Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Beginner Hard40 hours

Threat Intelligence

Turning raw observations into assessed, actionable intelligence — with sourcing, structured analysis, and estimative language a decision-maker can act on. Recommended prior knowledge: Cyber Foundations or SOC Analyst L1.

Recommended first:Threat Hunting
Threat IntelligenceIOC AnalysisAnalyst ReportingLog AnalysisNetwork Analysis

What you will be able to do

  • Run the intelligence lifecycle from a requirement to a disseminated, actionable product.
  • Assess source reliability and express confidence with disciplined estimative language.
  • Map adversary behavior with Kill Chain, ATT&CK and the Diamond Model, and prioritize by the Pyramid of Pain.

Units

  1. 01

    What Cyber Threat Intelligence Is

    Data vs information vs intelligence, the strategic/operational/tactical levels, and what makes intelligence actionable rather than trivia.

    BeginnerAvailable

    Why you are learning this

    Everything in CTI rests on one distinction: an assessed, decision-ready product is intelligence; a list of indicators is not. This module builds that reflex.

    Unit contents6
  2. 02

    The Intelligence Lifecycle

    Direction, collection, processing, analysis, dissemination and feedback — and why intelligence requirements come first.

    BeginnerAvailable

    Why you are learning this

    Intelligence that does not start from a requirement answers no one's question. The lifecycle is the discipline that keeps CTI useful and directed.

    Unit contents6
  3. 03

    Collection & Source Evaluation

    OSINT and other collection sources, deduplication and enrichment, and the admiralty-style reliability/credibility grading of every source.

    BeginnerAvailable

    Why you are learning this

    An analyst is only as good as their sourcing discipline. This module builds the habit of grading a source before trusting a word of it.

    Unit contents7
  4. 04

    Analysis & Structured Techniques

    Cognitive bias, Analysis of Competing Hypotheses, confidence levels and estimative language, and the discipline of cautious attribution.

    Job-ReadyAvailable

    Why you are learning this

    The hardest part of CTI is thinking clearly under uncertainty. This module trains the structured techniques that guard against the analyst's own biases.

    Unit contents7
  5. 05

    Adversary Frameworks: Kill Chain, ATT&CK, Diamond & STIX

    The Cyber Kill Chain, MITRE ATT&CK, the Diamond Model, STIX/TAXII sharing, the Pyramid of Pain, and IOC lifecycle and decay.

    Job-ReadyAvailable

    Why you are learning this

    Frameworks are the shared language CTI uses to describe adversaries precisely and hand findings to hunting and IR. This module makes them second nature.

    Unit contents7
  6. 06

    Production, Dissemination & Feedback

    Writing for strategic, operational and tactical audiences, RFIs and threat assessments, dissemination, the feedback loop — and the integrated Sahab capstone.

    Job-ReadyAvailable

    Why you are learning this

    Intelligence that is not communicated to the right audience in the right form changes no decision. This module closes the lifecycle — then proves it.

    Unit contents7

Recommended next