You can learn to map a threat report to MITRE ATT&CK in about four hours, for free, from the team that maintains ATT&CK. You can also pay $8,780 for six days of SANS FOR578, and an attempt at the matching GIAC GCTI exam adds $999 (US prices on 28 September 2026). Both are cyber threat intelligence training. They are not substitutes for each other, and plenty of people asking "which CTI course should I take?" do not need either one yet.
One disclosure before anything else: we run CTI Academy, which sells CTI training, and it appears in this guide. Weigh our section accordingly. Every price, duration and exam detail below comes from the provider's own page, checked on 28 September 2026. Prices move, so read them as a snapshot, not a quote.
This is a practitioner's map of the options: the free material that is genuinely good, the paid courses and who they suit, the certifications (GCTI, CTIA, the CREST ladder and Mandiant's MCTIA) side by side, what job postings actually ask for, and a sensible order to take things in.
What Cyber Threat Intelligence Training Actually Teaches
Cyber threat intelligence training teaches the analytic process behind CTI: turning a stakeholder's question into an intelligence requirement, collecting from technical and human sources, grading how far each source can be trusted, analyzing adversary behavior with models such as MITRE ATT&CK, the Diamond Model and the Cyber Kill Chain, and writing an assessment that a defender or an executive can act on. It comes in three forms: free self-study material, paid courses with labs or instructors, and certifications that test you against a published syllabus. If you want the discipline itself explained first, start with our guide to what cyber threat intelligence is, and the breakdown of the strategic, operational, tactical and technical levels most syllabi are built around.
The useful question is what employers need that training to produce. When we coded 214 detailed CTI job postings, reporting and briefing appeared in 95% of them and threat actor, TTP and campaign analysis in 90%. MITRE ATT&CK came up in 49%. Detection engineering (52%) and SOC or incident response integration (49%) each showed up in about half, which means CTI work is expected to feed defenders directly.
The demand side agrees. In the SANS 2026 CTI Survey, 91% of CISOs rated CTI valuable or extremely valuable, but only 26% said it significantly influences their decisions (the executive figures come from a module of 67 security leaders, mostly CISOs and CSOs). SANS also found most CTI teams have fewer than four full-time staff. Small teams cannot carry an analyst who finds things but cannot explain them.
So judge any threat intelligence training by one test: does it make you produce and defend written judgments, or does it only teach you to recognize the right answer?
How to Choose CTI Training by Career Stage
New to security. Do not start with a CTI certification. Most CTI courses, ours included, assume you already know what phishing, malware, a SOC and a log look like. Get the fundamentals from any solid course first, then use the free CTI material below to find out whether you like the work before you pay for anything. Our guide on how to become a threat intelligence analyst covers the wider route, including the jobs that hire juniors.
SOC or incident response analyst moving over. You already have the part most beginners lack: you have seen real alerts and real intrusions. What you are missing is the intelligence half. That means requirements, source grading, structured analysis and writing for someone who is not technical. A structured course with graded written work pays off fastest for you. The SOC analyst vs CTI analyst comparison explains why this is the most common on-ramp into CTI.
Working CTI analyst. You need depth, a specialism and proof you can show. This is where employer-funded courses like SANS FOR578 and the senior certifications make sense, and where a public body of written work starts to matter more than any course.
Free Threat Intelligence Training Worth Your Time
A good free threat intelligence course is not a consolation prize. Some of the best CTI teaching material in existence costs nothing. These are the ones we would point a junior analyst to, in roughly this order.
MITRE ATT&CK CTI Training. Free, from the ATT&CK team. MITRE describes it as five modules of videos and exercises, designed to take about four hours, solo or as a team. You map behaviors from finished reports (a guided exercise on Cybereason's Cobalt Kitty report and an unguided one on FireEye's APT39 report, both with answer sets), then from raw incident tickets, then compare groups in ATT&CK Navigator and turn the result into defensive recommendations. Two caveats sit on the page itself: it assumes you already know ATT&CK (MITRE points you to its ATT&CK Fundamentals training first), and the exercises were built on ATT&CK v8, so use that version if you want your answers to match.

