This Cyber Threat Intelligence course moves past theory-only content. You’ll work through the complete intelligence lifecycle – planning, collection, processing, analysis, and dissemination – inside real platforms such as MISP and OpenCTI, not just slides. Instructors are practicing security professionals who connect every concept to how intelligence is actually used inside a SOC: prioritizing alerts, briefing leadership, and hunting adversaries before damage occurs. You’ll finish with a portfolio-ready capstone investigation and exam-aligned preparation for recognized industry certifications.
Prerequisites
There’s no strict entry barrier, but the following will help you get the most out of the course:
- A basic understanding of networking concepts (TCP/IP, DNS, firewalls)
- Familiarity with core security concepts such as malware types, vulnerabilities, and the CIA triad
- 6+ months of experience in IT, networking, or a SOC/security analyst role is recommended, though not mandatory for career-switchers
- Basic comfort with Python or scripting is helpful for the automation-focused modules, but not required to start
Course Objectives
- Understand the end-to-end cyber threat intelligence lifecycle and where it fits into modern SOC and risk workflows
- Differentiate between strategic, operational, tactical, and technical intelligence, and know when to apply each
- Collect and validate intelligence from OSINT, dark web sources, closed communities, and commercial feeds
- Apply the MITRE ATT&CK framework, Cyber Kill Chain, and Diamond Model to map adversary behavior
- Build, enrich, and pivot on Indicators of Compromise (IOCs) using the Pyramid of Pain
- Operationalize intelligence inside SIEM, SOAR, and Threat Intelligence Platforms (TIPs)
- Write intelligence reports and briefings tailored to analysts, SOC managers, and executives
- Evaluate and select threat intelligence tools and frameworks based on an organization’s maturity level
- Prepare for globally recognized threat intelligence certification exams through case studies and mock assessments
What You Will Learn
- The Threat Intelligence Lifecycle: planning and direction, collection, processing, analysis, dissemination, and feedback
- Threat actor profiling: TTPs, motivations, and attribution using the Diamond Model and Cyber Kill Chain
- MITRE ATT&CK Navigator: mapping detections and coverage gaps against real adversary techniques
- OSINT tradecraft: advanced search operators, social media intelligence, dark web monitoring, and passive DNS analysis
- Malware and IOC fundamentals: static indicators, YARA rules, and reading sandbox/malware analysis reports
- Threat Intelligence Platforms (TIPs): hands-on workflows in MISP, OpenCTI, and an overview of Anomali and ThreatConnect
- SIEM/SOAR integration: feeding intelligence into platforms like Splunk or QRadar for automated response
- Threat hunting fundamentals: hypothesis-driven hunting built on ATT&CK-mapped intelligence
- Structured analytic techniques: Analysis of Competing Hypotheses and key assumptions checks
- Intelligence sharing standards: STIX/TAXII, Traffic Light Protocol (TLP), and ISAC participation
- Report writing for strategic, operational, and tactical audiences
- Supply chain, third-party, and cloud (AWS, Azure, GCP) threat intelligence considerations
Who Should Take This Course?
This course is built for professionals who want to move from reactive defense to proactive, intelligence-driven security.
- SOC Analysts (L1/L2) looking to move into a threat intelligence specialization
- Incident responders and digital forensics professionals
- Security engineers, network administrators, and systems administrators
- Aspiring threat hunters and malware analysts
- IT professionals transitioning into cybersecurity
- Risk, compliance, and GRC professionals who need to understand threat context
- Students and recent graduates in cybersecurity, IT, or computer science
- Security managers and CISOs who want a working understanding of CTI programs
Skills You Will Gain
- OSINT collection and dark web monitoring
- MITRE ATT&CK mapping and Navigator usage
- IOC/IOA identification and enrichment
- TIP configuration (MISP, OpenCTI)
- STIX/TAXII data exchange
- Basic scripting for intelligence automation
- Structured analytic techniques
- Adversary attribution and threat modeling
- Risk-based prioritization of alerts and hunts
- Bias recognition in intelligence analysis
- Executive-level threat briefings
- Technical and tactical intelligence report writing
- Cross-team collaboration with SOC, IR, and risk teams
Tools Covered
- MISP (Malware Information Sharing Platform)
- OpenCTI
- MITRE ATT&CK Navigator
- Maltego
- Shodan
- VirusTotal
- YARA
- TheHarvester and other OSINT frameworks
- Splunk / QRadar (for SIEM integration walkthroughs)
Career Outcomes
Completing this certification opens doors across SOCs, MSSPs, and enterprise security teams that are actively hiring for intelligence-driven roles.
- Cyber Threat Intelligence Analyst
- SOC Analyst (L2/L3)
- Threat Hunter
- Incident Response Analyst
- SOC Team Lead / Manager
- Malware Analyst
- Vulnerability & Risk Analyst
- Cybersecurity Consultant
Why Choose kodestree?
When you’re deciding where to invest your training hours, here’s what sets kodestree apart.
- Live, instructor-led sessions with practicing threat intelligence professionals
- Hands-on labs using MISP, OpenCTI, and MITRE ATT&CK Navigator
- Real-world case studies based on recent APT campaigns and ransomware incidents
- Flexible weekday and weekend batches
- Lifetime access to recorded sessions and course material updates
- Resume building, mock interviews, and placement assistance
- 24/7 learner support
- Globally recognized kodestree completion certificate