Threat intelligence is used to enrich security investigations, inform detection rules, and prioritize vulnerabilities. Sources range from commercial intelligence feeds to open-source repositories and government advisories. In SOC operations, CTI helps analysts quickly determine whether an observable is associated with known malicious activity, and provides context about attacker motivations and capabilities that informs response decisions.