"The structure, the practice exams, the instructor — all top tier. Passed first try."
Course Outline
What the programme covers, module by module.
Module 1: Introduction to Cyber Threat Intelligence
- Threat intelligence fundamentals
- Cyber threat landscape
- Intelligence terminology
- Intelligence objectives
- Intelligence consumers
- Intelligence-driven security
Module 2: Threat Intelligence Lifecycle
- Planning and direction
- Collection
- Processing
- Analysis
- Dissemination
- Feedback and improvement
Module 3: Types of Threat Intelligence
- Strategic intelligence
- Tactical intelligence
- Operational intelligence
- Technical intelligence
- Intelligence use cases
- Audience requirements
Module 4: Understanding Cyber Threats
- Threat actors
- Attack motivations
- Attack surfaces
- Threat vectors
- Cyber campaigns
- Emerging threats
Module 5: Threat Actor Profiling
- Threat actor categories
- Motivations and objectives
- Capabilities
- Behavioral patterns
- Infrastructure analysis
- Actor tracking
Module 6: Intelligence Requirements
- Intelligence priorities
- Stakeholder requirements
- Priority Intelligence Requirements
- Collection requirements
- Information gaps
- Intelligence planning
Module 7: Threat Intelligence Collection
- Collection strategies
- Internal sources
- External sources
- Security telemetry
- Threat feeds
- Source evaluation
Module 8: Open-Source Intelligence
- OSINT fundamentals
- Public information sources
- Search methodologies
- Domain intelligence
- Infrastructure research
- Source validation
Module 9: Indicators of Compromise
- IOC fundamentals
- IP addresses
- Domains
- URLs
- File hashes
- Indicator enrichment
Module 10: Indicators of Attack
- Behavioral indicators
- Attack patterns
- Suspicious activities
- Detection opportunities
- Contextual analysis
- Threat validation
Module 11: MITRE ATT&CK Framework
- ATT&CK fundamentals
- Tactics
- Techniques
- Sub-techniques
- Threat mapping
- Defensive applications
Module 12: Cyber Kill Chain
- Reconnaissance
- Weaponization
- Delivery
- Exploitation
- Installation
- Command and control
Module 13: Diamond Model of Intrusion Analysis
- Adversary
- Capability
- Infrastructure
- Victim
- Event relationships
- Analytical applications
Module 14: Threat Data Analysis
- Data normalization
- Data enrichment
- Correlation
- Pattern identification
- Context development
- Analytical conclusions
Module 15: Malware Intelligence
- Malware categories
- Malware behaviors
- File indicators
- Network indicators
- Malware campaigns
- Intelligence extraction
Module 16: Network Threat Intelligence
- Network indicators
- DNS intelligence
- IP reputation
- Traffic patterns
- Infrastructure relationships
- Network threat analysis
Module 17: Vulnerability Intelligence
- Vulnerability information
- Threat context
- Exploitation trends
- Exposure analysis
- Risk prioritization
- Remediation intelligence
Module 18: Threat Intelligence Platforms
- Platform concepts
- Intelligence repositories
- Data ingestion
- Indicator management
- Enrichment
- Intelligence sharing
Module 19: Structured Threat Information
- STIX concepts
- TAXII concepts
- Structured intelligence
- Indicator relationships
- Intelligence exchange
- Automation concepts
Module 20: Threat Hunting with Intelligence
- Threat hunting fundamentals
- Intelligence-driven hypotheses
- IOC hunting
- Behavioral hunting
- Data analysis
- Hunting outcomes
Module 21: SIEM & Threat Intelligence
- SIEM integration
- Indicator matching
- Alert enrichment
- Event correlation
- Detection enhancement
- Investigation support
Module 22: Incident Response Intelligence
- Incident intelligence
- Threat context
- Indicator enrichment
- Campaign relationships
- Response prioritization
- Lessons learned
Module 23: Threat Attribution Concepts
- Attribution fundamentals
- Evidence evaluation
- Infrastructure relationships
- Behavioral similarities
- Confidence levels
- Analytical limitations
Module 24: Intelligence Analysis Techniques
- Hypothesis development
- Pattern analysis
- Timeline analysis
- Link analysis
- Competing hypotheses
- Analytical reasoning
Module 25: Intelligence Automation
- Automated collection
- Data enrichment
- Indicator processing
- API integration concepts
- Workflow automation
- Analyst efficiency
Module 26: Threat Intelligence Reporting
- Intelligence reports
- Executive summaries
- Technical reports
- Threat briefings
- Visualization
- Actionable recommendations
Module 27: Intelligence Quality & Confidence
- Source reliability
- Information credibility
- Confidence assessments
- Bias awareness
- Analytical accuracy
- Quality assurance
Module 28: Intelligence-Driven Security Operations
- SOC integration
- Detection engineering
- Vulnerability management
- Incident response
- Security prioritization
- Defensive improvements
Module 29: Practical Threat Intelligence Analysis
- Intelligence requirement
- Data collection
- Indicator analysis
- Threat mapping
- Intelligence assessment
- Stakeholder reporting
Module 30: Advanced Threat Intelligence Practices
- Emerging threat trends
- Intelligence program maturity
- Cross-team collaboration
- Advanced analytics
- AI-assisted intelligence
- Continuous improvement
Who it's for & what's included
Pick a delivery method to see exactly who it suits and everything you receive.
Classroom
Best for learners who want face-to-face tuition and to network with peers in person.
Everything you get
- ✓ Live instructor on-site
- ✓ Printed workbook & materials
- ✓ Group exercises & case studies
Online Instructor-Led
Best for learners who want a live instructor and a fixed schedule, without the travel.
Everything you get
- ✓ Live instructor via video call
- ✓ Digital workbook & resources
- ✓ Session recordings
Self-Paced
Best for self-motivated learners who need maximum flexibility around work and life.
Everything you get
- ✓ On-demand video lessons
- ✓ Interactive quizzes
- ✓ 24/7 access on any device