Figure 1: Notice what the free MITRE course asks of you: map real reports, store and compare the mappings, then make defensive recommendations. That last step matters: over half of the CTI job postings we analyzed expect you to connect findings to detection or response work. Source: CTI Training, MITRE ATT&CK, captured 2026-09-28.
FIRST CTI SIG curriculum. FIRST, the Forum of Incident Response and Security Teams, publishes a free curriculum from its Cyber Threat Intelligence SIG. It is reading, not a course, but it covers the concepts beginners often get wrong: priority intelligence requirements, source evaluation and information reliability, human and machine analysis techniques, threat modelling, standards and a glossary. Its guidance on communicating uncertainty in CTI reporting is worth reading twice. FIRST also maintains the Traffic Light Protocol, which we explain in our TLP 2.0 guide.

Figure 2: The FIRST CTI SIG curriculum reads like a syllabus for the thinking half of the job: methodology, source reliability, analysis techniques, threat modelling and how to express uncertainty. None of it depends on a vendor tool. Source: Curriculum, Cyber Threat Intelligence SIG, FIRST, captured 2026-09-28.
arcX Cyber Threat Intelligence 101. A free, self-paced beginner course from a CREST-accredited training provider: 4+ hours of content including 2.5+ hours of video, 100+ practice questions and a final micro exam. Pass it and arcX awards its Foundation Level Threat Intelligence Analyst (FTIA) certification. arcX describes it as a deliberately basic, theory-first introduction for someone deciding whether a CTI career suits them, and it frames law and ethics from a UK analyst's point of view.
Mandiant Academy free on-demand courses. Mandiant's free cyber defense series includes an on-demand session, "Intelligence is the guiding light," on how threat intelligence drives the other defense functions, and the Mandiant Academy page offers a free preview of three of its threat intelligence courses on sign-up. Useful for a feel of how a large intelligence team thinks, not a full course.
TryHackMe's Cyber Threat Intelligence module. Rooms on CTI basics, CTI for alert triage, MISP, OpenCTI and a campaign-reconstruction exercise. Most of it is paid: when we checked on 28 September 2026, TryHackMe's own room data marked only the Intro to Cyber Threat Intel room (rated Easy, 45 minutes) as free to use; the OpenCTI room page said it was only available to Premium or Max subscribers, and the other three rooms were not flagged as free either. Good for tool familiarity if you come from the SOC side and already have a subscription.
Recorded Future University. Its Intelligence Fundamentals Certification path is listed as free to register: four short lessons (the last one on Recorded Future's browser extension) ending in an Intelligence Fundamentals badge, open to non-customers through a free browser-extension account. The full catalog requires a Recorded Future platform license, and much of it teaches the product. Worth it if your employer runs Recorded Future; otherwise treat it as a sampler.
Free reading. If you searched for threat intelligence ebooks, start with the one CREST lists in the recommended reading for all three of its CTI exams: Richards J. Heuer Jr.'s Psychology of Intelligence Analysis (1999), a free 214-page PDF from the CIA's Center for the Study of Intelligence. In our view it is still the best free text on cognitive bias written for analysts. Our ranked list of threat intelligence books covers what to read after it.
Paid Cyber Threat Intelligence Courses
Paid training earns its price in three ways: realistic data to work on, someone grading your output, and a credential at the end. Here is what the main options offer, in the providers' own terms.
SANS FOR578: Cyber Threat Intelligence. Probably the best-known cyber threat intelligence course, and the highest published price in this guide. Six days instructor-led or 36 hours self-paced with four months of access, rated intermediate, with 20 hands-on labs and a team capstone that turns a single intrusion into a campaign assessment. The labs are the point: building a collection plan, pivoting on domains and TLS certificates, storing threat data in MISP, analysis of competing hypotheses, writing YARA rules, and a lab called Operational Writing. SANS says the course is built around the GCTI exam objectives. On 28 September 2026 the OnDemand and US listings were $8,780, European events €8,230 and UK events £7,160, before local taxes, with the GIAC exam attempt as an add-on ($999 in the US listings). SANS pitches it at anyone with security training or experience who is comfortable at a Linux command line for a few labs.
