Begin Your Cybersecurity Journey With Threat Intelligence Essentials
The Threat Intelligence Essentials course equips learners with a strong technical foundational knowledge of threat intelligence concepts and tools. It provides essential knowledge in topics like cyber threat landscape, types of threat landscape, and more preparing you for progressive career paths as a threat intelligence analyst. No IT/Cybersecurity experience required for this course.
Test your learnings with CTF-based Capstone Projects and validate your newly acquired skills in proctored exams. Further, the course offers 18+ hours of premium self-paced video training in 10 modules with 5 labs to prepare students for real-world problems.
Program Information
Download the brochure to discover how this comprehensive course can equip you with the essential technical skills and foundational knowledge to get started in the field of threat intelligence. Learn about the distinct types of threat intelligence and their pivotal role in regulatory compliance and risk management. Prepare yourself for rewarding job roles such as a Security Operations Center (SOC) Analyst, Threat Intelligence Analyst, Cybersecurity Analyst, and more.
What Skills You’ll Learn
- Essential threat intelligence terminology, the role of intelligence in cybersecurity, and threat intelligence maturity models.
- Evaluating different types of threat intelligence, such as strategic, operational, and more focused forms, which guide vulnerability management or regulatory landscapes.
- The cyber threat landscape, trends, and ongoing challenges
- Data collection and sources of threat intelligence
- Threat Intelligence Platforms (TIPs)
- Threat intelligence analysis
- Threat hunting and detection
- Threat intelligence sharing and collaboration
- Threat intelligence in incident response
- Future trends and continuous learning
Course outline
Module 01: Introduction to Threat Intelligence
- Students will install the DetectionLab Security Operations Center (SOC) virtual environment. This Detection Lab environment will assist students in completing hands-on threat intelligence exercises found in Modules 3, 6, and 7.
- Students will learn fundamental principles and terminology, allowing them to quickly identify, separate, and act upon useful threat intelligence.
- Students will better understand threat intelligence’s role in enhancing a cybersecurity function, maximizing organizational value, and implementing frameworks to increase threat intelligence effectiveness.
- Students will install a defensive cybersecurity lab environment that will be useful throughout this program and as they advance further in their cybersecurity or threat intelligence careers.
- Threat Intelligence and Essential Terminology
- Key Differences Between Intelligence, Information, and Data
- The Importance of Threat Intelligence
- Integrating Threat Intelligence in Cyber Operations
- Threat Intelligence Lifecycles and Maturity Models
- Threat Intelligence Roles, Responsibilities, and Use Cases
- Using Threat Intelligence Standards or Frameworks to Measure Effectiveness
- Establishing SPLUNK Attack Range for Hands-on Experience
Module 02: Types of Threat Intelligence
Students will further understand how various sources generate threat intelligence and how it informs downstream cybersecurity
processes or compliance functions.
- Students will be able to articulate and explain the core differences between types of threat intelligence.
- Students will understand how threat intelligence is created and how it impacts regulatory decisions or essential cybersecurity controls.
- After completing this section, students will be able to comprehend the importance of various threat intelligence types and how to effectively select or integrate appropriate threat intelligence into specific business processes or situational scenarios.
- Understanding the Different Types of Threat Intelligence
- Preview Use Cases for Different Types of Threat Intelligence
- Overview of the Threat Intelligence Generation Process
- Learn How Threat Intelligence Informs Regulatory Compliance
- Augmenting Vulnerability Management with Threat Intelligence
- Explore Geopolitical or Industry Related Threat Intelligence
- Integrating Threat Intelligence with Risk Management
Module 03: Cyber Threat Landscape
- Previewing MITRE ATT&CK in DetectionLab
- Indicators of Compromise Overview in DetectionLab
- Students will learn the key concepts surrounding cyber threats and how to define them.
- Students will understand how threat actors, attack vectors, vulnerabilities, and exploits generate Indicators of Compromise (IoC) and how emerging technologies can complicate defensive efforts.
- After completing this section, students will be able to understand cyber threat actor profiles, their operational models, telemetry generated by threat actors, and how IoCs inform threat intelligence efforts.
