Human Source Collection for CTI
IntermediateWork human sources for cyber threat intelligence (HUMINT): what a person tells you, what their position actually lets them know, and what you are authorised to do about it. You separate a claim from an observation, grade the source and the claim as two different judgements, test whether several accounts are one route counted twice, run a research persona inside a community without leading it back to you, and write the collection note another analyst can still use after you have gone. Four sections, 53 lessons, and eight missions.

Curriculum
6 more steps behind a free account
Free account
Ready to start Human Source Collection for CTI?
Create a free account to open the remaining 6 steps, track every one you finish and earn your certificate.
- Free to start
- Progress saved on every step
- Certificate on completion
Already have an account? Sign in
About this path
Human source collection in cyber threat intelligence is narrower and more practical than the word HUMINT sometimes suggests. This path is not about recruiting agents, paying for access or pretending to be an intelligence service. It is about the situations cyber threat intelligence analysts actually face when useful information sits with a person rather than in a dataset: a peer analyst who answers, a broker posting in a community, an insider reporting through the right channel, or an unsolicited contact who claims to know more than you do.
The first section builds the vocabulary that keeps human reporting usable. A claim, an observation and a judgment are different things. Access and placement tell you what a person could plausibly know, while reliability is a judgement about the person, not about the thing they just said. You then take an existing intelligence requirement and narrow it into questions a specific source or population could answer without exposing more than the collection objective allows.
The second section is about source evaluation and corroboration. You grade the source and the information separately, reconstruct whether several voices are actually one route, compare conflicting accounts and test human reporting against technical evidence. It also covers the harder cases, including exaggeration, dangles, self-interest and the point where distortion entered the chain between source, collector and analyst.
The third section moves into research personas and controlled digital engagement. You decide which layer of an underground community can actually reach the requirement, build only the persona details the objective needs, manage correlation risk and work inside a written authorization with a clear stop condition. A persona is not built to look convincing for its own sake. It is built to collect without exposing the analyst, the organisation or the requirement.
The final section turns collection back into intelligence. You apply elicitation in asynchronous conversations, manage what each question reveals, task and debrief without writing the answer into the exchange, and produce a human source collection note that another analyst can use months later. The path closes by fusing human reporting with other evidence and turning it into a written assessment and a short briefing without making the conclusion sound more certain than the evidence supports.
Eight missions run across the four sections. They use worked exchanges, records and lab scenarios so you can practise the decisions without contacting real criminals or running live source operations.
What you will learn
- Separate a claim from an observation from a judgment. Keep the three on different lines in the note, so a cold reader can tell what the source said from what you saw and what you concluded.
- Read access and placement before credibility. Work out what a person could plausibly know from where they stand, and tell a first-hand position from a fluent retelling three hands away.
- Grade the source and the claim separately. Apply reliability to the person and credibility to the thing they just said, and write down why, so the grade survives without you.
- Count routes rather than voices. Trace several accounts back to the thread they all read, and recognise when four handles agreeing is one route counted four times.
- Recognise reporting shaped by the reporter. Find the part of a story the source needs you to believe, test that part specifically, and tell exaggeration and self interest apart from fabrication.
- Run a persona that stays consistent. Build the minimum legend the objective requires, keep a ledger of what it has already claimed, and hold fields open rather than inventing detail that can later contradict you.
- Hold the posture your authorization covers. Read an authorization for its limits and its stop condition, and know which rung between passive reading and directed tasking you are standing on before the first message.
- Write a note and a brief that survive you. Produce a collection note another analyst can open cold in March, fuse it with everything else without inventing causality, and brief it shorter without making it more certain.
Who this path is for
- CTI analysts who already run the intelligence cycle and now have an actual person in front of them, with no idea what they are allowed to ask.
- SOC, incident response and security analysts moving into CTI who read underground forums daily but have never worked a source or written a source evaluation.
- OSINT practitioners who have hit the point where the public record stops and the remaining answer is held by someone rather than published.
- Digital risk and threat research practitioners handed a cyber HUMINT brief without being taught source evaluation, persona discipline or how to read an authorization.
Guides for this path
- What Is HUMINT in Cybersecurity?HUMINT, or Human Intelligence, is the collection of information through interpersonal contact and human sources. Unlike signals intercepts or satellite imagery, HUMINT relies on direct engagement between intelligence officers and individuals who possess valuable knowledge. It is the oldest form of intelligence gathering, stretching back thousands of years to the earliest recorded civilizations.
Frequently asked questions
Cyber Threat Intelligence is advisory rather than enforced. This path assumes you already know what a requirement is, what the intelligence cycle does and why a source gets graded, and it teaches everything specific to human sources from scratch. Two modules here are shared: Working Human Sources with the CTI path and Verification with the OSINT path, so if you have done either, that module is already familiar and your progress on it carries across.
No, and the line is worth drawing precisely, because the path does teach two things people associate with espionage. It teaches research personas, meaning a non-attributed account carrying only the detail a stated requirement needs, and it teaches elicitation, meaning open questions in an ordinary conversation rather than interrogation. What it does not teach is the recruitment half: turning someone into a controlled source, paying for access, or applying pressure to get an answer. Those are not merely out of scope, they are written into the lessons as stop conditions, from "coercion is where you stop" to a worked authorization that lists purchasing access and direct-messaging a seller under not allowed. Recruitment appears in this path only as adversary behaviour you read and assess.
No, and you should not. Every exercise works on material you already have or on the worked cases in the lessons. The missions are exchanges and records you answer step by step rather than live conversations, so nothing in this path asks you to contact anybody.
Most exercises have a version you can run alone. Where a lesson asks you to check something with a colleague or work under an existing authorization, there is a single-analyst route beside it, and writing the authorization you would want is itself one of the exercises.
OSINT works the record somebody left behind. This path starts where that stops, at the point where the remaining answer is held by a person who has to choose to give it to you. The verification discipline is shared, which is why one OSINT module is reused here, but evaluation, elicitation, persona consistency and authorization are specific to working with people.
Not for the lessons. All 53 of them, and every written exercise, need nothing beyond a browser and somewhere to write. Four of the eight missions run inside the lab environments and need the lab connection: Conflicting Sources, The Dangle, The Conversation and The Insider. The other four missions, and the whole of the teaching, run without it.