Join our Newsletter — 33% off our NHI Course

Intent Detection

Intent detection is the practice of identifying what an actor is trying to achieve by analysing behaviour rather than only inspecting visible indicators. In this context, it helps security teams distinguish legitimate-looking email from messages that are trying to alter a workflow, divert funds, or exploit trust.

What Intent Detection Actually Means

Intent detection is about interpreting behaviour, context, and sequence, not just individual artefacts. The goal is to infer what an actor is trying to accomplish so defenders can distinguish routine-looking activity from behaviour that is steering a workflow toward fraud, misuse, or trust abuse.

This makes the term broader than simple content classification. A message, request, or action can appear ordinary on the surface while still belonging to a harmful campaign when it is evaluated alongside timing, relationships, and the business process it is trying to influence.

Where Intent Detection Fits in Security Operations

In practice, intent detection sits between raw signal collection and response decisions. It helps teams move from “what was seen” to “what the actor is attempting,” which is useful when the same technical artefact can support benign automation, social engineering, or account abuse.

The concept is especially valuable in environments where attackers hide behind legitimate channels. A well-formed email, approved workflow, or normal-looking API call may still be suspicious if the surrounding pattern suggests diversion, impersonation, or pressure toward an unauthorised outcome.

That is why intent detection is usually an analytical layer rather than a single control. It draws on behavioural baselines, user or entity context, and process knowledge to decide whether a sequence is consistent with ordinary operations or with adversarial manipulation.

Signals, Context, and Common Failure Modes

Intent detection depends on context richness. The same signal can mean very different things depending on who sent it, when it arrived, what systems it touched, and whether the requested action aligns with normal business flow.

Common failure modes include overreliance on surface indicators, brittle rules that miss novel abuse, and alerting that treats isolated events as decisive. When defenders cannot connect the request to a broader behavioural pattern, legitimate-looking steps can slip through until the final harmful action is attempted.

For this reason, intent detection is usually strongest when it is combined with behavioural analytics and control points that compare request patterns against established baselines. MITRE D3FEND is useful here because it frames defensive methods for reasoning about adversary behaviour, not just single events.

Why Intent Detection Matters for Trust Decisions

Intent detection matters wherever trust is granted on the basis of appearance alone. If a message or action can persuade a person or system to approve a payment, change an account, expose data, or follow a new workflow, the security problem is often the actor’s objective rather than the visible content.

That is why the term shows up in anti-fraud, phishing, and workflow-abuse discussions. It helps answer whether a request is merely unusual or whether it is part of a directed attempt to manipulate decision-making and exploit organisational trust.

Teams that work on detection engineering and incident response often use this kind of reasoning to prioritise suspicious behaviour patterns over one-off indicators. Practitioner-oriented detection references such as SANS Security Resources can help ground that analysis in operational practice.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK provides the primary governance reference for this term.

Framework Control / Reference Relevance
MITRE ATT&CK T1566 — Phishing Intent detection is used to infer deceptive objectives behind socially engineered messages.
T1190 — Exploit Public-Facing Application Behavioural intent analysis can help distinguish normal requests from malicious attempts to drive exploitation.
T1071 — Application Layer Protocol Intent detection often evaluates whether ordinary-looking traffic is being used to hide malicious communication.
Recommendation — Map suspicious message patterns to phishing techniques and validate whether the request is steering a harmful action. Correlate abnormal request sequences with exploitation attempts and escalate when the objective is system abuse. Inspect protocol behaviour for patterns that indicate covert or abusive use rather than routine business activity.