- Overview of Cyber Threats Including Trends and Challenges
- Emerging Threats, Threat Actors, and Attack Vectors
- Deep Dive on Advanced Persistent Threats
- The Cyber Kill Chain Methodology
- Vulnerabilities, Threat Actors, and Indicators of Compromise (IoC)
- Geopolitical and Economic Impacts Related to Cyber Threats
- How Emerging Technology is Impacting the Threat Landscape
- MITRE ATT&CK & Splunk Attack Range IOC Labs
Module 04: Data Collection and Sources of Threat Intelligence
- Registering for MS-ISAC, Center for Internet Security (CIS) and other Threat Intelligence Advisories
- Methodologies & Techniques for Conducting OSINT Investigations with TraceLab
- Students will learn how to assess threat intelligence sources for credibility, different data collection methods, and concepts useful for managing threat intelligence data.
- Students will be introduced to several direct and indirect threat intelligence collection methods, such as OSINT, HUMINT, and IoC analysis.
- After completing this section, students will gain competence in directly assessing threat intelligence data sources, acquiring reputable threat intelligence, focusing data collection efforts, and exploiting useful elements from acquired threat intelligence.
- Making Use of Threat Intelligence Feeds, Sources, and Evaluation Criteria
- Overview of Threat Intelligence Data Collection Methods and Techniques
- Compare and Contrast Popular Data Collection Methods
- Bulk Data Collection Methods and Considerations
- Normalizing, Enriching, and Extracting Useful Intelligence from Threat Data
- Legal and Ethical Considerations for Threat Data Collection Processes
- Threat Data Feed Subscription and OSINT Labs
Module 05: Threat Intelligence Platforms
- Accessing and Searching for IoC data in AlienVault Open Threat Exchange
- Setting up and Deploying MISP to enrich threat intelligence data
- Students will learn how to leverage external or internal Threat Intelligence Platforms (TIPs) to gather actionable data to reduce their attack surface.
- Students will be introduced to data management concepts for threat intelligence to drive efficiencies and effective use of threat intelligence received from TIPs.
- After completing this section, students will gain competence in accessing and directly leveraging TIPs for threat hunting, cybersecurity risk validation, and data aggregation or information sharing purposes.
- Introduction to Threat Intelligence Platforms (TIPs), Roles, and Features
- Aggregation, Analysis, and Dissemination within TIPs
- Automation and Orchestration of Threat Intelligence within TIPs
- Bulk Data Collection Methods and Considerations
- Evaluating and Integrating TIPs into Existing Cybersecurity Infrastructure
- Collaboration, Sharing, and Threat Hunting Features of TIPs
- Customizing TIPs for Organizational Needs
- Using TIPs for Visualization, Reporting, and Decision Making
- AlienVault OTX and MISP TIP Platform Labs
Module 06: Threat Intelligence Analysis
- Generating and Reviewing TTP data in DetectionLab
- Building a sample Threat Actor Profile
- Students will learn the importance and differences of threat intelligence data analysis methods.
- Students will learn how to correlate, enrich, and build essential reporting metrics around acquired threat intelligence.
- After completing this section, students will acquire hands-on experience with identifying relevant threats in their environment, communicating threat actor data using key metrics, and focusing defensive efforts using actionable threat intelligence.
- Introduction to Data Analysis and Techniques
- Applying Statistical Data Analysis, Including Analysis of Competing Hypothesis
- Analysis Methods for Threat Actor Artifacts
- Threat Prioritization, Threat Actor Profiling, and Attribution Concepts
- Leveraging Predictive and Proactive Threat Intelligence
- Reporting, Communicating, and Visualizing Intelligence Findings
- Threat Actor Profile Labs and MISP Report Generation Lab
Module 07: Threat Hunting and Detection
This section will provide an operational overview of Threat Hunting, contemporary threat hunting methodologies, and tools or techniques students can leverage to perform hypothesis-driven threat hunts.
Labs:
- Conducting a guided Threat Hunt in DetectionLab
Module Objectives:
- Students will learn core threat-hunting terminology, methods, and frameworks used to conduct threat hunts.
