Learning Paths

Guided routes that put modules, missions and simulator practice in the order they make sense. Sections unlock as you complete them, and every path ends with a verifiable certificate.

7 paths

Learn Cyber Threat Intelligence (CTI) analyst tradecraft from the first intelligence requirement to a defensive handoff. You will build PIRs, grade sources, work with OSINT and human reporting, use MITRE ATT&CK, the Diamond Model and the Cyber Kill Chain, track threat actors and campaigns without forcing attribution, manage IOC context, write assessments, and turn external intelligence into questions a SOC or incident response team can test. The curriculum was reviewed against roughly 1,000 job-market observations and a detailed sample of current CTI role descriptions, then checked against real analyst workflows and documented incidents. Three sections, 76 lessons, and six case-based missions.

89 steps3 sections~16 hrsCertificate
Start path
01CTI Fundamentals and Frameworks6 modules · 2 missions · 1 simulator
02Core Analyst TradecraftUnlocks after the previous section3 modules · 2 missions
03Applied Analyst TradecraftUnlocks after the previous section7 modules · 2 missions
Certificate of completionFull curriculum and details

Learn the fundamentals every other CTI Academy path assumes you already have: what a threat, an asset and a vulnerability actually are, how the CIA triad and defense-in-depth hold together, how attackers actually get in through malware and social engineering, and how Linux becomes a daily analysis tool rather than a list of commands to memorise. You will work through core information security concepts, then spend three sections on grep, awk, sed, log analysis, process and network investigation, and bash automation using real-looking incident data. Four sections, 58 lessons, and four case-based missions.

62 steps4 sections~14 hrsCertificate
Start path
01Information Security Foundations4 modules
02Linux Fundamentals and Text ProcessingUnlocks after the previous section5 modules · 1 mission
03Linux Log and File System AnalysisUnlocks after the previous section2 modules · 1 mission
04Linux Process, Network and AutomationUnlocks after the previous section4 modules · 2 missions
Certificate of completionFull curriculum and details

Learn Open Source Intelligence (OSINT) as an investigation process, not a list of tools. Plan collection, search across people, domains, DNS, certificates, images, phone numbers and public records, verify sources, preserve evidence, and write findings for Cyber Threat Intelligence, fraud and digital risk work. The path also covers research OPSEC, isolated workstations and research personas so the investigation does not point back to you. Four sections, 42 lessons, and five case-based investigations.

47 steps4 sections~10 hrsCertificate
Start path
01What Open Source Intelligence Is2 modules · 1 mission
02Working SafelyUnlocks after the previous section3 modules · 1 mission
03Collection on the Open WebUnlocks after the previous section3 modules · 2 missions
04Verification and ReportingUnlocks after the previous section2 modules · 1 mission
Certificate of completionFull curriculum and details

Work human sources for cyber threat intelligence (HUMINT): what a person tells you, what their position actually lets them know, and what you are authorised to do about it. You separate a claim from an observation, grade the source and the claim as two different judgements, test whether several accounts are one route counted twice, run a research persona inside a community without leading it back to you, and write the collection note another analyst can still use after you have gone. Four sections, 53 lessons, and eight missions.

56 steps4 sections~13 hrsCertificate
Start path
01Human Source Collection in CTI4 modules · 1 mission
02Evaluating Human ReportingUnlocks after the previous section4 modules · 2 missions
03Research Personas and Controlled EngagementUnlocks after the previous section3 modules
04Digital Elicitation, Debriefing and ReportingUnlocks after the previous section3 modules
Certificate of completionFull curriculum and details

Learn Attack Surface Management (ASM) as an operational discipline, not a scanner report. You will discover an organisation's external footprint through DNS, WHOIS, certificate transparency and cloud storage, verify what a scan actually proves versus what it merely returns, enumerate subdomains passively and actively, spot subdomain takeovers and shadow IT before an attacker does, and turn a raw asset list into a prioritised, owner-assigned remediation queue. The curriculum was reviewed against a detailed sample of roughly 54 EASM and exposure-management job descriptions inside a wider 1,000 job-market scan, then checked against real reconnaissance and exposure workflows. Four sections, 63 lessons, and four case-based missions.

67 steps4 sections~13 hrsCertificate
Start path
01Attack Surface Management Foundations3 modules · 1 mission
02Domain and Ownership IntelligenceUnlocks after the previous section3 modules · 1 mission
03Infrastructure DiscoveryUnlocks after the previous section6 modules · 1 mission
04Port Scan and Service DetectionUnlocks after the previous section2 modules · 1 mission
Certificate of completionFull curriculum and details

Take one domain or one address and turn it into a verified picture of the infrastructure behind it. This path works the public record layer in depth, which means reading a DNS answer rather than running a lookup, reading a certificate rather than checking that it is valid, and dating a change rather than describing a state.

59 steps6 sections~6 hrsCertificate
Start path
01Records, Registration and History2 modules · 2 missions
02Mapping Internet Presence and OwnershipUnlocks after the previous section2 modules · 2 missions
03Identity and Account CorrelationUnlocks after the previous section1 module
04Fingerprinting What You FoundUnlocks after the previous section2 modules · 1 mission
05The Archived and the Visual WebUnlocks after the previous section2 modules
06Collection at ScaleUnlocks after the previous section2 modules
Certificate of completionFull curriculum and details

Learn threat actor profiling and attribution: grade evidence, weigh competing hypotheses, and state confidence you can defend. You work an unnamed activity cluster through infrastructure, behaviour and underground persona analysis, decide what the evidence actually supports about the operator, and write an actor intelligence product a decision maker can act on. The path teaches the refusal as well as the claim: when the evidence will not carry a name, saying so is the finding. Four sections, 38 lessons, 190 quizzes and seven hands-on missions on live investigation surfaces.

45 steps4 sections~10 hrsCertificate
Start path
01Attribution Discipline3 modules · 2 missions
02Technical CorrelationUnlocks after the previous section2 modules · 1 mission
03Behavioral & Identity CorrelationUnlocks after the previous section2 modules · 2 missions
04Actor Intelligence ProductUnlocks after the previous section2 modules · 2 missions
Certificate of completionFull curriculum and details

More paths on the way

New guided paths are in production and show up here the day they ship.