Cyber Security · PPL

Threat Intelligence Analyst Certification

An advanced program focused on collecting, analyzing, and interpreting cyber threat intelligence to identify threats and support informed security decisions.

  • 4 DaysDuration
  • PPLAccredited
  • 3 LanguagesArabic · English · Hindi
  • ₹14,999.00 Per delegate

This course is accredited by PPL

This is for all ppl accredited courses
2M+ Delegates trained worldwide
15,000+ Corporate clients
490+ Training locations
4.8 ★ Average learner rating
20% OFF Limited-time launch offer
— The journey

Course Outline

What the programme covers, module by module.

Module 1: Introduction to Cyber Threat Intelligence

  • Threat intelligence fundamentals
  • Cyber threat landscape
  • Intelligence terminology
  • Intelligence objectives
  • Intelligence consumers
  • Intelligence-driven security

Module 2: Threat Intelligence Lifecycle

  • Planning and direction
  • Collection
  • Processing
  • Analysis
  • Dissemination
  • Feedback and improvement

Module 3: Types of Threat Intelligence

  • Strategic intelligence
  • Tactical intelligence
  • Operational intelligence
  • Technical intelligence
  • Intelligence use cases
  • Audience requirements

Module 4: Understanding Cyber Threats

  • Threat actors
  • Attack motivations
  • Attack surfaces
  • Threat vectors
  • Cyber campaigns
  • Emerging threats

Module 5: Threat Actor Profiling

  • Threat actor categories
  • Motivations and objectives
  • Capabilities
  • Behavioral patterns
  • Infrastructure analysis
  • Actor tracking

Module 6: Intelligence Requirements

  • Intelligence priorities
  • Stakeholder requirements
  • Priority Intelligence Requirements
  • Collection requirements
  • Information gaps
  • Intelligence planning

Module 7: Threat Intelligence Collection

  • Collection strategies
  • Internal sources
  • External sources
  • Security telemetry
  • Threat feeds
  • Source evaluation

Module 8: Open-Source Intelligence

  • OSINT fundamentals
  • Public information sources
  • Search methodologies
  • Domain intelligence
  • Infrastructure research
  • Source validation

Module 9: Indicators of Compromise

  • IOC fundamentals
  • IP addresses
  • Domains
  • URLs
  • File hashes
  • Indicator enrichment

Module 10: Indicators of Attack

  • Behavioral indicators
  • Attack patterns
  • Suspicious activities
  • Detection opportunities
  • Contextual analysis
  • Threat validation

Module 11: MITRE ATT&CK Framework

  • ATT&CK fundamentals
  • Tactics
  • Techniques
  • Sub-techniques
  • Threat mapping
  • Defensive applications

Module 12: Cyber Kill Chain

  • Reconnaissance
  • Weaponization
  • Delivery
  • Exploitation
  • Installation
  • Command and control

Module 13: Diamond Model of Intrusion Analysis

  • Adversary
  • Capability
  • Infrastructure
  • Victim
  • Event relationships
  • Analytical applications

Module 14: Threat Data Analysis

  • Data normalization
  • Data enrichment
  • Correlation
  • Pattern identification
  • Context development
  • Analytical conclusions

Module 15: Malware Intelligence

  • Malware categories
  • Malware behaviors
  • File indicators
  • Network indicators
  • Malware campaigns
  • Intelligence extraction

Module 16: Network Threat Intelligence

  • Network indicators
  • DNS intelligence
  • IP reputation
  • Traffic patterns
  • Infrastructure relationships
  • Network threat analysis

Module 17: Vulnerability Intelligence

  • Vulnerability information
  • Threat context
  • Exploitation trends
  • Exposure analysis
  • Risk prioritization
  • Remediation intelligence

Module 18: Threat Intelligence Platforms

  • Platform concepts
  • Intelligence repositories
  • Data ingestion
  • Indicator management
  • Enrichment
  • Intelligence sharing

Module 19: Structured Threat Information

  • STIX concepts
  • TAXII concepts
  • Structured intelligence
  • Indicator relationships
  • Intelligence exchange
  • Automation concepts

Module 20: Threat Hunting with Intelligence

  • Threat hunting fundamentals
  • Intelligence-driven hypotheses
  • IOC hunting
  • Behavioral hunting
  • Data analysis
  • Hunting outcomes

Module 21: SIEM & Threat Intelligence

  • SIEM integration
  • Indicator matching
  • Alert enrichment
  • Event correlation
  • Detection enhancement
  • Investigation support

Module 22: Incident Response Intelligence

  • Incident intelligence
  • Threat context
  • Indicator enrichment
  • Campaign relationships
  • Response prioritization
  • Lessons learned

Module 23: Threat Attribution Concepts

  • Attribution fundamentals
  • Evidence evaluation
  • Infrastructure relationships
  • Behavioral similarities
  • Confidence levels
  • Analytical limitations

