
Meet a cyber threat intelligence analyst with army and private sector experience. He bridges geopolitics, report writing, and the technical CTI skills needed to enter threat intelligence.
Explore theoretical and practical objectives. Learn cyber terminology, intelligence levels, and models like the diamond model and cyber kill chain, plus threat actor analysis, ransomware modus operandi, and darkweb monitoring.
Target students and early-career professionals from computer science, cyber security, international relations, or geopolitics to explore CTI concepts and use cases as a cybersecurity framework support.
Explore CTI fundamentals, definitions, and vocabulary across tactical and strategic levels, cover models like Diamond model and Cyber Kill Chain, and study ransomware methods, dark web monitoring, and Shodan-based hunting.
Understand the three components of cyber threat intelligence: cyberspace, threats, and the intelligence process, and how they combine to form the overall approach.
Cyberspace splits into physical, logical, and information layers; CTI analysts monitor vulnerabilities, backdoors, and campaigns across these layers, including disinformation in information and software use in the logical layer.
Threat equals intention plus capabilities plus opportunity, analyzed through malicious groups' objectives, tactics, techniques and procedures, and initial foothold methods to determine if a group truly threatens the organization.
Define intelligence as information that is collected, crossed, and analyzed to form an actionable final product; follow a five-phase lifecycle: planning and direction, collection, processing, analysis and production, and dissemination.
Define cyber threat intelligence as analyzed information on an adversary's malicious intent, capabilities, and opportunity to compromise a client or organization, with victimology and modus operandi guiding recommendations.
Define core CTI terms such as threat actor, persona, intelligence requirements, campaign, tactics, techniques and procedures (TTPs), intrusion, traffic light protocol, and indicators of compromise to clarify CTI conversations.
Identify threat actors behind cyber incidents—from cyber criminals and ransomware groups to state-sponsored apps, activists, and script kiddies—and their motives and targets.
Persona is the avatar or fake name adopted by the adversary, with threat actors operating on dark web forums and marketplaces and using GitHub profiles to reveal skills or interests.
Define intelligence requirements as client driven questions that drive the intelligence process, guiding analysis, assessment, and recommendations through the intelligence lifecycle.
A campaign is the final objective of a series of malicious operations. It describes a sophisticated group compromising hospitals across countries such as France, Germany, Italy, and Spain.
Identify how adversaries use tactics, techniques, and procedures, from initial compromise to discovery, through the Meteor Attack framework, and examine spear phishing and vulnerability exploitation.
Define intrusion as any adversary attempt to compromise a network, whether successful or failed, and log and analyze these attempts to track threat actors and evolving techniques.
Explore the traffic light protocol (TLP) that governs how threat intelligence—such as TTPs and malware details—can be shared with partners and within organizations across four levels: clear, green, amber, red.
Define indicators of compromise as technical artifacts like IP addresses, domains, hashes, or registry keys, combined with contextual evidence of malicious activity such as phishing or brute-force campaigns.
Navigate how cyber threat intelligence informs decision making for executives, SOC and CERT leaders, and SOC and CERT analysts by tailoring reports to strategic, operational, and tactical audiences.
Deliver succinct situation reports to executives by presenting graphs, trends, and actionable recommendations. Analysts translate cyber threat intelligence into hypotheses of future developments and recommendations to facilitate near-term decisions.
At the operational level, threat intel analysts disseminate information on new threat actors, operations, and tools to SOC or CERT leaders, guiding priorities in threat hunting, monitoring, and malware analysis.
Targeting the tactical level, this lecture trains analysts to support investigations through analyzing suspicious artefacts—IP addresses, binaries, and domains—and understanding threat actor modus operandi to speed investigations and block attacks.
Navigate the three levels of threat intelligence, linking geopolitics, cyber operations, threat actors, and suspicious domains, files, IPS, and logs for incident responses.
Examine four widely used CTI models to analyze threat actors' modus operandi and defend against them. Explore the cyber kill chain for incident response, the diamond model for activity groups, the meter attack matrix, and the final model that prioritizes hunting indicators of compromise.