SANS FOR589: Cybercrime Investigations. A specialism after the core: five days or 30 hours self-paced, intermediate, 20 labs, $8,260 in the OnDemand and US listings on 28 September 2026. It covers the cybercrime underground, dark web marketplaces and forums, and tracing cryptocurrency proceeds. Worth knowing about if your role leans toward cybercrime; no GIAC certification is listed with it.
Mandiant Academy. Its foundational cyber intelligence training course, Cyber Intelligence Foundations, runs three days in person or four days virtual and is also offered on demand. It covers the intelligence cycle, structured analytic techniques, countering bias, malware basics and writing well-structured reports, for learners who already have a working understanding of security and a general understanding of threat intelligence. Threat Intelligence and Attribution is one day in person or two virtual. Mandiant does not publish course prices on these pages; you contact Mandiant Academy or buy its Learning Pass.
arcX Practitioner and Advanced. The CPTIA-aligned Practitioner course is CREST-accredited, self-paced and intermediate: 25+ hours of content, 17+ hours of video, 48 units, 21 exercises, 500+ practice questions and an arcX exam with a free re-test, with 12 months of access. arcX's checkout sets currency and tax by visitor location: viewed from Germany on 28 September 2026 it showed about €243 before VAT (€289.44 with 19% German VAT), so check the price for your own country. The CRTIA-aligned Advanced course has 40+ hours of content and showed about €370 before VAT on the same check. arcX's FAQ on both pages says the course does not include a CREST exam voucher; you buy that separately through CREST or Pearson VUE.
EC-Council CTIA training. EC-Council's Certified Threat Intelligence Analyst program is a three-day course offered as self-study video (iLearn), live online (iWeek) or in person through training partners. EC-Council says 40% of training time is spent in labs, across 27 hands-on labs, and the syllabus runs from planning a CTI program through OSINT, HUMINT, malware analysis and Python scripting to threat hunting and CTI in SOC and incident response. On 28 September 2026, EC-Council's own iClass store listed individual prices of $1,069 for a self-paced package with one video course, labs and the exam, and $4,379 for live online or in-person training. Exam retakes on the video packages were $199.
CTI Academy is also a paid option; we cover it separately below so you can discount it properly.
CTI Certifications Compared: GCTI vs CTIA vs CREST vs Mandiant
A CTI certification does two jobs: it gets you past a filter on a job posting, and it forces you to cover a syllabus end to end. It does not prove you can do the work, and exams differ a lot in how close they get. Here are the main cyber threat intelligence analyst certifications in 2026, with the formats their owners publish.
| Certification | Owner | Price shown by owner | Time | Audience the owner describes | Exam format |
|---|---|---|---|---|---|
| GCTI | GIAC | $999 standalone attempt | 3 hours, 71% to pass | IR, threat hunters, SOC staff, experienced forensic analysts | 82 questions, multiple choice plus CyberLive hands-on lab items, proctored |
| CTIA | EC-Council | From $1,069 with training | 2 hours, 70% cut score | Mid- to high-level professionals, 2 to 3 years' experience | 50 multiple-choice questions |
| CPTIA | CREST | Set per country booking | 2 hours | Entry level, no experience required | 120 multiple-choice questions, closed book, Pearson VUE |
| CRTIA | CREST | Set per country booking | 3 hours | Two years' CTI experience expected | 120 multiple-choice plus two long-form written answers |
| CCTIM | CREST | Set per country booking | 2 x 3 hours | People leading a threat intelligence team | Short-form, long-form and scenario questions, two sessions |
| MCTIA | Mandiant | $250 per attempt | 1 hour, 70% to pass | 3 to 5 years of CTI experience recommended | Up to 50 multiple-choice questions, remote proctored |
All details from each owner's certification page, exam notes or registration page, checked 28 September 2026. EC-Council's page gives three years of experience in one place and two in its FAQ.
GCTI (GIAC). The one with a hands-on component. GIAC's CyberLive items run in real virtual machines, and GIAC says they are typically weighted more than the multiple-choice items. Paired with FOR578 it is, in our view, the most thorough route, and it is the most expensive. Our advice: take it when an employer pays; paying out of pocket early rarely makes sense.
