This is a div block with a Webflow interaction that will be triggered when the heading is in the view.

Look Left
Like new visitors to London, security leaders are learning to look to the left of the traditional kill chain. But questions remain. Where does pre-attack intelligence actually sit relative to the tools already in place? What does it replace? What does it complement?
This guide compares four established categories - traditional threat intelligence feeds, dark web monitoring, digital risk protection, and SIEM/SOC tooling - against pre-attack intelligence across a shared set of criteria: what each category sees, when it sees it, what action it enables, and where it falls short.
Key findings
- All four established categories - TI feeds, dark web monitoring, DRP, and SIEM/SOC tooling - map to Detect and Respond in NIST CSF; pre-attack intelligence maps to Identify and Protect.
- Anthropic research covering 832 banned accounts and 13,873 attack technique observations over 12 months found Resource Development (MITRE ATT&CK TA0042) dominates the risk leaderboard, with T1583, T1587, and T1588 among the top five highest-risk techniques.
- 69% of actors in the dataset used AI for Develop Capabilities (T1587), the single most common parent technique, and 57.9% used AI to acquire infrastructure such as domains, VPS, and servers.
- Every IOC in a traditional feed exists because a compromise already happened; pre-attack intelligence reads similar data types at the opposite end of the timeline, flagging assets while they are being assembled.
- Government seizures have driven sophisticated actors off crawlable dark web forums; the signals that lead to concrete defensive action now often live on the open internet, in pre-attack prevention territory.
- Pre-attack intelligence does not replace the stack. It extends the timeline the stack can see, routing validated IoPAs into existing SIEM detection rules and SOAR playbooks.
What is inside
- The Stack You Inherited
- The Comparison Matrix
- Traditional Threat Intelligence Feeds
- Dark Web Monitoring
- Digital Risk Protection and Brand Monitoring
- SIEM/SOC Tooling
- How These Layers Work Together
- Decision Framework: Where to Invest First
- Look Left
Frequently asked questions
What is Pre-Attack Intelligence?
Pre-Attack Intelligence is the discipline of observing, validating, and acting on adversary preparation before execution. It focuses on infrastructure and capabilities developed during MITRE ATT&CK TA0042, Resource Development.
How is Pre-Attack Intelligence different from traditional threat intelligence feeds?
Traditional TI feeds deliver IOCs from compromises that already happened, making them retrospective by design. Pre-Attack Intelligence reads similar data at the opposite end of the timeline, flagging malicious infrastructure while it is being assembled.
How is Pre-Attack Intelligence different from dark web monitoring?
Dark web monitoring captures what actors say they plan to do. Pre-Attack Intelligence captures what they are already building, through concrete signals such as domain registrations, certificate issuance, hosting configurations, and DNS activity.
How is Pre-Attack Intelligence different from Digital Risk Protection?
DRP detects impersonation after the fraudulent asset is live and reachable. Pre-Attack Intelligence works earlier in the timeline - when the domain is registered, the certificate is issued, and the hosting is configured - enabling takedown before any customer or employee is exposed.
Does Pre-Attack Intelligence replace my existing security stack?
No. Each category sits at a different point on the attack timeline, and detection and response tools remain necessary for threats that reach execution. Pre-Attack Intelligence extends coverage to the left, into the days or weeks when attacker infrastructure is being assembled.
What is an IoPA?
An IoPA, Indicator of Pre-Attack, is a validated signal that adversary infrastructure is being prepared before use. Validated IoPAs flow downstream into the tools already in place, improving SIEM detection rules, TI platforms, and SOAR playbooks.









