
Introduce the fundamentals of cyber threat intelligence, the five-stage lifecycle, and four types, then apply concepts in hands-on labs using Microsoft Sentinel and MISP.
Learn what threat intelligence is, who might attack, why they attack, how they attack, and how to defend using threat intel and IOCs.
Use a real-world burglary analogy to explain threat intelligence: map fingerprints, cctv footage, and malware clues to a threat intelligence database and siem logs, revealing attackers' ip addresses.
Define the direction phase of threat intelligence by planning hospital-specific objectives, identifying ransomware and PHI risks, and outlining IOCs, phishing domain monitoring, and HIPAA considerations.
During the collection phase, gather raw threat data from open source intelligence, commercial feeds, private sharing groups, and internal logs, consolidating IOCs and TTPs for analysis.
Transform raw threat data into structured CSV or JSON formats by cleaning duplicates and noise, using Python and PowerShell, and tag IOCs to malware families for actionable insight.
Analyze the data in the analysis phase by correlating CSV IOCs with SIEM logs, running queries to detect ransomware like Conti, triggering threat intel rules, and blocking detected IOCs.
Disseminate finished threat intelligence to the right stakeholders, share structured IOCs and daily threat summaries to the SOC team, and feed alerts to SIEM, EDR, and firewalls for automated blocking.
Strategic threat intelligence informs executives about threat trends, adversary motives, and health sector risks, highlighting ransomware and information stealer activity to justify security budgets and defenses.
Explain how tactical threat intelligence captures tactics, techniques, and procedures used by threat actors, including PowerShell obfuscation and Cobalt Strike, to inform security operations center engineers, analysts, and threat hunters.
Explore operational threat intelligence guiding hospital defenses against a live phishing campaign, including IOCs, domains, and TTPs. See practical actions: analytics rules, email blocks, and endpoint isolation.
Learn how technical threat intelligence uses machine-readable indicators like IPs, URLs, domains, and file hashes to automate detections, alerts, and blocks across Microsoft Sentinel, firewalls, and Microsoft Defender for Endpoint.
Set up an azure free account, complete email verification and otp, and start a free trial in the azure portal. Learn to create virtual machines, storage, and sql databases.
Perform a hands-on lab to create an azure resource group, select a subscription and region, and configure a sentinel training resource group to host virtual machines.
Learn to set up a log analytics workspace in Azure, create the Sentinel Training resource group, validate deployment, and prepare for Microsoft Sentinel.
Set up Microsoft Sentinel in Azure by using the existing Log Analytics workspace in the training resource group, activate the 31-day free trial with 10 GB per day ingestion.
Explore how Microsoft Sentinel's content hub centralizes data connectors, analytics rules, hunting queries, and workbooks, and how to integrate threat intelligence logs via data connectors.
Learn to integrate external threat intelligence feeds into Microsoft Sentinel via a data connector, configure API details, and verify indicators with analytics rules and hunting queries.
Add indicators of compromise (IOCs) manually in Microsoft Sentinel using threat intelligence and Mitre framework mappings to monitor command and control and phishing activity.
Add IOCs to Microsoft Sentinel threat intel using the threat intel blade, creating IPv4 indicators and URLs, mapping to MITRE kill chains and validating via logs.
Compare indicators of compromise and indicators of attack to differentiate evidence of breach from ongoing attack, including IP addresses, domain names, hashes, URLs, and DDoS-like symptoms.
Explore how tactics, techniques, and procedures (TTPs) drive cyber attacks, with MITRE framework stages like initial access, execution, and examples such as phishing, social engineering, and data theft.
Explore the Mitre attack framework from reconnaissance to exfiltration, highlighting initial access, execution with PowerShell, persistence via registry run keys, discovery, lateral movement, and command and control.
Explore the cyber kill chain, a seven-phase framework from reconnaissance to action on object, and learn how stopping attackers early reduces risk with phishing and endpoint security.
Identify reconnaissance as the information-gathering phase, covering passive and active methods, public data research, and social engineering to learn about targets, with defenses like limiting public information and honey pots.
Craft malware or exploits for vulnerabilities in the weaponization phase, embedding them in PDFs or Word documents and sending phishing attachments to target employees.
Explore how attackers deliver malware via phishing emails, fake websites, drive-by downloads, and infected USB drives, weaponizing exploits and payloads to target organizations; strengthen defenses with verification and security awareness.
Explore how exploitation targets unpatched servers and vulnerabilities with weaponized payloads, enabling ransomware and data theft. See defensive measures: avoid suspicious attachments and links, update software, and use two-factor authentication.
Learn how attackers install malware after exploiting a weakness, hide backdoors and covert access in untrusted software, and defend with updated security software and limited admin rights.
Explains how attackers use a command and control server to issue commands to infected machines, steal data, and spread malware, while encrypting traffic to hide communications and avoid detection.
Explore attacker actions on objectives after gaining control, including data theft, silent spying, ransomware deployment, disruption, and persistence, and learn defenses like early detection, zero trust, and offline backups.
Discover top threat intelligence tools like Misp, Threat Connect, anomaly detection, Recorded Future, and IBM X-Force, and how they feed threat intel into security tools to improve visibility and response.
Discover how MISP enables structured threat intelligence sharing across a financial cyber shield, storing indicators like hashes and URLs, and automating responses to Bank East with SIEM, firewall, and IDS.
Install misp on a cloud ec2 instance with ubuntu 22, allocate enough ram and elasticsearch support, and login to the misp console to update the default password.
Explore adding and managing threat feeds in the MISP portal by enabling default feeds, loading feed metadata, and fetching data to populate events.
Create and manage threat feeds in MISP by adding events and IOCs like MD5 hashes, IP addresses, and domains. Share this data within your organization or with the banking community.
Are you ready to dive into the world of Cyber Threat Intelligence (CTI) and build job-ready skills in one of the most in-demand areas of cybersecurity?
This beginner-friendly course is designed to give you a clear, hands-on understanding of how Cyber Threat Intelligence works, how it supports Security Operations Centers (SOCs), and how you can start using real-world tools and platforms like Microsoft Sentinel and MISP to collect, process, and act on threat data. You’ll also gain insights into TTPs (Tactics, Techniques, and Procedures) used by adversaries and how CTI helps detect and defend against them.
What You’ll Learn:
Section 1: Introduction to CTI
Understand what CTI is and why it’s critical to modern cybersecurity.
Learn through real-world analogies that make complex topics easy to grasp.
Section 2: CTI Lifecycle Explained
Follow the CTI lifecycle: Direction, Collection, Processing, Analysis, and Dissemination.
Learn how each phase supports threat detection and enables a proactive defense strategy.
Section 3: Types of Threat Intelligence
Dive into the four core types: Strategic, Tactical, Operational, and Technical intelligence.
Understand how to apply them based on organizational needs and threat landscapes.
Section 4: Labs – Threat Intelligence in Microsoft Sentinel
Set up your Microsoft Azure environment and deploy Microsoft Sentinel.
Configure Log Analytics, explore the Content Hub, and integrate threat intelligence feeds including TTPs and IOCs.
Learn how to operationalize CTI in a cloud-native SOC platform.
Section 5: Tools Every Analyst Should Know
Explore the top 5 threat intelligence tools, including MISP for threat sharing and enrichment.
See how these tools help track, analyze, and defend against real-world attacks using known TTPs.