CTIA (EC-Council). Far cheaper than the FOR578 and GCTI route as a training-plus-exam package, and broad, with scripting and threat hunting in the syllabus. The exam is multiple choice only, so it tests what you know rather than what you can produce. EC-Council describes it for professionals with a few years of experience, and the route it describes runs through its official training. Our own job-market research names GCTI and CTIA as the two CTI certifications that come up consistently.
The CREST ladder (CPTIA, CRTIA, CCTIM). Three levels with a clear progression. Of the exams in the table, CPTIA is the only one whose owner says outright that no prior experience is required. CRTIA and CCTIM make you write long answers, which is closer to the job than any multiple-choice paper. The track has deep UK roots: an undated training note in FIRST's CTI SIG curriculum says CRTIA was created to support analysts working on the UK's CBEST and STAR threat-led testing schemes, and CREST's own reading list for all three exams includes the Bank of England's CBEST guide. CREST's CTI credentials are valid for three years.
MCTIA (Mandiant). A short, remote, proctored exam aimed at experienced analysts, valid for three years. Mandiant says study materials are not provided before the exam and that its courses are optional preparation, not an exam review. At $250 per attempt it is the cheapest exam in the table with a published price.

Figure 3: The first column is recall only; the others make you produce something. Only GCTI puts you in a lab, and only CRTIA and CCTIM make you write at length. Rows follow the audience each owner describes (GIAC gives no years for GCTI, so its row is our reading). Exam formats from GIAC, EC-Council, CREST and Mandiant, checked 28 September 2026. Diagram: CTI Academy.
If you are deciding whether to sit one at all, this is the rule of thumb we give people. It is our judgment, not any provider's.

Figure 4: Start at the top question. If none of the jobs you want asks for a certification, the money is better spent on practice and written work. Our rule of thumb, based on the published audience for each exam. Diagram: CTI Academy.
What Employers Actually Ask For
Start with what the job postings say, because that part is data. In our analysis of 214 CTI job postings, the skills employers asked for most were communication and judgment: reporting and briefing (95%) and threat actor and campaign analysis (90%). The entry-level signal was OSINT, requested in 63% of entry-level postings but only 26% at the advanced tier, while scripting and detection engineering rose sharply with seniority. None of that is a certification.
What follows is practitioner opinion, not survey data. Our view: for a junior candidate, three good written assessments beat a certification line on a CV. A good one states the question it answers, grades its sources, gives a judgment with a stated confidence level, and ends with what a defender should do next. If you want a structure to follow, our guide on writing a threat intel report nobody ignores walks through one.
Certifications still help at two points: getting past automated filters when a posting names one, and structuring your study when you have no mentor. They matter less once someone is reading your work. For where junior roles actually are, see entry-level CTI jobs. If you are weighing a certification against pay, our threat intelligence analyst salary guide shows the ranges and treats certifications as one pay lever alongside seniority, sector, clearance and location.
A Sensible Learning Order
Put together, the order looks like this. Each stage should leave you with something written, and certifications come after you can produce the work, not before.

Figure 5: The bottom lane is the one that gets you hired. Each learning step above it should produce a piece of work, and the certification lane only starts once you have something to show. Beginners enter at stage 1, SOC and IR analysts at stage 2, working CTI analysts at stage 4. Our recommended order. Diagram: CTI Academy.
- Basics. Security fundamentals from any solid course, plus arcX CTI 101 to test your interest. Output: one-page summaries of a few public threat reports.
- CTI core, free. MITRE's ATT&CK CTI training, the FIRST CTI SIG curriculum and Heuer's book. Output: one report mapped to ATT&CK, with your reasoning.
- Practice with feedback. One structured cyber threat intelligence course with graded work or hands-on missions. Output: three short written assessments with sources graded and confidence stated.
- Proof. A public portfolio of your best writing. Sit CPTIA or CTIA only if the jobs you want ask for one.
