Skip to main content
Course

Cyber Threat Intelligence Foundations

Turn raw threat data into intelligence that drives decisions.

Beginner

Level

4

Modules

8

Lessons

4

Graded quizzes

2

Assignments

7 hours

Estimated time

What you will be able to do

  • You will be able to explain what cyber threat intelligence is and how raw data becomes finished intelligence that helps someone make a decision.
  • You will be able to tell strategic, operational, and tactical intelligence apart and match each type to the audience that acts on it.
  • You will be able to run the six phases of the intelligence lifecycle, beginning by turning a stakeholder's question into a clear priority intelligence requirement.
  • You will be able to judge a source for reliability and credibility and record your confidence in plain, honest estimative language.
  • You will be able to tell indicators of compromise apart from an adversary's tactics, techniques, and procedures (TTPs), and explain why behavior is harder for an attacker to change than a single artifact (the idea behind the Pyramid of Pain).
  • You will be able to map an intrusion with the Cyber Kill Chain and the Diamond Model to show how the pieces of an attack fit together.
  • You will be able to map observed attacker behavior to MITRE ATT&CK techniques and hand the result to detection and response teams.
  • You will be able to write a short, well-sourced intelligence product that answers the requirement and is pitched at the right reader.

What is inside

4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    What Cyber Threat Intelligence Is

    Before you can produce intelligence, you need to know what separates it from a pile of alerts and feeds. This module defines cyber threat intelligence, shows how raw data becomes a finished product that answers a real question, and introduces the three levels of intelligence along with the very different people who consume each one.

    2 lessons · 5 quiz questions

  2. 02

    Running the Intelligence Lifecycle

    Good intelligence is the output of a repeatable process, not a lucky find. This module walks the full lifecycle: turning a stakeholder's question into priority intelligence requirements (PIRs), collecting and processing the right data, analyzing it without fooling yourself, and getting the answer to the people who need it. You will also learn to weigh how trustworthy a source is and to state your confidence in plain, honest language.

    2 lessons · 5 quiz questions · assignment

  3. 03

    Indicators Versus Adversary TTPs

    Not every clue about an attacker carries the same weight. This module separates indicators of compromise, such as a file hash or a bad domain, from an adversary's tactics, techniques, and procedures (TTPs), which describe how the attacker actually operates. Using the Pyramid of Pain, you will see why forcing an attacker to change behavior costs them far more than burning a single indicator, and what that means for where you spend your time.

    2 lessons · 5 quiz questions

  4. 04

    The Core Analytic Models

    Analysts lean on shared models so their findings make sense to everyone else. This module teaches the three you are expected to know: the Cyber Kill Chain for the stages of an attack, the Diamond Model for connecting the pieces of an intrusion, and MITRE ATT&CK (short for Adversarial Tactics, Techniques, and Common Knowledge) for cataloging real-world attacker behavior. You will practice mapping an intrusion into each model and then handing the result to the teams that detect and respond.

    2 lessons · 5 quiz questions · assignment