Threat Intelligence Collection & Analysis
Collect from every source, test your thinking, and reach threat judgments that hold up.
Tuition
$349
Intermediate
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
8 hours
Estimated time
What you will be able to do
- You will be able to run the threat intelligence lifecycle and translate a stakeholder's needs into priority intelligence requirements that focus your collection.
- You will be able to run collection across open sources, commercial threat feeds, and the dark web while protecting your identity and staying within legal and ethical limits.
- You will be able to map adversary behavior to established models such as MITRE ATT&CK, the Diamond Model, and the Cyber Kill Chain.
- You will be able to organize and assess evidence with structured analytic techniques that reduce the pull of cognitive bias.
- You will be able to run an analysis of competing hypotheses to test rival explanations and pinpoint the evidence that would change your mind.
- You will be able to grade source reliability and information credibility, then set a calibrated confidence level for each judgment.
- You will be able to write and brief a finished threat intelligence product that uses clear estimative language and is honest about its confidence and gaps.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
Threat Intelligence Foundations and Requirements
Good intelligence starts with a clear question, not a pile of data. This module grounds you in the threat intelligence lifecycle and in the difference between strategic, operational, and tactical intelligence. You will learn to turn a stakeholder's needs into priority intelligence requirements (PIRs) that steer your work, and you will meet the core models analysts use to structure threats: the MITRE ATT&CK knowledge base, the Diamond Model, and the Cyber Kill Chain.
2 lessons · 5 quiz questions
- 02
Collecting from OSINT, Commercial Feeds, and the Dark Web
With your requirements set, the next job is getting the data. This module covers collection across the three sources that matter most to a threat intelligence analyst: Open Source Intelligence (OSINT), commercial threat feeds, and criminal spaces on the dark web. You will learn to judge feed quality, work with indicators of compromise (IOCs) and adversary tactics, techniques, and procedures (TTPs), protect your identity with managed attribution, and stay within clear legal and ethical limits.
2 lessons · 5 quiz questions · assignment
- 03
Structured Analytic Techniques and Competing Hypotheses
Collection gives you material; analysis turns it into a judgment. This module shows how professional analysts think on purpose, using structured analytic techniques (SATs) to slow down, surface their assumptions, and reduce the pull of cognitive bias. You will then work through analysis of competing hypotheses (ACH), a step-by-step method for weighing rival explanations against the evidence, so the conclusion you reach is the one the evidence actually supports.
2 lessons · 5 quiz questions
- 04
Source Evaluation, Confidence, and Reporting
A judgment is only as trustworthy as the sources behind it and the honesty of its confidence level. This module teaches you to grade source reliability and information credibility using the Admiralty System (also called the NATO System, named for the North Atlantic Treaty Organization), then to set and defend a calibrated confidence level for each key finding. You will finish by writing a clear intelligence product that uses careful estimative language, states its gaps, and briefs a busy decision-maker in plain terms they can act on.
2 lessons · 5 quiz questions · assignment