Cyber Threat Intelligence
BeginnerLearn Cyber Threat Intelligence (CTI) analyst tradecraft from the first intelligence requirement to a defensive handoff. You will build PIRs, grade sources, work with OSINT and human reporting, use MITRE ATT&CK, the Diamond Model and the Cyber Kill Chain, track threat actors and campaigns without forcing attribution, manage IOC context, write assessments, and turn external intelligence into questions a SOC or incident response team can test. The curriculum was reviewed against roughly 1,000 job-market observations and a detailed sample of current CTI role descriptions, then checked against real analyst workflows and documented incidents. Three sections, 76 lessons, and six case-based missions.

Curriculum
9 more steps behind a free account
Free account
Ready to start Cyber Threat Intelligence?
Create a free account to open the remaining 9 steps, track every one you finish and earn your certificate.
- Free to start
- Progress saved on every step
- Certificate on completion
Already have an account? Sign in
About this path
Most threat intelligence work does not fail because the analyst found too little. It fails because the work was aimed at nobody in particular, arrived after the decision had closed, or stopped at a list of indicators without explaining what anyone should do next. This path starts with the analyst's real job: turning a question into a defensible judgement for a named consumer.
The curriculum was reviewed against roughly 1,000 job-market observations and a detailed sample of current Cyber Threat Intelligence role descriptions. The recurring themes were clear: intelligence requirements, source evaluation, threat actor and campaign analysis, MITRE ATT&CK, reporting and briefing, IOC context, and the ability to connect external intelligence to internal defensive work. Those market signals were used as a scope check, not as a keyword list, and the lessons stay grounded in analyst workflows and documented incidents.
The first section builds the intelligence process and the models underneath it. You turn vague questions into PIRs, build collection plans, grade sources, work through the Cyber Kill Chain, Diamond Model and MITRE ATT&CK, and learn where open, human and internal telemetry fit. The second section moves into collection and source work, including OPSEC, OSINT and human reporting, with missions that make you hold the legal and analytical boundary while you investigate.
The third section is where the pieces have to work together. You test competing hypotheses, track campaigns without forcing attribution, manage IOC context, run collection as a standing capability, work a phishing case into a campaign cluster, and turn external intelligence into a testable internal hypothesis for SOC, incident response or hunting teams. The path closes with a one-page assessment and a short executive brief, so the final product is not just something you found, but something another person can act on.
It assumes you already know roughly what phishing, malware, a SOC and a security log are. If those are new, start with Cybersecurity Foundations and come back. You do not need to be working in a security team to complete the path, and the exercises include public-data versions when internal telemetry is not available.
What you will learn
- Tell intelligence from information. Name the reader and the decision behind any product, and recognise when you have written neither.
- Run the intelligence cycle end to end. Turn a vague question into a priority intelligence requirement, build a collection plan from it, and record its gaps honestly.
- Grade what you read. Apply the Admiralty Code so source reliability and claim credibility stop being the same judgement.
- Place an intrusion on three models. Use the Kill Chain for when, the Diamond Model for what connects, and MITRE ATT&CK for what to call it, and know which question each answers.
- Rank indicators by what they cost the adversary. Use the Pyramid of Pain to explain why a wall of blocked hashes stops nobody who matters.
- Work without breaking the law or your own case. Know where authorisation ends, which lawful substitute answers the same question, and how to keep notes that survive a challenge six months later.
- Build and run a separate research environment. A disposable virtual machine, traffic separation, and a handling routine for malicious files that does not announce you to the sender.
- Track campaigns without forcing attribution. Separate a threat actor from a campaign, activity cluster and intrusion set, compare vendor naming through evidence, and leave the actor unknown when the record does not support a name.
- Manage an IOC as evidence with a lifecycle. Carry provenance, first and last seen, confidence, scope, action and a review point beside an indicator so stale or shared infrastructure does not become a permanent false positive.
- Deliver intelligence that defenders can test. Turn an external finding into a testable internal hypothesis, name the telemetry and team that can confirm or weaken it, then finish with a one-page assessment and a 60-second brief.
Who this path is for
- Anyone moving into threat intelligence from a SOC, IT, or another analytical field, who can already read a security alert but has never been handed a requirement.
