Back to Resources
Threat Intelligence Report Template: visual preview
Template

Threat Intelligence Report Template

CTI Reporting & Actionable Threat Indicators

Overview

Threat intelligence only has value when it leads to action. A well-structured intelligence report translates raw threat data into decisions: which detection rules to deploy, which vulnerabilities to prioritize, which attack scenarios to prepare for. This template helps you produce consistent, actionable threat intelligence reports that your SOC, leadership, and partner teams can actually use, not just read and file away.

Report Sections

  • Executive summary: key findings and recommended actions in plain language
  • Threat actor profile: attribution, motivation, known campaigns, and target sectors
  • Tactics, techniques, and procedures (TTPs): MITRE ATT&CK mapping
  • Indicators of compromise: IPs, domains, hashes, URLs, email addresses
  • Attack chain analysis: step-by-step reconstruction of the threat activity
  • Detection and mitigation recommendations: specific controls and rules
  • Intelligence gaps: what we do not know and what we need to investigate further
  • Confidence assessment: reliability of sources and analytical confidence level

Intelligence Classification

LevelAudienceContent focusUpdate frequency
StrategicCISO, Board, ExecutivesThreat landscape trends, risk to business objectives, industry targetingQuarterly
OperationalSOC Manager, IR LeadCampaign details, threat actor profiles, attack patternsMonthly or per campaign
TacticalSOC Analysts, Detection EngineersIOCs, detection rules, hunt queries, signaturesWeekly or real-time
TechnicalMalware Analysts, ForensicsMalware samples, exploit code, infrastructure analysisPer investigation

Writing for Different Audiences

The same threat information needs to be packaged differently depending on who is reading it. The CISO wants to know how this threat affects business risk and what investment is needed. The SOC manager wants to know which detection gaps to close and whether the team needs additional resources. The analyst wants IOCs they can load into their tools in the next five minutes. Write each section for its audience. Lead the executive summary with business impact, not technical details. Include IOCs in a machine-readable format alongside the narrative.

Confidence and Source Assessment

Rate the confidence of each finding using a standard framework like the Admiralty system or a simple High/Medium/Low scale. A high-confidence finding is based on multiple independent, reliable sources. A low-confidence finding may be based on a single unverified report or speculative analysis. Document your sources without compromising sensitive collection methods. Be transparent about what you know versus what you assess. Intelligence consumers make better decisions when they understand the reliability of the information they are acting on.

Operationalizing Intelligence

  • Convert IOCs into SIEM detection rules and EDR watchlists within hours of report publication
  • Map TTPs to MITRE ATT&CK and identify gaps in your defensive coverage
  • Brief the SOC team during shift handovers on active threats from the latest reports
  • Feed intelligence into threat hunting hypotheses for proactive investigation
  • Share anonymized findings with your ISAC and trusted peers for collective defense
  • Track whether intelligence-driven actions prevented or detected actual threats

Frequently asked questions