This document is a guide that outlines the framework for an internal threat intelligence program. The objective is to provide timely and actionable intelligence to stakeholders, aiding in decision-making and enhancing the organization's security posture. The playbook details the roles and responsibilities of various stakeholders, the types of threats to be monitored, and the assets involved in the program. It describes processes for planning, collection, analysis, and dissemination of intelligence. Specific methodologies for identifying priority intelligence requirements (PIR) and collection methods are included, emphasizing the importance of automated collection and collaboration with threat intelligence services. The governance section addresses product quality measurement and metrics, while communication protocols for escalation are also defined. Additionally, the playbook includes standard operating procedures (SOPs) and a glossary of terms relevant to the threat intelligence domain.