Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Certified Cyber Threat Intelligence Analyst
Rating: 4.4 out of 5(1,152 ratings)
5,206 students

Certified Cyber Threat Intelligence Analyst

Learn to intelligently detect and take down cyber threats
Last updated 6/2017
English
English [Auto],

What you'll learn

  • 7 threat intelligence phases
  • Hunting - The goal of hunting is to establish techniques to collect samples from different sources that help to start profiling malicious threat actors.
  • Extraction -The goal of Features Extraction is to identify unique static features in malware binaries that help classify them into malicious groups.
  • Behavior Extraction - Identifies unique dynamic features in binaries that help classify them as malicious.
  • 'Correlation and Clustering' - This method identifies malware based on its behavior and features and uses that information to classify it.
  • Threat Actor Attribution - The goal of Threat Actors is to locate the threat actors behind the malicious clusters identified.
  • Tracking - The goal of tracking is to anticipate new attacks and identify new variants proactively.

Course content

8 sections69 lectures9h 39m total length
  • Threat Intelligence Researcher Course Intro6:43

    Earn the cyber security threat intelligence researcher certification to perform technical research on malware and threat actors, use open source intelligence, and generate indicators of compromise reports for security operations.

  • Phases Overview Part 17:28

    Learn phases of cyber threat intelligence with labs and ethical research, beyond IP addresses and hashes, and gather indicators of attack, indicators of compromise, and attacker motivation to inform decisions.

  • Phases Overview Part 25:40

    Explore the seven steps of full threat intelligence, starting with hunting and feature extraction, to understand malware behavior, clustering, actor attributes, and takedown with law enforcement.

  • Phases Overview Part 35:29

    Identify and track trade actors, stay proactive, and build a full picture of malware behavior through intelligence research goals; collaborate with security teams and law enforcement to disrupt operations.

  • Hunting Part 16:11

    Embark on hunting as the first phase of cyber threat intelligence, gathering samples from diverse sources to profile malware and actors using tools like VirusTotal.

  • Hunting Part 29:22

    Explore hunting techniques in cyber threat intelligence, from analyzing underground forums and the deep web with tor to leveraging honeypots and open source intelligence for instant response engagement.

  • Features Extraction Part 17:50

    Explore static feature extraction in cyber threat intelligence, uncovering time stamps, digital certificates, and other static indicators to classify malware and verify trusted sources without executing code.

  • Features Extraction Part 27:17

    Master feature extraction for cyber intelligence, leveraging exif metadata, language clues, import hash tables, strings, ssdeep fuzzy hashes, mutexes, PDB, and control messages to profile malware and guide threat hunting.

  • Behavior Extraction Part 16:53

    Identify unique dynamic features of malware through behavior extraction to classify and cluster samples into malicious groups using sandbox analysis and memory dumps.

  • Behavior Extraction Part 25:54

    Explore behavioral extraction of malware, from droppers and process injection to downloaders, keystroke logging, and sandbox evasion techniques that reveal malicious activity via IPs and delays.

  • Behavior Extraction Part 36:45

    Identify persistence techniques used by malware, including registry keys, services, and scheduled tasks. Explore memory hash dumping, file infector activity, and passive DNS for crime scene mapping and behavior classification.

  • Clustering and Correlation8:04

    Cluster and correlate malware by classifying nodes with features and behaviors. Link insights via gravity graphs to map attack flows, relationships, and identifiers across a graph structure.

  • Threat Actor Attribution Part 15:27

    Identify the threat actor behind a malicious cluster by locating origin and sponsorship, and pinpoint the targeted sector. Assess command and control infrastructure to map back to the attacker.

  • Threat Actor Attribution Part 25:58

    Analyze threat actor tactics, techniques, and procedures (TTPs) to identify entry points, persistence, privilege escalation, lateral movement, and exfiltration strategies, aided by reverse engineering.

  • Tracking5:46

    Track threat activity to anticipate new attacks and identify variants proactively. Use passive DNS, internet port scans, VirusTotal lookups, and open source intelligence and deep hash analysis.

  • Taking Down8:12

    Take down phase teaches coordinating with local and international law enforcement to dismantle organized crime networks using sinkhole and man-in-the-middle techniques, tracking hacking forums, and navigating jurisdictional constraints.

  • Threat Intelligence Overview

Requirements

  • Familiar with cyber exploits and breaches that have occurred in the public

Description

The Cyber Security Threat Intelligence Researcher Certification will help you acquire the skills needed to find out who is behind an attack, what the specific threat group is, the nation from which the attack is being launched, as well as techniques being used to launch this attack.

You will know how to take a small piece of malware, find out who is responsible for launching it, the threat actor location and also how to take down that threat actor, with the support of your local law enforcement.

In today’s cyber security landscape, it isn't possible to prevent every attacks. Today’s attackers have significant funding, are patient, sophisticated, and target vulnerabilities in people and processes as well as technologies. With organizations increasingly relying on digitized information and sharing vast amounts of data across the globe, they have become easier targets for many different forms of attack. As a result, every company’s day-to-day operations, data and intellectual property are seriously at risk. In a corporate context, a cyber attack can not only damage your brand and reputation, it can also result in loss of competitive advantage, create legal/regulatory noncompliance and cause steep financial damage.

Today’s secure environment will have vulnerabilities in it tomorrow, so an organization cannot allow itself to become complacent. There is only so much an organization can do by defending itself against threats that have already occurred. If an organization only reacts to new threats as they come up, are likely acting too late. It is important to understand and prioritize cyber threat intelligence processes, and how they can be integrated into an organization’s security operations in a way that adds value. 

Cyber threat intelligence (CTI) is an advanced process enabling organizations to gather valuable insights based on analysis of contextual and situational risks. These processes can be tailored to the organization’s specific threat landscape, industry and market. This intelligence can make a significant difference to organizations' abilities to anticipate breaches before they occur. Giving organizations the ability to respond quickly, decisively and effectively to confirmed breaches allows them to proactively maneuver defense mechanisms into place, prior to and during the attack.

In this course, we’ll introduce you to the 8 phases of threat intelligence:

  • Hunting - The goal of hunting is to establish techniques to collect samples from different sources that help to start profiling malicious threat actors.
  • Features Extraction - The goal of Features Extraction is to identify unique Static features in the binaries that help to classify them into a specific malicious group.
  • Behavior Extraction - The goal of Behavior Extraction is to identify unique Dynamic features in the binaries that help to classify them into a specific malicious group.
  • Clustering and Correlation -  The goal of Clustering and Correlation is to classify malware based on Features and Behavior extracted and correlate the information to understand the attack flow.
  • Threat Actor Attribution - The goal of Threat Actors is to locate the threat actors behind the malicious clusters identified.
  • Tracking - The goal of tracking is to anticipate new attacks and identify new variants proactively.
  • Taking Down - The goal of Taking down is to Dismantled Organized Crime Operations.

Who this course is for:

  • anyone interested in preventing cyber threats