Explore the cyber kill chain and its attack phases, showing how defenders detect early, stop intrusions, and CTI analysts map a threat actor’s modus operandi for reports and incident response.
Explore the reconnaissance phase of the cyber kill chain, where attackers gather target data, identify vulnerabilities, and plan tools and infrastructure for the next weaponization phase.
Unify attacker infrastructure with malware during the weaponization phase by linking code to an IP address for persistence, and obfuscate with packers or password-protected archives in phishing emails to evade defenses.
Identify how malware reaches a targeted network during the delivery phase, via physical media like USB keys and through internet-based methods such as phishing, watering hole attacks, and internet-facing applications.
Exploiters gain an initial foothold through phishing and social engineering or by exploiting vulnerable internet-facing applications such as mail servers or VPNs.
Explains how the install phase sustains persistence on a compromised machine across reboots. Shows methods like scheduled tasks, startup folder, and legitimate remote tools such as AnyDesk and TeamViewer.
Analyze how adversaries use command and control to communicate with compromised hosts, highlighting encoding and obfuscation techniques like steganography and base64, and how CTI analysts detect suspicious C2 traffic.
Detect and stop malicious actions before the objective phase of the cyber kill chain, helping soc and cert teams prevent ransomware exfiltration and encryption, theft, or destruction.
Explore a full cyber kill chain example from the kumo group, detailing reconnaissance, weaponization, delivery, exploitation, install, c2, and data encryption to illustrate threat actor modus operandi.
Explore the diamond model, linking the adversary, infrastructure, capabilities, and victim to explain how techniques enable exploitation and how analysts fill the four sides to track groups and attribute incidents.
Track a Turkish threat actor Red Cherry with the diamond model, mapping spear phishing, cobalt strike links, and infrastructure to a Dubai bank case for CTI, SOC, and CERT teams.
Explore the Mitre ATT&CK Matrix Navigator to visualize tactics, techniques, and procedures, export the matrix as JSON or Excel, and support primary analysis or incident response reporting.
Explore how the Pyramid of Pain prioritizes threat intelligence by ranking threat-actor artifacts—from hashes and IPs to custom tools—by the effort attackers must expend to change them.
Explore the APT1 report structure, including executive summary, threat actor context, infrastructure timeline, attack life cycle, and IOCs, with insights on victimology and industries targeted.
Explore the Lockbit 2.0 ransomware analysis framework, including executive summaries, facts and analyst comments, recent attacks, and a flow graph of infection from VPN exploitation to domain controller encryption.
Build an excel cheat sheet for SOC analysts that catalogs threat actors, tools (custom vs open source), capabilities, kill chain phase, samples, Yara rules, and analyst assessments for rapid detection.
Analyze the Black Basta ransomware group, detailing context, victimology, past operations, and modus operandi to defend a Dubai bank within the intelligence lifecycle from planning to dissemination.
Define an intelligence planning workflow using a planning workbook to translate the SOC leader's requirements into an actionable plan, identifying TTPs, tools, victims, and gaps.
In the collection phase, define sources of information—external channels such as social media, cybersecurity reports, CTI feeds, and internal sources—and learn to extract relevant data from open source reports.
Learn collection-phase tips using Malpighia, Google Sheets, GitHub, and national certs to identify threat actors and ransomware, aided by Google Docs search queries.
Learn to use a five-part osint report integration framework—context, victimology, tools, meta attack, and iocs—to extract key information, track threat actors, and produce operational reports.
Explore an osint integration framework by analyzing a Black Basta ransomware report, mapping techniques to meteor attack procedures, and cataloging on-the-shelf and custom tools plus IOCs.
Cross-check multiple reports in a generic analysis document to validate overlaps and build confidence on details, like first operations in April 2022 and Quackpot as the initial infection vector.
