
Get an overview of the course structure, key topics you'll explore, and what you can expect to achieve by the end. Understand how this course will help you build skills in threat intelligence and apply them in real-world scenarios. Introduction to the instructor and their background, with insights on their approach to teaching the course.
Identify types of threat intelligence, classify strategic intelligence objectives, and implement the consumer intelligence lifecycle.
Identify and understand types of threat actors. Understand their motivations and capabilities. Apply attribution methodologies.
Compare and contrast multiple threat modeling frameworks, including MITRE ATT&CK, Diamond Model, Cyber Kill Chain and STRIDE and PASTA.
Apply ethics in intelligence gathering and OSINT ethics and responsible disclosure to intelligence sharing laws and frameworks (e.g., GDPR, CCPA, NIST).
Get a practical understanding of OSINT tools and platforms (Shodan, VirusTotal, Maltego, etc.). Dark web and deep web intelligence gathering of
HUMINT, SIGINT, and proprietary sources.
Deconstruct domain, IP, and malware infrastructure mapping.
Investigate high-level static and dynamic analysis practices. Campaign tracking and actor TTP correlation. Using sandboxes and threat repositories.
Cross-referencing data for verification using threat intelligence platforms (TIPs) and threat feeds. STIX/TAXII standards for structured data exchange.
Discover Structured Analytic Techniques (SATs): ACH, Red Teaming, What-If brainstorming. Bias awareness and mitigation.
Risk scoring and impact assessment.
Linking TTPs to specific threat actors using evidence correlation and confidence levels. Use of geopolitical and regional intelligence. This video will include a thank-you message to learners.
Apply structured analytic techniques for threat attribution. Model threats to organizational risk scenarios. Assess attribution confidence and intelligence reliability.
Describe the principles and purpose of the ACH methodology. Apply the ACH process to evaluate competing hypotheses in a given intelligence scenario. Compare and contrast evidence to identify biases and gaps in analysis. Evaluate the consistency of evidence with multiple hypotheses using an ACH matrix. Create a structured ACH report justifying the most likely hypothesis based on weighted evidence.
Explain the objectives and methodologies of red teaming in threat analysis. Differentiate between red teaming, wargaming, and other adversarial simulation methods.
Design plausible threat scenarios using adversarial modeling techniques. Assess organizational vulnerabilities through structured red team exercises.
Construct scenario models to simulate attacker behaviors and test strategic responses.
Identify key frameworks and indicators used in threat actor attribution. Analyze the reliability and relevance of artifacts and behaviors in attribution efforts
Critique common pitfalls and biases in cyber attribution. Evaluate attribution claims based on confidence levels, supporting evidence, and geopolitical context. Develop a defensible attribution assessment using a structured analytic framework.
Summarize multiple real-world examples of APT attribution.
Define terms and scales used in expressing analytic confidence and likelihood. Distinguish between high, moderate, and low confidence in intelligence judgments.
Apply confidence language appropriately in written intelligence assessments.
Justify the level of confidence assigned to an analytic judgment. Revise analytic statements to reflect proper sourcing, uncertainty, and confidence levels.
Describe different threat modeling methodologies (e.g., STRIDE, ATT&CK, PASTA).
Develop a comprehensive threat model aligned with organizational goals and resources.
Conduct structured open-source and technical threat research. Analyze malware behaviors and campaign infrastructure. Correlate threat elements across incidents.
Advanced OSINT tradecraft. Sensor networks, honeypots, and dark web monitoring. Leveraging SIGINT and private CTI feeds
High-level static & dynamic analysis workflows. Identifying custom malware, implants, loaders. Toolset reuse across threat groups.
Linking disparate incidents via TTPs, IOCs, and infrastructure. Attribution frameworks and confidence scoring. Fingerprinting actor behaviors.
Analysis of Competing Hypotheses (ACH). red Team Analysis and What-If scenarios. Temporal and behavioral modeling.
Mapping threats to business risk. Scenario-based modeling (e.g., geopolitical escalation). Crown Jewel analysis.
Attribution matrix: evidence types and corroboration. Handling deception and false flags. Confidence language and intelligence judgments.
TIPs (ThreatConnect, MISP, Anomali). Graph analytics & link analysis (Maltego, i2 Analyst’s Notebook). CTI enrichment via APIs, sandboxes, YARA.
Learn how to transform messy graphs into clear threat intelligence using centrality metrics, infrastructure overlap detection, real-world investigative pivots, and automated Cypher alerts that surface emerging threats in real time.
The Cyber Threat Intelligence Professional Specialization empowers learners with a comprehensive understanding of modern cyber threats, analytical methodologies, and intelligence-driven security practices. Through this specialization, participants will master identifying threat actors, analyzing malicious activity, recognizing patterns across multiple data sources, and transforming raw cyber threat intelligence into actionable security insights that protect individuals and organizations.
Following established frameworks like the MITRE ATT&CK Matrix and NIST 800-53 security controls, each module dives into key concepts and is complemented by real-world threat scenarios, investigative walkthroughs, hands-on analysis exercises, and guided intelligence reporting.
Learners will develop practical skills in OSINT, HUMINT, SIGINT collection, deep-web and dark-web research, malware analysis, APT campaign analysis, and intelligence attribution techniques. The specialisation emphasises a holistic understanding of the cyber threat landscape, including identity theft, ransomware, business email compromise, and weaponised misinformation. You’ll learn to interpret adversarial tactics, techniques, and procedures (TTPs) to construct effective defense strategies.
In addition to technical skills, participants will also gain proficiency in writing cyber threat intelligence reports and delivering impactful oral briefings tailored to different audiences from security engineers and IT operations teams to senior executives with minimal technical expertise.
By the end of this program, learners will be equipped to contribute as cyber threat intelligence analysts, capable of identifying trends, mapping indicators of compromise, supporting incident response, and providing strategic, operational, and tactical intelligence. This specialization gives professionals the tools, frameworks, and analytical mindset needed to safeguard enterprises, protect sensitive information, and drive security-focused decision-making in a hyperconnected world while fostering adaptability, critical thinking, and leadership within the cybersecurity domain.