Course

Cyber Intelligence Foundations

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.
Difficulty Beginner
Modules 6
Lessons 16
Time 8 hr 50 min
Language en
Created by Threat Intelligence Lab
Updated 11 September 2026
Cyber Intelligence Foundations course map A light-theme course map connecting a security question to evidence, analysis, and a defensive decision. THREAT INTELLIGENCE LAB Cyber Intelligence Foundations Ask clearly. Collect carefully. Analyze honestly. Act deliberately. QUESTIONWhat matters? EVIDENCEWhat supports it? ANALYSISWhat does it mean? DECISIONWhat happens next? A repeatable workflow makes uncertainty visible and action useful.

About this course

Cyber Intelligence Foundations is a step-by-step course for learners who want to understand how useful security intelligence is made. You will move from vague threat awareness to clearly framed intelligence questions, lawful evidence collection, source evaluation, structured analysis, and concise reporting for real decision-makers.

The course uses a fictional organization and realistic defensive scenarios so you can practice without needing privileged systems or sensitive data. Each lesson adds one capability to the previous lesson. By the end, you will produce a short intelligence assessment that states what is known, what is uncertain, why it matters, and what a defender should do next.

What you'll learn

  • Explain how data, information, intelligence, and decisions differ in a defensive security workflow.
  • Turn a stakeholder concern into a specific intelligence requirement with a decision, audience, and timeframe.
  • Collect and evaluate public evidence while recording provenance, limitations, and confidence.
  • Analyze adversary behavior, infrastructure, and indicators without overstating attribution or certainty.
  • Produce a concise intelligence assessment that separates observations, judgments, implications, and recommended actions.

Before you begin

You will get more from this course if these foundations are already familiar.

  • Basic security vocabulary — You should be comfortable with terms such as asset, vulnerability, authentication, malware, log, and incident. No programming or prior intelligence experience is required.

Course content

Module 4: Module 4: Turn Intelligence Into Better Defense

Move from a finished assessment to a bounded defensive workflow, measurable outcomes, and a maintenance plan that keeps intelligence useful after publication.

Keep building