Resources · Guide · MDR · CTI · 4 min read

From MDR to MDIR: intelligence enters the defence lifecycle

In short

MDIR (Managed Detection, Intelligence and Response) is the term Fortgale uses to name the evolution of MDR: cyber threat intelligence integrated into every phase of the defence lifecycle, from detection to response. Knowing the adversary gives weight to every alert, makes response faster and more effective, and allows offensive actions to be anticipated. A service that stops at the alert belongs to the previous generation of defence.

Why intelligence enters the defence lifecycle

The history of detection & response is a steady shift of the centre of gravity: first you detected (EDR), then you correlated (XDR), then human operation 24·7 was added (MDR). The next step is not another technology: it is knowledge of the adversary inside the operational flow. This is what Fortgale calls MDIR, Managed Detection, Intelligence and Response.

The reason lies in how attacks actually work. A cyber attack is not something: it is someone. It has infrastructure, recurring techniques, preferred sectors, a history. Defending without knowing who attacks means treating every alert as an isolated fact, all with the same weight, all verified from zero. With intelligence in the loop, every signal is read against what is known about the adversary: understanding first, action second.

  • 287
    adversary groups and attack tools profiled
  • <15 min
    median TTD · telemetry to alert
  • <30 min
    median TTC · detection to action
  • >90%
    alert noise cut by day 30

What changes with intelligence in the flow

THE MDIR LOOP · INTELLIGENCE DOES NOT ARRIVE DOWNSTREAM: IT CIRCULATES DETECTION INTELLIGENCE RESPONSE every signal, weighted 287 profiles · who they are, how they operate targeted containment anticipated moves 287 ADVERSARY GROUPS AND ATTACK TOOLS APPLIED IN THE TRIAGE OF EVERY ALERT T1078 · known infrastructure
Intelligence circulates in the loop: every alert is read against 287 adversary profiles, and response feeds new TTPs back into them.

The effect is measurable, not abstract. Every alert acquires weight: a valid-account access (T1078) is an ordinary signal until its command infrastructure matches a group targeting your sector; prioritisation moves from generic severity to relevance for your context, which is how alert noise drops by more than 90% within the first month. Response becomes faster and more effective: knowing the adversary means knowing their TTPs, where they will attempt persistence, which accounts they will hunt, how they exfiltrate; containment becomes targeted instead of generic. Offensive actions can be anticipated: an attack follows a kill chain, and recognising the actor at the third move means knowing the fourth and the fifth. Prediction is not an AI promise: it is the product of adversary profiles built on field-observed TTPs, applied by a European SOC team operating since 2017 from Milan, with detection under 15 minutes and containment under 30 as median times.

Intelligence in the flow means understanding, and understanding means valid defence. A service that only talks about alerts, how many it generates and how many it forwards, belongs to the previous generation of defence: the one that handed the customer the work of understanding.

A term we propose, a substance we prove

To be explicit: MDIR is not an industry standard, and the acronym circulates with more than one expansion. Fortgale adopts and defends it in this form, Managed Detection, Intelligence and Response, because it names precisely the evolution we pursue: intelligence as the centre of gravity of the managed service. The acronym is only worth what the I can prove. Ask any provider, Fortgale included, for evidence: how many adversaries profiled and from which sources, how intelligence enters triage and response, which real cases document it. Read more: What is MDR and Cyber Threat Intelligence, where that knowledge is built.


A cyber attack is not something: it is someone. Knowing them, anticipating their moves, stopping them in time: MDIR is the name of that sequence. Knowing the adversary is the first act of defence. Stopping it in time is the second.

Comparison

The centre of gravity shifts: from the alert to understanding the adversary

StageCentre of gravityTypical output
EDRDetect on the endpointAlerts
XDRCorrelate across domainsCorrelated alerts
MDRManage detection and response 24·7Closed incidents
MDIRIntegrate intelligence into every phaseClosed incidents, knowing the adversary
Field-observed proof · intelligence in the loop

In Operation Storming Tide containment, eradication, exfiltration and ransomware prevented: the response was decisive because it was guided by knowledge of the adversary, their TTPs and their infrastructure. That is the intelligence in the operational loop that the term MDIR makes explicit.

Read the analysis →
FAQ

Frequently asked.

What does MDIR mean?

MDIR stands for Managed Detection, Intelligence and Response. It is the term Fortgale uses to name the evolution of the MDR model: cyber threat intelligence not as an accessory feed, but as a structural component of the defence lifecycle. Intelligence exists to understand the attacker and the attack, to respond to the incident in the best way, and to anticipate offensive actions.

What is the difference between MDR and MDIR?

The position of intelligence. In many MDR services CTI is a purchased stream of IOCs that arrives downstream. In the MDIR model intelligence sits inside the operational flow: it enriches detection by giving weight to every alert, it guides response because the analyst knows who they are facing and how they operate, and it feeds prediction of the next moves along the kill chain.

Is MDIR an industry standard?

No, and it is worth being explicit: the acronym circulates with more than one expansion and no third-party body defines it. For Fortgale the I means Intelligence, and that is the direction we pursue. What matters is verifiable beyond the name: 287 adversary groups and attack tools profiled, intelligence applied in the triage of every alert, detection and containment times measured.

Is intelligence not already included in every MDR?

A feed of indicators is not intelligence in the loop. The difference is between receiving a list of IOCs and holding adversary profiles built on field-observed TTPs, kept alive by real incidents and applied in triage, response and prediction. The question to ask any provider: how does intelligence enter your operational decisions, from which sources, with what evidence?

How Fortgale delivers it

From theory to a real operation.

What you read here, Fortgale runs every day with a European SOC 24·7·365: 287 tools and actors profiled, <30 min median containment. Explore the service: Fortgale MDR service.

Related resources: What is MDR · Cyber Threat Intelligence · Incident Response

Want to go deeper with an analyst?

A technical conversation, not a funnel.

Leave your details: an analyst calls you back within one business day. European SOC, same time zone, proprietary intelligence on the actors active across the EU.

Response time: < 1 business day.