- Students will learn how threat hunting may be achieved through monitored endpoint solutions and/or across a network.
- After completing this section, students will gain direct experience in developing and executing threat-hunting hypotheses to drive proactive cybersecurity processes within an organization.
Topics Covered:
- Operational Overview of Threat Hunting and Its Importance
- Dissecting the Threat Hunting Process
- Threat Hunting Methodologies and Frameworks
- Explore Proactive Threat Hunting
- Using Threat Hunting for Detection and Response
- Threat Hunting Tool Selection and Useful Techniques
- Forming Threat Hunting Hypotheses for Conducting Hunts
Module 08: Threat Intelligence Sharing and Collaboration
This section will discuss the benefits of threat intelligence information sharing, platforms used to share industry-specific threat intelligence, and the cybersecurity or regulatory concerns that influence information sharing.
Labs:
- Sharing Threat Intelligence using the Anomali Platform
Module Objectives:
- Students will learn how proper information sharing can decrease the cybersecurity attack surface for organizations.
- Students will be introduced to threat intelligence information-sharing platforms, products, and techniques.
- After completing this section, students will understand how to properly share or receive shared threat intelligence using available open-source or free platforms.
Topics Covered:
- Importance of Information Sharing Initiatives in Threat Intelligence
- Overview of Additional Threat Intelligence Sharing Platforms
- Building Trust Within Intelligence Communities
- Sharing Information Across Industries and Sectors
- Building Private and Public Threat Intelligence Sharing Channels
- Challenges and Best Practices for Threat Intelligence Sharing
- Legal and Privacy Implications of Sharing Threat Intelligence
- Sharing Threat Intelligence Using MISP and Installing Anomali STAXX
Module 9: Threat Intelligence in Incident Response
- Accessing and Searching for IoC data in AlienVault Open Threat Exchange
- Setting up and Deploying MISP to enrich threat intelligence data
- Students will learn how to leverage external or internal Threat Intelligence Platforms (TIPs) to gather actionable data to reduce their attack surface.
- Students will be introduced to data management concepts for threat intelligence to drive efficiencies and effective use of threat intelligence received from TIPs.
- After completing this section, students will gain competence in accessing and directly leveraging TIPs for threat hunting, cybersecurity risk validation, and data aggregation or information sharing purposes.
- Introduction to Threat Intelligence Platforms (TIPs), Roles, and Features
- Aggregation, Analysis, and Dissemination within TIPs
- Automation and Orchestration of Threat Intelligence within TIPs
- Bulk Data Collection Methods and Considerations
- Evaluating and Integrating TIPs into Existing Cybersecurity Infrastructure
- Collaboration, Sharing, and Threat Hunting Features of TIPs
- Customizing TIPs for Organizational Needs
- Using TIPs for Visualization, Reporting, and Decision Making
- AlienVault OTX and MISP TIP Platform Labs
Module 10: Future Trends and Continuous Learning
- Students will learn about emerging technologies that are impacting the threat intelligence community, core security processes, and technology frameworks like IoT.
- Students will get an overview of threat intelligence career paths, approaches to ongoing professional development, and engagement with the broader threat intelligence community.
- After completing this section, students will understand future risks and technologies impacting the threat intelligence community and educational approaches they can adopt to keep pace with this fast-moving industry.
- Emerging Technologies in Threat Intelligence
- Evolution of Threat Intelligence in Response to Advanced Threats
- Threat Intelligence for Emerging Technologies
- The Role of Threat Intelligence in Evolving Cyber Threats
- The Convergence of Threat Intelligence and Risk Management
- Importance of Continuous Learning and Professional Development in Threat Intelligence
- Career Paths and Opportunities in the Threat Intelligence Field
- Anticipating Future Challenges and Opportunities in Threat Intelligence
- Engaging with the Threat Intelligence Community
- Keeping Up to Date with Evolving Threat Landscapes
- Ethical Considerations in Threat Intelligence Research and Reporting
- Global and Regional Threat Intelligence Trends and Challenges
- The Role of Threat Intelligence in National Security and Defense
- The Influence of Threat Intelligence on Cybersecurity Regulations





