
Meet the cyber threat intelligence instructor, bringing a decade of Azure and cybersecurity expertise to deliver real-world, hands-on insights. Learn to design cloud, cybersecurity, and AI architectures with clear guidance.
Navigate the complexity of cyber security as people, cloud, endpoints, mobile, and IoT expand, challenging defenses and amplifying the need for threat hunting and integrated XDR and SIEM strategies.
Explore how security operations centers conduct threat intelligence, threat hunting, log management, threat detection, and incident response to identify adversaries, gather IOCs, and reduce attack surfaces.
Explore three-tier soc model where automation handles commodity malware and repetitive tasks, tier one handles easier alerts, tier two addresses threats, and tier three performs threat hunting and forensics.
Align stakeholders to prepare an incident response process per the NIST guide, defining preparation, detection and analysis, containment, eradication and recovery, and post-incident lessons learned.
Demystify EDR, XDR, SIEM, and SOAR by explaining their roles in a SoC, including Defender for Endpoint, Sentinel, and Logic Apps for incident automation.
Explore blue, red, and purple teaming: blue team defense with monitoring and incident response; red team testing and social engineering; purple teaming unites both to simulate TTPs and improve defenses.
Explore why cloud computing exists by examining five properties: on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service.
Define public, private, hybrid, and multi-cloud types with Azure, AWS, and GCP as examples, and explain how hybrid and multi-cloud patterns combine on-premises and public cloud.
Explore Azure global backbone, detailing data centers, fiber and subsea cables, edge sites, peering connections, and extensive connectivity that deliver performance, fault tolerance, and business continuity for users.
Explore the shared responsibility model across on premises, IaaS, PaaS, and SaaS in Azure, AWS, and GCP. Identify which layers—physical, OS, network, and apps—remain yours versus the provider's, including security.
Explore the Azure resource hierarchy, including management groups, subscriptions, and resource groups. Learn how grouping by region, department, or lifecycle supports governance and security.
Explore Azure subscription types, including free, student, pay-as-you-go, and enterprise agreements, with a focus on the free option for demos in this course.
Explore how Entra ID tenants relate to Azure subscriptions, with identities in the Entra ID tenant accessing resources in subscriptions and resource groups, and clarify that tenants are identity providers.
Zero trust is a security strategy and mindset, not a product, built on verify explicitly, least privileged access, and assume breach to minimize blast radius.
Explore the Microsoft security cosmos, focusing on cloud security, SOC, and CTI, with Defender XDR covering identity, endpoint, cloud apps, all 365, and cloud security posture management.
Explore a cyber kill chain and defend steps with Defender for Office, Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps against phishing, credential compromise, and data exfiltration.
Refine and analyze information to produce intelligence that yields actionable advice. Relate raw data to the operational environment and past experience to transform data into intelligence.
Apply the observe, orient, decide and act loop to turn gathered data into contextualized intelligence, then act and repeat in a never-ending cycle.
Explore the intelligence cycle, from defining objectives and collecting data to processing, analyzing, disseminating, and gathering feedback to improve cyber threat intelligence programs.
Analyze competing hypotheses to overcome biases; generate hypotheses, gather evidence, assess credibility and relevancy, refine, test inconsistency, perform sensitivity analysis, and report findings using a matrix.
Explain how the traffic light protocol, with red, amber, green, and clear labels, governs need-to-know sharing of cyber threat intelligence within communities and organizations across threat intelligence tools and platforms.
Explore cyber threat intelligence sources, including Humint from interviews and conversations. Examine Osint, Geoint, Masint, image resource intelligence, and financial intelligence for signals like netflow, satellites, and cryptocurrency trails.
Identify the three levels of intelligence—strategic, operational, and tactical—and map them to cyber security, from macro trend analysis to actor behavior, capabilities, and indicators of compromise (IOCs).
Define cyber threat intelligence as knowledge about adversaries’ motivations, intentions, and methods collected to inform defense. Focus on tactics, techniques, and procedures (TTPs) and threat actor behavior for threat-informed defense.
Clarify the distinctions between intelligence, threat intelligence, and cyber threat intelligence, showing that cyber threat intelligence focuses on adversary threat actors using cyber security related tactics, techniques, and procedures.
Define a threat using the NIST standard: any event that harms operations or assets through an information system, via unauthorized access, destruction, modification, disclosure, or denial of service.
