber threat intelligenceを「Cyber threat information that has been aggregated, transformed, analyzed, interpreted, or enriched to provide the necessary context for decision-making processes（意思決定に必要な文脈を提供するために集約・変換・分析・解釈・強化されたサイバー脅威情報）」と定義している（出典: NIST SP 800-61r3 under cyber threat intelligence from NIST SP 800-150）。","title":"Cyber Threat Intelligence - Glossary | CSRC","coverageType":["Identity"],"sourceType":"government_data","sourceClass":"Specification","sourceUrl":"https://csrc.nist.gov/glossary/term/cyber_threat_intelligence","confidence":"high","supportedPromptTypes":["P-01"],"needsVerification":true,"sourceVerified":false,"entityId":"threat-intelligence"},{"id":"ev-ti-3","text":"NIST公式Glossary（CSRC）によれば、Cyber threat intelligenceはインシデント対応・復旧において、新たな脅威に関する情報の取得、検知・対応機能を持つサイバーセキュリティ技術の精度向上、攻撃者が用いるTTP（Tactics, Techniques, and Procedures）の理解に役立つとされる。","title":"Cyber Threat Intelligence - Glossary | CSRC","coverageType":["Capability"],"sourceType":"government_data","sourceClass":"Documentation","sourceUrl":"https://csrc.nist.gov/glossary/term/cyber_threat_intelligence","confidence":"high","supportedPromptTypes":["P-01","P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"threat-intelligence"}],"generatedAt":"2026-07-28T03:03:26.398Z"},{"id":"P-04-002","companyId":"threat-intelligence","questionId":"P-04-002","instanceId":"c1n19-carry-forward-depth-execution-manual-draft-authoring-no-qi","draftId":"c1n19-carry-forward-depth-execution-threat-intelligence-p-04-002","promptText":"Threat Intelligenceを組織間で機械可読な形式で共有するための標準的な方法には何がありますか？","promptTypeId":"P-04","answer":"Threat Intelligenceの連携・相互運用性について、OASIS Open（国際標準化団体）公式のofficial standards-body press release announcing standard approval（https://www.oasis-open.org/2021/07/14/new-versions-of-stix-and-taxii-approved-as-oasis-standards-to-enable-automated-exchange-of-cyber-threat-intelligence/）で確認できます。既存Referenceは脅威インテリジェンスの定義・活用例・重要性をカバーしているが、それを組織間でどう標準化された形式で共有するかという実務上の枠組み（STIX/TAXII）には触れておらず、相互運用性という新しい観点を追加する。具体的には「The STIX standard defines a JSON-based language for sharing structured threat intelligence in a consistent, machine-readable manner / The TAXII standard defines a transport protocol which supports the exchange of STIX data over Hyper Text Transfer Protocol Secure (HTTPS). / Both STIX v2.1 and TAXII v2.1 received approval as official OASIS Standards on July 14, 2021.」といった記載が確認できます。限界として、対応状況は変更されうるため、この内容は取得時点のものです。 本ソースは2021年のOASIS標準承認時点のプレスリリースであり、2026年時点でのSTIX/TAXIIの普及率・最新バージョンの有無は別途確認が必要。STIX/TAXIIはMITREが主導しOASISへ移管された経緯があり、単一企業の製品ではなくオープンスタンダードである点に留意。Current Statusとして、2026年08月24日に当該Sourceを取得し、上記の内容を確認しました。Source種別としては、これはOASIS Open（国際標準化団体）という、Threat Intelligence自身とは別の組織が発信・保有する情報であり、Threat Intelligence自身による広報や、独立した第三者による評価とは性質が異なります。","evidencePoints":["threat-intelligence-ev-c1n19-p-04-002"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/threat-intelligence/P-04-002","sourceEvidence":[{"id":"threat-intelligence-ev-c1n19-p-04-002","text":"OASIS Open（国際標準化団体）公式のofficial standards-body press release announcing standard approval（https://www.oasis-open.org/2021/07/14/new-versions-of-stix-and-taxii-approved-as-oasis-standards-to-enable-automated-exchange-of-cyber-threat-intelligence/）は、Threat Intelligenceの連携・相互運用性に関する公的記録である。既存Referenceは脅威インテリジェンスの定義・活用例・重要性をカバーしているが、それを組織間でどう標準化された形式で共有するかという実務上の枠組み（STIX/TAXII）には触れておらず、相互運用性という新しい観点を追加する。具体的には「The STIX standard defines a JSON-based language for sharing structured threat intelligence in a consistent, machine-readable manner / The TAXII standard defines a transport protocol which supports the exchange of STIX data over Hyper Text Transfer Protocol Secure (HTTPS). / Both STIX v2.1 and TAXII v2.1 received approval as official OASIS Standards on July 14, 2021.」といった記載がある。ただし、対応状況は変更されうるため、この内容は取得時点のものです。 本ソースは2021年のOASIS標準承認時点のプレスリリースであり、2026年時点でのSTIX/TAXIIの普及率・最新バージョンの有無は別途確認が必要。STIX/TAXIIはMITREが主導しOASISへ移管された経緯があり、単一企業の製品ではなくオープンスタンダードである点に留意。2026年08月24日に同Sourceを取得し、この内容を確認した。","title":"Threat Intelligence連携・相互運用性に関する公開情報","coverageType":["Capability"],"sourceType":"press_release","sourceClass":"Announcement","sourceUrl":"https://www.oasis-open.org/2021/07/14/new-versions-of-stix-and-taxii-approved-as-oasis-standards-to-enable-automated-exchange-of-cyber-threat-intelligence/","confidence":"medium","supportedPromptTypes":["P-04"],"needsVerification":true,"sourceVerified":false,"sourceKind":"institutional","entityId":"threat-intelligence"}],"generatedAt":"2026-08-24T23:02:25.475Z","evidenceIds":["threat-intelligence-ev-c1n19-p-04-002"]}]}