- Specialize. FOR578, or FOR589 for cybercrime work, ideally employer-funded, and GCTI, CRTIA or MCTIA at that level. CCTIM when you lead a team.
What to Skip
- A certification before you can write one page. You may pass the exam and still stall at the interview, where someone asks you to walk through an assessment.
- Courses that are CTI in name only. Read the syllabus, not the title. If a course never asks you to grade a source or write a judgment, it is teaching something else, however it is named.
- Tool counts as a quality signal. A tool count describes breadth of coverage (EC-Council lists "200+ threat intelligence tools" for CTIA), not what you will be able to produce. In our view, learning to produce something with MISP, ATT&CK Navigator and a spreadsheet is worth more than a tour of many tools.
- Platform certifications for platforms you do not use. Recorded Future's Certified Analyst Lab, for example, is aimed at experienced users who hold a Recorded Future Threat Intelligence license. It is built for them, so it is the wrong purchase if you are not one of them.
- Exam dumps. CREST candidates sign a non-disclosure agreement before the exam, and dumps train recall, the part of this job that matters least.
- Paying SANS prices yourself at the start. FOR578 has a strong reputation, and at $8,780 in the US it is, in our experience, usually bought with an employer's training budget. It will still be there when you have one.
Where CTI Academy Fits, and Where It Doesn't
Here is our own offer, described only from what is on our public pages. The Cyber Threat Intelligence path is rated Beginner and runs in three sections that unlock in order: 16 modules with quizzes and six hands-on missions, broken into 82 steps and estimated at around 16 hours. The missions are cases worked in dialogue with a senior analyst rather than multiple-choice recall, and the path closes with a one-page assessment and a 60-second executive brief. It uses ATT&CK Navigator and small samples of endpoint, DNS, authentication and email telemetry, but does not depend on a specific SIEM or threat intelligence platform. Completing every step earns a certificate with a public verification page, and the whole path, certificate included, is free.

Figure 6: Our catalog view of the CTI path: rated Beginner, 82 steps in three sections, about 16 hours, ending in a certificate. Note the line above it: sections unlock as you complete them, so the path is meant to be worked in order. Source: Cyber Threat Intelligence Learning Paths, CTI Academy, captured 2026-09-28.
On price: the Cyber Threat Intelligence path is free end to end, certificate included, with no card and no expiry. Our other paths open their first modules for free, and Premium, listed at €15.99 a month before tax on our pricing page on 28 September 2026, unlocks the rest of them along with unlimited simulator runs and the LeakLens and NullBase practice platforms. There is a €8.99 a month student rate, before tax, for verified partner-university emails.
Now the honest part. CTI Academy does not give you a proctored industry certification, so if a posting filters on GCTI, CTIA or a CREST credential, our certificate will not clear that filter. If you want a public instructor-led class as an individual, SANS and Mandiant Academy run them; our live and on-site training is sold through the Enterprise plan for teams. If you work in the UK on CREST-scheme engagements, the arcX and CREST route is the better fit. If your team runs Recorded Future, its own university will teach you that platform better than anyone.
Where we think we fit is stages 2 and 3 of the order above: the practice-with-feedback stretch where theory turns into judgment. Reading teaches you what a source grade is; you only get good at grading by doing it on cases where the answer can be wrong. If that is the gap you have, you can take the Cyber Threat Intelligence learning path for free, end to end, and see whether the missions work for you.
Frequently Asked Questions
What is the best cyber threat intelligence training for beginners?
Start free. MITRE's ATT&CK CTI training (about four hours), the FIRST CTI SIG curriculum and arcX's free CTI 101 course cover the core concepts without costing anything. Once you know you like the work, add one structured course with graded practice. Skip certifications until the jobs you want ask for one.
Is there a free threat intelligence course with a certificate?
Yes. arcX's Cyber Threat Intelligence 101 is free and ends with an exam that awards its Foundation Level Threat Intelligence Analyst (FTIA) certification. Recorded Future University lists its Intelligence Fundamentals Certification path as free to register, and it ends in an Intelligence Fundamentals badge. Our own Cyber Threat Intelligence path is free end to end, certificate included. None of these carries the weight of a proctored exam such as GCTI or CPTIA.