Define threats, vulnerabilities, and risks, and identify how threat actors exploit vulnerabilities to cause downtime, confidentiality breaches, or data integrity violations, yielding risk as impact plus likelihood.
Define your organization's mission, identify threat actors in your industry, map their motivations and TTPs, and use threat informed defense to detect and protect.
Learn how tactics, techniques, and procedures (TTPs) define threat actor behavior from high-level objectives to detailed actions, with procedures revealing sequence steps and deep dives into technology.
Differentiate iocs and ioas: iocs are evidence of compromise, such as file hashes or domains, while ioas focus on attacker behavior and intent for threat-informed defense.
Learn the indicator lifecycle in cyber threat intelligence, from CDI reports and IOCs to revealing, maturing, and using indicators in detections within your SoC.
Explore the pyramid of pain, where changing hashes, IPs, and domains is easy, but detecting TTPs is hard, with tools like Mimikatz, Metasploit, Cobalt Strike, and Burp Suite.
Pivoting in cyber threat intelligence connects seemingly unrelated data points to identify potential threats and adversaries, linking metadata, detections like Yara signatures, and artifacts such as domains and IPs.
Threat hunting is the proactive search for undetected threats in your environment. Use intelligence-based hunting with IOCs and hypothesis-based hunting focused on adversary behavior, often in a hybrid approach.
Explore cti sources across enterprise tools, open source intelligence (osint), and social media, with examples like Microsoft Defender Threat Intelligence, VirusTotal, Shodan, and Twitter/X.
The diamond model of intrusion analysis links adversaries, capabilities, infrastructure, and victims, showing how adversaries deploy capabilities over infrastructure to target victims.
Analyze the Lockheed Martin cyber kill chain, from reconnaissance through actions on objectives, including weaponization, delivery, installation, and command and control, to understand adversary behavior in cyber security.
Explore the MITRE ATT&CK framework to map adversarial tactics and techniques for threat-informed defense. Discover how MITRE offers free resources, enterprise services, and practical use in Sentinel to assess coverage.
Map the pyramid of pain to MITRE ATT&CK by aligning tactics, techniques and sub techniques, emphasizing TPS over artifacts like hashes or IPs.
Examine the three core matrices—enterprise, mobile, and industrial control systems—with enterprise submatrices for Windows, Linux, macOS, and cloud matrices such as Azure AD, O365, Google Workspaces, plus networks and containers.
Explore the 14 enterprise tactics in the middle attack framework, from reconnaissance to exfiltration and impact, highlighting how tactics define adversaries' high-level objectives and behaviors.
Explore the techniques layer of the middle attack framework, covering 201 techniques across tactics. Highlight examples like active scanning, reconnaissance, initial access, persistence, and exfiltration via C2.
Examine how adversaries use 424 sub techniques to perform attacks, linking selected sub techniques to tactics and techniques with examples like vulnerability scanning, spear phishing, and DLL injection.
Explore tactics, techniques, and subtechniques in the attack framework, showing how tactics reveal adversaries' motivations, techniques show how objectives are achieved, and subtechniques like python detail methods.
Identify and onboard data sources to collect telemetry for detecting adversaries, focusing on network traffic and logs from web application firewalls and on premises networks to spot vulnerability scanning.
Identify detections as high-level strategies for adversaries’ techniques and sub-techniques, focusing on reconnaissance and scanning. Use web application firewall logs to detect vulnerability scans and trigger alerts via CIM rules.
Explore mitigations as preventative configurations to reduce the attack surface, prioritize minimizing data exposed to external parties, and implement privileged account management to prevent privilege escalation.
Track adversaries with related behavior under common names in cyber threat intelligence, though vendors assign different names. Note that apt41 is named differently by Mandiant, CrowdStrike, and Microsoft.
Explore software in cyber threats as the tools and malware adversaries use, linked to techniques, groups, and campaigns, including built-in, commercial, and open-source options such as PowerShell.
Campaigns are orchestrated intrusion operations over a defined period with common targets and objectives, often by nation-state actors, exemplified by the Ukraine power grid attack and cuckoo bees espionage.
Explore how threat groups use tactics, objectives, motivations, techniques, sub techniques, and software to form campaigns, and how data sources enable detections of adversary activity.
Operationalize the meta attack framework to standardize communication across the SOC and CTI teams, shifting from tool-centric to behavior-based detections that are more scalable and sustainable.
