Threat Intelligence

Concept

脅威インテリジェンス(セキュリティ概念)

最終更新: 2026-07-28

4 References

https://www.refbase.ai/entity/threat-intelligence

Knowledge Dossier

公開済みEvidenceをIdentity / Capability / Credibility / Use Case / Constraints・Current Statusの軸で機械的に集約したものです(新規の主張・推測は含みません)。

Identity

  • NIST公式Glossary(CSRC)は、cyber threat intelligenceを「Cyber threat information that has been aggregated, transformed, analyzed, interpreted, or enriched to provide the necessary context for decision-making processes(意思決定に必要な文脈を提供するために集約・変換・分析・解釈・強化されたサイバー脅威情報)」と定義している(出典: NIST SP 800-61r3 under cyber threat intelligence from NIST SP 800-150)。検証待ち Cyber Threat Intelligence - Glossary | CSRC

Capability

  • NIST公式Glossary(CSRC)によれば、Cyber threat intelligenceはインシデント対応・復旧において、新たな脅威に関する情報の取得、検知・対応機能を持つサイバーセキュリティ技術の精度向上、攻撃者が用いるTTP(Tactics, Techniques, and Procedures)の理解に役立つとされる。検証待ち Cyber Threat Intelligence - Glossary | CSRC

Credibility

公開Evidence未整備

Use Case

  • Google Cloud公式サイト(Mandiant)によれば、Mandiantの専門家は「extensive incident response experience with real-time threat intelligence(豊富なインシデント対応経験とリアルタイムの脅威インテリジェンス)」を組み合わせて侵害の痕跡を発見するとされ、Threat Intelligenceの実装例の一つである。検証待ち Mandiant Cybersecurity Consulting | Google Cloud
  • Recorded Future公式サイトによれば、同社のIntelligence Graph®は「indexes, organizes, and analyzes data from over a million sources(100万以上の情報源からデータをインデックス化・整理・分析する)」ことで「real-time, and unbiased threat intelligence(リアルタイムで偏りのない脅威インテリジェンス)」を提供するとされ、Threat Intelligenceの実装例の一つである。検証待ち Intelligence Platform | Recorded Future

Constraints / Current Status

  • NIST公式Glossary(CSRC)は、threat informationを「Analytical insights into trends, technologies, or tactics of an adversarial nature affecting information systems security(情報システムセキュリティに影響する敵対的な傾向・技術・戦術に関する分析的洞察)」(CNSSI 4009由来)と定義しており、これは未加工の脅威情報であり、集約・分析・文脈化を経たThreat Intelligenceとは区別される段階にある。検証待ち threat information - Glossary | CSRC

Key References

Knowledge Graph

References — 問い別の知識

データアクセス

各APIエンドポイントはJSON形式でデータを返します。生成AIのツール呼び出し・RAG連携での利用を想定しています。