02. 10. 2026 Lorena Goldoni Blue Team, Detection Engineering, SEC4U

From Threat Intelligence to Detection: Building an Intelligence-Driven Detection Model

Turning relevant campaigns into actionable security content

To prioritize detection rule deployment based on threats that could realistically affect our organization or customer environments, we developed an intelligence-driven detection model.

Rather than prioritizing rules solely by mapping MITRE ATT&CK techniques and addressing coverage gaps indiscriminately, the model uses threat intelligence to identify which campaigns, behaviors, and attack stages deserve detection engineering effort first.

The model combines three complementary paths:

  • Open-source intelligence (OSINT) provides early visibility into new campaigns, malware, infrastructure, and attack techniques. CTI analysts validate and enrich this information before assessing its relevance.
  • SOC investigations provide internally observed evidence that allow CTI analysts to extract the observed kill chain and turn an individual case into reusable campaign intelligence: from a SOC ticket to a MISP event.
  • Threat Profiles help identify campaigns that match the sectors, technologies, and threat scenarios defined for our group or our customers.

SOC alerts that are opened by analysts are also considered as an additional input. After investigation, CTI analysts assess and, where appropriate, integrate the relevant findings into MISP so that threats actively targeting specific environments or sectors are represented in the intelligence workflow.

These three paths converge in the CTI prioritization process, where the selected campaign is structured in MISP and passed to the detection team. CTI acts as a prioritization layer between external reporting, SOC investigations, and detection engineering: instead of forwarding every report or indicator, CTI analysts assess the campaign’s relevance, activity, targeting, observed tactics and techniques, confidence, and potential detectability in the monitored environment.

Extracting the kill chain and creating the MISP event

From a SOC case or an OSINT report, CTI analysts extract only the attack stages supported by evidence, because the goal is not to force a complete attack narrative, but to connect observed indicators and behaviors to the relevant kill-chain stages and identify potential detection points.

The selected campaign is then documented in a MISP event containing the campaign or incident context, source and confidence, relevant dates, observables, relationships, kill-chain phases, supporting analysis, and links to the original source or case. This context enables detection engineers to distinguish between an indicator that is useful for matching or enrichment and a behavior that should be implemented as an analytic rule.

The detection team maps the MISP event to available telemetry and existing coverage. The technical workflow includes reviewing the campaign context, identifying the required data sources, checking existing rules, implementing new detections or tuning current ones, and validating the results against historical data and expected false positives.

Static indicators can support matching, blocking, or enrichment, but they are often short-lived. The more durable detections are based on observed behaviors, such as process relationships, authentication anomalies, network connections, persistence mechanisms, or sequences of related events.

Conclusion

An intelligence-driven detection model connects threat understanding with operational defense. By prioritizing relevant campaigns, combining OSINT with evidence from SOC investigations, extracting the observed kill chain, and representing the results in MISP, the CTI team provides detection engineers with structured intelligence that can be implemented and validated.

The model also establishes a shared operating model across teams:

  • CTI analysts provide context, assessment, and prioritization.
  • SOC analysts contribute evidence from real investigations and monitored environments.
  • Detection engineers translate relevant behaviors into detection coverage and validate its effectiveness.

The objective is not to collect more threat information. It is to make the most relevant information actionable, measurable, and available to the right team at the right time.

These Solutions are Engineered by Humans

Did you learn from this article? Perhaps you’re already familiar with some of the techniques above? If you find cyber security issues interesting, maybe you could start in a cyber security or similar position here at Würth IT Italy.

Lorena Goldoni

Lorena Goldoni

Detection Engineer at Würth IT Italy

Author

Lorena Goldoni

Leave a Reply

Your email address will not be published. Required fields are marked *

Archive