Detail a final report on the Black Basta ransomware group, outlining operations, extortion techniques, victimology, and infection vectors, including the Quakebot malware and analysis methodology.
Monitor the dark web to detect data leaks, access for sale, or confidential documents related to the organization, tracing compromised credentials and remote access used to launch ransomware.
Prepare a virtual lab with virtual box, remnux vm, vpn, and brave browser with tor to create an avatar and identify darkweb forums and marketplaces for credentials and data leaks.
Explore how Tor uses three onion routers (entry, intermediary, and exit) to provide anonymity and confidentiality. Three-layer encryption is peeled at each node, protecting the message end to end.
Create an encrypted link from your device to a vpn server, hiding your identity from destination servers and protecting against man-in-the-middle attacks, with Proton VPN atop Tor for extra anonymity.
Set up VirtualBox to isolate malware analysis and dark web investigations in a virtual machine. Import and run Remnux, malware analysis toolkit, and use snapshots to return to clean states.
Install and configure the Brave browser with Tor connectivity on a Remnux machine. Create a ProtonMail account, install ProtonVPN, and set up KeePassXC to centralize credentials.
Identify dark web forums and marketplaces via GitHub, Telegram, and dark web scrapers; understand data leaks and credential access for sale and why Tor links fluctuate.
Dark web monitoring reveals how ransomware groups exfiltrate data, employ double extortion, and publish samples via onion URL to pressure victims into paying.
this lecture presents three c2 infrastructure hunting methods to block adversary activity: ssl certificate analysis; pivoting from a known c2 ip with ssl; and pivoting from a known c2 server.
master c2 infrastructure hunting by discovering adversary controlled IP addresses and SSL certificates, applying jump fingerprinting and domain pattern analysis to identify related infrastructure and block malicious activity.
Explore how SSL certificates authenticate websites and encrypt client-server communications, and learn to pivot on certificates to identify additional C2 servers used by attackers.
Germ fingerprinting analyzes tls handshakes via client hello packets, producing a hash of cipher, tls version, and tls extensions; it enables shodan pivoting to detect cobalt strike and sliver hosts.
Pivot on ssl certificate serial numbers and jarm fingerprints in Shodan to identify Cobalt Strike and other attack emulation servers, then blacklist malicious ips to protect networks.
Review cyber threat intelligence definitions and objectives, outline current models, and demonstrate ransomware primer, dark web monitoring, and c2 hunting with Shodan via ssl certificates and germ fingerprints.
Cyber Threat Intelligence is a relatively new field within cyber security. As cyber attacks increase both in terms of volume and sophistication, organizations felt the need to anticipate future cyber attacks by analyzing threat actors, malwares, used modus operandi, motivations and possible affiliations.
Are you a young graduate in the field of cyber security, computer science, international relations & geopolitics?
Are you a junior cyber security professionals (SOC analysts, CERT analysts)?
Are you interested in cyber security and would like to know more about Cyber Threat Intelligence?
If yes, this class will provide you:
The theoretical foundations of Cyber Threat Intelligence with:
Definitions of the fundamentals (cyberspace, threat, intelligence, Indicators of Compromise,etc.)
Definition and explanation of CTI specific models (Cyber Kill Chain, Diamond Model, Pyramid of Pain, MITRE ATT&CK)
Explanation of CTI objectives (Tactical level, Operational level, Strategic Level Intelligence)
Concrete examples of reports published nowadays
Quizzes to test your knowledge
The practical experience to complete CTI related tasks:
Primo-analysis of a threat actor (context, modus operandi analysis, assessment and recommendations)
Asset monitoring in the Darkweb (setup a virtual environment, VPN connection, identify Darkweb forums and ransomware group activities)
Adversary controlled infrastructure hunting (SSL certificate pivoting and JARM fingerprint pivoting)
Resources for your future tasks as a CTI analyst:
OSINT report integration framework
Intelligence Workbook
Analysis and reports examples
This class is synthetic, straight to the point and well resourced. Enjoy the class and welcome to the CTI community!