TLP WHITE - FINAL
Element 3: Threat Intelligence
Threat Intelligence is a core phase of the overall TLPT process. Threat intelligence providers use
threat intelligence and reconnaissance focused on the entity to create credible threat profiles
which, mimicking real-life cyber threat actors, are critical to the scoping of testing activities. The
threat profiles contain cyber threat scenarios which help the Red Team develop test plans, used
during the Penetration Testing phase.
Roles and Responsibilities
The threat intelligence provider is typically responsible for: (i) producing threat intelligence
deliverables, aligned to the scope of test, and in accordance with direction provided by the entity;
(ii) justifying the relevance of the threat intelligence deliverables; (iii) disseminating threat
intelligence deliverables to the White Team; and (iv) providing support, as required, to the Red
Team. This includes helping to develop the cyber threat scenarios, as well as fulfilling any new
intelligence needs that occur as the Penetration Testing phase progresses.
The entity should provide: (i) direction to the threat intelligence provider regarding functions or
systems in scope; (ii) additional background information to assist the threat intelligence provider
in the timely and effective development of the threat profiles; and (iii) threat intelligence
deliverables to the penetration testing provider, appropriate stakeholders, and authorities as
needed.
Threat Intelligence Competencies
Effective threat intelligence providers typically demonstrate the following minimum capabilities:
Ability to profile cyber threat actors relevant to the entity, sector and geographical region;
Ability to produce cyber threat scenarios, replicating the methodology of chosen threat
actors;
Utilization of different methodologies and multiple sources and types of intelligence,
such as Open Source Intelligence (OSINT) and industry related Indicators of
Compromise (IoCs), to fully develop an accurate and up-to-date picture of an entity’s
vulnerable attack surfaces, focusing on people, processes and technology; and
Multi-language intelligence collection ability.
Threat Intelligence Deliverables
For each TLPT engagement the threat intelligence provider should produce deliverables that
contain the following types of information:
Threat Intelligence Report (TIR) – The TIR should contain profiles of cyber threat actors
who represent a credible threat to the entity. Where no specific reporting relating to the
entity is available, actors may be selected based on previous known activity within
relevant sectors or regions. Each threat actor profile should contain a cyber threat
scenario that best highlights the methodology and tools utilized by the threat actor. Cyber
threat scenarios should be detailed enough to provide penetration testing providers with
all relevant approaches and information required to formulate effective test plans.
Targeting Report (TR) – The TR should provide a profile of the entity that highlights
vulnerable or exposed attack surfaces relevant to people, processes and technology, in
accordance with the scope. The report should seek to provide the penetration testing
provider with potential threat vectors into the target entity.
TLP WHITE: Subject to standard copyright rules, this document may be distributed freely, without restriction.
5