Module 24: Intelligence Analysis Techniques

  • Hypothesis development
  • Pattern analysis
  • Timeline analysis
  • Link analysis
  • Competing hypotheses
  • Analytical reasoning

Module 25: Intelligence Automation

  • Automated collection
  • Data enrichment
  • Indicator processing
  • API integration concepts
  • Workflow automation
  • Analyst efficiency

Module 26: Threat Intelligence Reporting

  • Intelligence reports
  • Executive summaries
  • Technical reports
  • Threat briefings
  • Visualization
  • Actionable recommendations

Module 27: Intelligence Quality & Confidence

  • Source reliability
  • Information credibility
  • Confidence assessments
  • Bias awareness
  • Analytical accuracy
  • Quality assurance

Module 28: Intelligence-Driven Security Operations

  • SOC integration
  • Detection engineering
  • Vulnerability management
  • Incident response
  • Security prioritization
  • Defensive improvements

Module 29: Practical Threat Intelligence Analysis

  • Intelligence requirement
  • Data collection
  • Indicator analysis
  • Threat mapping
  • Intelligence assessment
  • Stakeholder reporting

Module 30: Advanced Threat Intelligence Practices

  • Emerging threat trends
  • Intelligence program maturity
  • Cross-team collaboration
  • Advanced analytics
  • AI-assisted intelligence
  • Continuous improvement
— 01.2 · Is it right for you?

Who it's for & what's included

Pick a delivery method to see exactly who it suits and everything you receive.

Who it's for

Classroom

Best for learners who want face-to-face tuition and to network with peers in person.

What's included

Everything you get

  • Live instructor on-site
  • Printed workbook & materials
  • Group exercises & case studies
Who it's for

Online Instructor-Led

Best for learners who want a live instructor and a fixed schedule, without the travel.

What's included

Everything you get

  • Live instructor via video call
  • Digital workbook & resources
  • Session recordings
Who it's for

Self-Paced

Best for self-motivated learners who need maximum flexibility around work and life.

What's included

Everything you get

  • On-demand video lessons
  • Interactive quizzes
  • 24/7 access on any device
— What you will master

Course Objectives

01

Understand the cyber threat intelligence lifecycle and major intelligence categories.

02

Collect and evaluate threat information from internal, external, and open-source sources.

03

Analyze indicators of compromise, threat behaviors, actors, campaigns, and infrastructure.

04

Apply MITRE ATT&CK and other analytical models to threat intelligence activities.

05

Integrate threat intelligence with SOC, SIEM, incident response, and threat-hunting workflows.

06

Evaluate intelligence sources and communicate analytical confidence appropriately.

07

Develop actionable technical and strategic threat intelligence reports.

08

Apply advanced analytical techniques to support intelligence-driven cybersecurity decisions.

— Your learning path

Where this fits in your Cyber Security journey

Click any stage to open its detail page. You are at Threat Intelligence Analyst Certification.

Start Build Advanced Mastery
— Questions answered

Frequently Asked Questions

What does a Threat Intelligence Analyst do?
A Threat Intelligence Analyst collects and analyzes information about cyber threats, threat actors, attack techniques, vulnerabilities, and campaigns to support organizational security decisions.
Who should attend this course?
This course is suitable for threat intelligence analysts, SOC analysts, cybersecurity analysts, incident response professionals, and security operations professionals.
What prior knowledge is recommended?
A good understanding of cybersecurity, networking, security monitoring, and common cyber threats is recommended for this advanced program.
What frameworks and technologies are covered?
The course covers MITRE ATT&CK, Cyber Kill Chain, Diamond Model, STIX, TAXII, SIEM integration, threat intelligence platforms, OSINT, and intelligence analysis techniques.
What practical skills will I develop?
You will develop skills in intelligence collection, OSINT, IOC analysis, threat actor profiling, threat hunting, intelligence enrichment, analytical reasoning, and professional threat reporting.
— Trusted by learners

What our delegates say

★★★★★

"The structure, the practice exams, the instructor — all top tier. Passed first try."

AS
Aarti SharmaSenior Project Manager · TCS
★★★★★

"Best training I have attended. The content is exactly what modern projects need."

JD
James DonovanProgramme Director · Capgemini
★★★★★

"24/7 support actually means 24/7 — got help on my mock exam at 2am. Worth every dollar."

MO
Maya OkaforPMO Lead · Standard Bank

★ 4.8 / 5 from 12,000+ verified learner reviews on Trustpilot & Google.

PPL Academy enquiry form

Get the course
that's right for you.

Our advisors respond within one business day.

Full name
Work email
Contact number
Message (optional)
Your details are never shared with third parties.
< 24h Response
Live & online Delivery
Certified Instructors