- Students and career changers who have finished Cybersecurity Foundations and want the analytical half rather than more tooling.
- Working analysts who were given a threat intel job title without ever being taught the cycle, source grading, or the models underneath it.
- Security leads who commission intelligence and want to know what a good product looks like before they pay for another feed.
Guides for this path
- The CTI & EASM Job Market in 2026: What 1,000 Job Postings Actually ShowWe scanned 1,000 cybersecurity job postings and went deep on 214 CTI and 54 EASM listings to find out what employers actually ask for. Here's the skill data, the salary ranges, and what it means for anyone deciding where to start.
- Infostealer Malware, Explained: How Stolen Logs Get UsedAn infostealer does not break anything, it runs once, copies what the browser already remembered, and leaves. The file it produces, a stealer log, is worth more to the criminal economy than the access it had. How the chain works, why the Lumma takedown didn't hold, and why a password reset is not enough.
- Living Off the Land: Why Attackers Prefer Your Own Windows ToolsThere is no malware in a living off the land intrusion. No implant, no dropper, no new file for antivirus to recognise. The intruder signs in with a working password and runs the same programs your administrators run all day, every one written and signed by Microsoft, and on the disk long before anyone attacked anything. CrowdStrike counted 82 percent of its detections in 2025 as malware-free, up from 51 percent in 2020.
- Entry-Level CTI Jobs: Where to Find Them and How to Land OneNinety percent of organizations now have dedicated threat intelligence resources, and most of those teams run on four or fewer analysts. That gap between demand and headcount is why entry-level threat intelligence jobs exist almost everywhere but rarely carry the title you'd search for. This guide covers the seven employer categories that actually hire juniors, the job titles that hide CTI work, and what gets an application shortlisted instead of filtered.
- SOC Analyst vs CTI Analyst: Which Cybersecurity Career Fits You?Ask ten CISOs where they started, and eight will say some version of a security operations center. SOC analyst and CTI analyst are not a fork in the road, they are two seats on the same team, and one is the most common on-ramp to the other. Here is the honest comparison: salary, mindset, burnout, and the career path between the two roles.
- Traffic Light Protocol (TLP 2.0), ExplainedThe fastest way to get quietly cut out of an information sharing community is not leaking something. It is mislabeling it. The Traffic Light Protocol exists to prevent exactly that: four short labels, standardized as TLP 2.0 by FIRST, that tell a recipient how far they may pass something on.
Frequently asked questions
Cybersecurity Foundations first if you are new. This path assumes you already recognise phishing, malware, a SOC and a hash, and it teaches everything specific to intelligence from scratch. If those four are familiar you can start here.
No. Every lesson closes with an exercise, and each one has a version you can run on public reporting from your own machine if you do not yet have a team, a ticket queue or logs of your own.
Almost none of it. You will use ATT&CK Navigator and read small samples of endpoint, DNS, authentication and email telemetry, but the path does not depend on a specific SIEM, TIP or detection platform. The reasoning should still hold when the organisation changes tools.
Cases you work through in dialogue with a senior analyst, using what the preceding lessons taught. They are not multiple-choice recall exercises. You grade a source, spot the missing line in a judgement, refuse unauthorised access, place an intrusion on three models, and close the final case with a one-page assessment and a 60-second executive brief.
It will teach you to separate actors, campaigns, activity clusters and intrusion sets, compare vendor naming through evidence, and understand where attribution becomes fragile. You will learn to build a useful campaign profile with the adversary still unknown, because naming a group on thin evidence is a habit this path is designed to break.
Around sixteen hours if you complete the lessons, exercises and missions rather than only reading the pages. The estimate includes the new campaign analysis, IOC lifecycle and operational handoff work, and it will be refined as mission timing data improves.
The curriculum was reviewed against roughly 1,000 job-market observations and a detailed sample of current CTI role descriptions, then compared with the work analysts actually have to perform. We published the full skill-frequency and salary data as "The CTI & EASM Job Market in 2026: What 1,000 Job Postings Actually Show" on the CTI Academy blog. The market review was used to check coverage and priority, not to turn job-ad keywords into lessons, so the path still teaches the reasoning and tradecraft underneath the role.