Leverage the Mitratech framework and attack navigator to map tactics, techniques, and sub techniques to detections and mitigations, enabling threat informed decision making.
Explore the enterprise matrix of the MITRE ATT&CK framework, navigating tactics, techniques, sub-techniques, mitigations, detections, and data sources, with CTI insights on groups, campaigns, and software like Mimikatz.
Explore the ATT&CK navigator to operationalize attack insights with an interactive heat map of tactics, techniques, and sub-techniques, and color-code to highlight detections and mitigations.
Build a collaborative purple team approach with ATT&CK to identify relevant ttps, develop detections, and test capabilities through red and blue team simulations for continuous defense improvement.
The ATT&CK framework evolves as a dynamic framework updated roughly every six months with new techniques and sub-techniques observed by the intelligence community, with the latest update in October 2023.
Identify threat actors in cybersecurity, including nation-states, criminals, hacktivists, terrorists, and unknowns. Map their motivations from geopolitics and espionage to financial gain, political aims, and ideological aims.
Examine how the Sandworm advanced persistent threat used NotPetya in 2017 to destroy systems via a Medoc supply-chain attack, disguising ransomware while moving laterally and dumping credentials.
Learn to install and configure VirtualBox to host Kali Linux, including downloading the installer, selecting your OS, running through default settings, and viewing the overview.
Download Kali Linux from the resources, install it with VirtualBox, extract the zip, add the image, adjust RAM and cores, boot, and log in as Carly to start attacking infrastructure.
Configure the Kali Linux keyboard layout via the settings manager, add keyboards (German and US English), and adjust priority with up and down arrows; remove unused keyboards and close settings.
Explore the whois lookup, a built-in OSINT tool, to fetch domain details such as registrar, creation date, name servers, and privacy-protected registrant information.
Explore the harvester, a Kali Linux osint tool for gathering domain or company information using sources like Bing, DuckDuckGo, and URL scan, with -D, -B, and -L options.
Explore open source intelligence with SpiderFoot on Kali Linux, initiate a local scan via 127001, and analyze IPs, DNS, and geolocation data to map domain associations.
This course contains the use of artificial intelligence.
Cyber Threat Intelligence (CTI) by Christopher Nett is a meticulously organized Udemy course designed for IT professionals aiming to master CTI to empower threat-informed defenses. This course systematically guides you from the basis to advanced concepts of CTI.
By mastering CTI, you're developing expertise in essential topics in today's cybersecurity landscape. Through this course, you'll develop expertise in CTI, a comprehensive topic widely recognized for understanding tactics, techniques and procedures of adversaries and defending against cyber threats.
This deep dive into CTI equips you with the skills necessary for a cutting-edge career in cybersecurity.
Key Benefits for you:
SOC Basics: Understand the foundational structures of Security Operations Centers and their role in cybersecurity.
Azure Basics: Gain essential knowledge of Microsoft Azure's infrastructure.
Zero Trust Basics: Learn the principles of the Zero Trust security model.
Intelligence: Explore the methods of collecting and analyzing data to predict and prevent threats.
CTI: Delve into the core techniques of Cyber Threat Intelligence to identify potential threats before they impact.
CTI Related Frameworks: Discover various frameworks that enhance the effectiveness of CTI processes.
MITRE ATT&CK: Study this globally-accessible knowledge base of adversary tactics and techniques.
Threat Actors and Advanced Persistent Threats: Identify common adversaries in cyber warfare.
CTI Tools: Get hands-on experience with the tools that professionals use for CTI gathering and analysis.
CTI Platforms: Familiarize yourself with platforms specifically designed for managing and operationalizing CTI.
AI & CTI: Explore the intersection of Artificial Intelligence and CTI to enhance threat detection.
Case Study I - MISP on Azure: Analyze how the MISP threat intelligence platform can be implemented on Azure to manage CTI.
Case Study II: Researching APT41 with ATT&CK: Understand the approach to investigating the TTPs of APT41 using the MITRE ATT&CK framework.
Case Study III: Leveraging CTI in Microsoft Sentinel: See practical applications of CTI in enhancing Microsoft Sentinel's threat detection capabilities.
Case Study IV: Building a CTI Program: Learn from a comprehensive blueprint on setting up a successful CTI program within an organization.
This course contains promotional materials.