Evidence-based knowledge about existing or emerging threats, used to inform security decisions.
Threat intelligence feeds tell defenders what indicators — IP addresses, file hashes, attack patterns — are currently associated with active threat campaigns, helping prioritize detection and response.