---
title: "Intelligence Requirements"
slug: "intelligence-requirements"
description: "This article provides an overview of Intelligence Requirements in ThreatConnect, which are objects defined by logic-based keyword queries that identify and retrieve relevant information in your ThreatConnect owners."
tags: ["Getting Started"]
status: "update"
updated: 2024-07-11T02:23:28Z
published: 2024-07-11T02:23:28Z
canonical: "knowledge.threatconnect.com/intelligence-requirements"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://knowledge.threatconnect.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Intelligence Requirements

## Overview

An Intelligence Requirement (IR) is a collection of topics or a research question reflecting an organization’s cyber threat–related priorities that guides a security or threat intelligence team’s research and analysis efforts. By establishing IRs, analysts can focus on investigating the things that matter most to their organization and stakeholders and spend less time sifting through various data sources for useful information.

In ThreatConnect®, you can create an IR object with a logic-based keyword query that identifies information relevant to the IR. ThreatConnect will query the owners you have access to and the ThreatConnect Global Intelligence Dataset and retrieve Cases, Groups, Indicators, Tags, and Victims that match the query. These results are displayed on the IR’s **Details** screen, providing a central location where you can review the results and take an appropriate course of action for each one: associate the result to the IR object, archive the result, or mark the result as a false result.

ImportantThe ThreatConnect Global Intelligence Dataset, historically known as CAL™, can still be leveraged even if an instance does not have CAL turned on. In this scenario, data returned from the ThreatConnect Global Intelligence Dataset will be read only, and no information stored in your instance will be shared with or collected by CAL.

## In This Series

- [*Best Practices: Intelligence Requirements*](https://knowledge.threatconnect.com/docs/best-practices-intelligence-requirements): Learn about what an IR is, the types and subtypes of IRs, and best practices to take when writing IRs for your organization.
- [*Best Practices: Keywords for Intelligence Requirements*](https://knowledge.threatconnect.com/docs/best-practices-keywords-for-intelligence-requirements): Learn about how the IR keyword query logic works in ThreatConnect and best practices for building your IR keyword queries.
- [*Intelligence Requirement Categories*](https://knowledge.threatconnect.com/docs/intelligence-requirement-categories): Learn how to view, create, and manage IR categories on the **System Settings** screen (System Administrators only).
- [*Creating Intelligence Requirements*](https://knowledge.threatconnect.com/docs/creating-intelligence-requirements): Learn how to create and configure an IR and view its preliminary results.
- [*Viewing Intelligence Requirement Details*](https://knowledge.threatconnect.com/docs/viewing-intelligence-requirement-details): Learn how to view an IR’s **Details** screen, edit its keyword query, and view and manage its results.

---

*ThreatConnect® is a registered trademark, and CAL™ is a trademark, of ThreatConnect, Inc.*

20159-01 v.02.A
