Threat Intelligence
Turning raw observations into assessed, actionable intelligence — with sourcing, structured analysis, and estimative language a decision-maker can act on. Recommended prior knowledge: Cyber Foundations or SOC Analyst L1.
What you will be able to do
- Run the intelligence lifecycle from a requirement to a disseminated, actionable product.
- Assess source reliability and express confidence with disciplined estimative language.
- Map adversary behavior with Kill Chain, ATT&CK and the Diamond Model, and prioritize by the Pyramid of Pain.
Units
- 01
What Cyber Threat Intelligence Is
Data vs information vs intelligence, the strategic/operational/tactical levels, and what makes intelligence actionable rather than trivia.
BeginnerAvailableWhy you are learning this
Everything in CTI rests on one distinction: an assessed, decision-ready product is intelligence; a list of indicators is not. This module builds that reflex.
- 02
The Intelligence Lifecycle
Direction, collection, processing, analysis, dissemination and feedback — and why intelligence requirements come first.
BeginnerAvailableWhy you are learning this
Intelligence that does not start from a requirement answers no one's question. The lifecycle is the discipline that keeps CTI useful and directed.
- 03
Collection & Source Evaluation
OSINT and other collection sources, deduplication and enrichment, and the admiralty-style reliability/credibility grading of every source.
BeginnerAvailableWhy you are learning this
An analyst is only as good as their sourcing discipline. This module builds the habit of grading a source before trusting a word of it.
Unit contents7
Theory Lessons(6)
Practical Labs(1)
- 04
Analysis & Structured Techniques
Cognitive bias, Analysis of Competing Hypotheses, confidence levels and estimative language, and the discipline of cautious attribution.
Job-ReadyAvailableWhy you are learning this
The hardest part of CTI is thinking clearly under uncertainty. This module trains the structured techniques that guard against the analyst's own biases.
Unit contents7
Theory Lessons(6)
Practical Labs(1)
- 05
Adversary Frameworks: Kill Chain, ATT&CK, Diamond & STIX
The Cyber Kill Chain, MITRE ATT&CK, the Diamond Model, STIX/TAXII sharing, the Pyramid of Pain, and IOC lifecycle and decay.
Job-ReadyAvailableWhy you are learning this
Frameworks are the shared language CTI uses to describe adversaries precisely and hand findings to hunting and IR. This module makes them second nature.
Unit contents7
Theory Lessons(6)
Practical Labs(1)
- 06
Production, Dissemination & Feedback
Writing for strategic, operational and tactical audiences, RFIs and threat assessments, dissemination, the feedback loop — and the integrated Sahab capstone.
Job-ReadyAvailableWhy you are learning this
Intelligence that is not communicated to the right audience in the right form changes no decision. This module closes the lifecycle — then proves it.
Unit contents7
Theory Lessons(6)
Practical Labs(1)
Recommended next
Threat Hunting
Proactive, hypothesis-driven investigation — finding attacker behavior the alerts missed, and turning what you find into new detections. Recommended prior knowledge: Cyber Foundations or SOC Analyst L1.
Incident Response
Move from a confirmed alert into structured response: validate, scope, preserve evidence, contain, eradicate, recover — and report to both engineers and executives. Recommended prior knowledge: Cyber Foundations or SOC Analyst L1.