Is the GCTI certification worth it?
For a working analyst whose employer pays, usually yes, in our view: it is the only certification in our comparison with hands-on lab items, and FOR578 is built around its objectives. Paying yourself is harder to justify. On 28 September 2026, FOR578 was listed at $8,780 in the US and a standalone GCTI attempt at $999.
GCTI vs CTIA: which should I take?
GCTI tests practical skill with CyberLive lab items and suits experienced practitioners, usually with employer funding. EC-Council's CTIA costs far less as a training-plus-exam package, uses a multiple-choice-only exam and is aimed at professionals with a few years of experience, with the route running through official training. Our job-market research names both as the CTI certifications that come up consistently; check which one the jobs you want name.
How much does a CTI certification cost?
On the owners' own pages on 28 September 2026: a standalone GIAC GCTI attempt was $999, Mandiant's MCTIA exam $250 per attempt, and EC-Council's CTIA came bundled with training from $1,069 on its iClass store. CREST sets CPTIA, CRTIA and CCTIM prices per country booking through Pearson VUE.
Do I need a certification to get a threat intelligence job?
Not usually, in our experience. In the 214 CTI job postings we analyzed, the most-requested skills were reporting and briefing (95%) and threat actor analysis (90%). A certification helps when a posting names one or an automated filter screens for it. In our view, a portfolio of written assessments is what carries you through the interview.
What is the CREST CPTIA?
The CREST Practitioner Threat Intelligence Analyst is CREST's entry-level CTI exam: 120 multiple-choice questions in two hours, closed book, at Pearson VUE centers, with no required prior experience. It is the first step on CREST's ladder, followed by CRTIA and CCTIM, and it is valid for three years.
How long does cyber threat intelligence training take?
The courses themselves are short: about four hours for MITRE's ATT&CK CTI training, around 16 hours for our CTI path, 25+ hours for arcX Practitioner and six days or 36 hours for SANS FOR578. Becoming job-ready takes longer, because the skill that gets you hired, writing defensible assessments, only improves with repeated practice and feedback.
Sources
Free training and reading - MITRE ATT&CK: CTI Training - FIRST: Cyber Threat Intelligence SIG curriculum - FIRST: CTI SIG curriculum, Training - arcX: Cyber Threat Intelligence 101 - Mandiant Academy: Free cyber defense training - Mandiant Academy overview - TryHackMe: Cyber Threat Intelligence module - TryHackMe: Intro to Cyber Threat Intel room - TryHackMe: OpenCTI room - Recorded Future University - Recorded Future University: Intelligence Fundamentals Certification path - CIA Center for the Study of Intelligence: Psychology of Intelligence Analysis
Paid courses - SANS: FOR578 Cyber Threat Intelligence - SANS: FOR589 Cybercrime Investigations - Mandiant Academy: Cyber Intelligence Foundations - Mandiant Academy: Threat Intelligence and Attribution - arcX: Cyber Threat Intelligence Practitioner - arcX: Advanced Cyber Threat Intelligence Analyst - EC-Council: Certified Threat Intelligence Analyst (CTIA) - EC-Council iClass: CTIA training packages - Recorded Future: Certified Analyst Lab
Certifications - GIAC: Cyber Threat Intelligence (GCTI) - GIAC: Certification pricing and fees - GIAC: CyberLive hands-on testing - CREST: Practitioner Threat Intelligence Analyst (CPTIA) - CREST: CPTIA Notes for Candidates (PDF) - CREST: Registered Threat Intelligence Analyst (CRTIA) - CREST: CRTIA Notes for Candidates (PDF) - CREST: Certified Threat Intelligence Manager (CCTIM) - CREST: CCTIM Notes for Candidates (PDF) - Mandiant Academy: Cyber Threat Intelligence Analysis certification - Mandiant Academy: MCTIA registration - Mandiant Academy: MCTIA exam guide (PDF)
Market data - SANS: 2026 Cyber Threat Intelligence Survey, key findings - CTI Academy: The CTI & EASM Job Market in 2026 - CTI Academy: Pricing