Certified Threat Intelligence Analyst training is EC-Council’s specialist-level program covering the complete intelligence lifecycle: direction, structured collection, analysis, and dissemination. Unlike broader security certifications, CTIA focuses specifically on turning raw threat data into decisions a security team can act on. kodestree’s version adds instructor-led labs, real threat feeds, and report-writing practice, so you leave able to brief a SOC team, not just answer exam questions.
Prerequisites
EC-Council offers two paths into the CTIA exam: completing authorized training (which satisfies eligibility automatically) or applying separately with documented experience. Before joining kodestree’s course, you should ideally have:
- At least 2 years of hands-on experience in information security, network security, or a related field
- Working knowledge of core security concepts, including malware behavior, APTs, and common vulnerabilities
- Basic networking fluency: TCP/IP, DNS, firewalls, and proxy architecture
- Familiarity with at least one SIEM, SOAR, or threat feed platform (helpful, not mandatory)
- A CEH, CND, Security+, or equivalent background is useful but not required to enroll
Course Objectives
- Explain the difference between strategic, operational, tactical, and technical threat intelligence and when to use each
- Build a threat intelligence program from requirements gathering through stakeholder reporting
- Apply MITRE ATT&CK, the Cyber Kill Chain, and the Diamond Model to real adversary behavior
- Collect and validate intelligence from OSINT, HUMINT, and closed threat feeds without drowning in noise
- Apply structured analytic techniques (ACH/SACH) to reduce analyst bias
- Package findings into STIX/TAXII-compliant reports that SOC and IR teams can act on immediately
- Hunt proactively for threats using hypothesis-driven, intelligence-led methodology
- Prepare for and sit the EC-Council CTIA (312-85) exam with confidence
What You Will Learn
- The complete threat intelligence lifecycle: direction, collection, processing, analysis, dissemination, and feedback
- How to profile adversaries and map their TTPs using MITRE ATT&CK and the Diamond Model
- Data collection from OSINT sources, dark web monitoring, malware sandboxes, and commercial threat feeds
- Cloud-native threat intelligence collection across AWS, Azure, and hybrid environments
- Structured analytic techniques used by professional intelligence analysts, not just security engineers
- Writing and disseminating intelligence reports using STIX 2.1 and TAXII 2.x standards
- Threat hunting methodology built on intelligence-led hypotheses rather than random log searches
- Integrating threat intelligence into SOC workflows, SOAR playbooks, and incident response
- How AI and machine learning are reshaping threat feed triage and IOC enrichment in 2026
- Threat intelligence sharing frameworks, ISAC participation, and the legal and regulatory limits around sharing
Who Should Take This Course?
This course is built for professionals who already work with security data daily and want to move from reacting to threats to anticipating them.
- SOC Analysts (L1/L2) looking to move into a threat intelligence or L3 role
- Incident responders who want to add proactive threat-hunting skills
- Penetration testers and red teamers moving toward defensive intelligence work
- Digital forensics and malware analysts who need structured reporting skills
- Security engineers responsible for tuning SIEM/SOAR platforms with threat intelligence feeds
- IT and network administrators pivoting into a dedicated cybersecurity career
- CEH- or CND-certified professionals looking for their next specialist credential
Skills You Will Gain
- Structured analytic techniques (ACH, SACH) and threat modeling
- Bias reduction and confidence-level scoring in intelligence judgments
- OSINT tradecraft and dark web monitoring basics
- Threat feed integration with SIEM and SOAR platforms
- Scripting-assisted collection and enrichment using Python
- Writing tactical, operational, and strategic intelligence reports
- Formatting and sharing intelligence using STIX/TAXII standards
- Building a threat intelligence program from the ground up
- Aligning intelligence requirements with organizational risk priorities
Tools Covered
- MITRE ATT&CK Navigator
- STIX/TAXII (2.1) intelligence sharing standards
- MISP (Malware Information Sharing Platform)
- Maltego and theHarvester for OSINT reconnaissance
- Shodan and Censys for internet-facing asset intelligence
- YARA for signature-based threat detection
- Splunk and IBM QRadar for SIEM correlation
- Enterprise threat intelligence platform workflows (Recorded Future, Anomali, ThreatConnect concepts)
- Python for threat feed automation and IOC enrichment scripting
Career Outcomes
CTIA-certified professionals are hired into roles that sit between security operations and strategic decision-making, including:
- Threat Intelligence Analyst
- Cyber Threat Hunter
- SOC Analyst (L2/L3)
- Incident Response Specialist
- APT / Malware Research Analyst
- Security Operations Consultant
- Threat Intelligence Program Manager
According to Salary.com’s 2026 data, threat intelligence analysts in the United States earn an average of roughly $77,800 a year, with senior analysts and program leads earning significantly more depending on industry and geography.
Why Choose kodestree?
Here’s what you get when you train with kodestree:
- Live, instructor-led sessions taught by practicing threat intelligence professionals
- Hands-on labs using MITRE ATT&CK, MISP, and OSINT tooling
- Curriculum mapped to the current EC-Council CTIA v2 (312-85) blueprint
- Flexible weekday, weekend, and fast-track batch options
- Recorded sessions and lifetime access to course material
- Guidance through the exam voucher and eligibility application process
- Corporate and 1-on-1 training options
- Placement assistance and resume support after certification