Cyber Threat Intelligence Foundations: From Evidence to Decision
Learn to turn cyber evidence into defensible, decision-relevant intelligence through requirements, collection, structure...
12 lessons · 8 hr 15 minCyber Intelligence Foundations is a step-by-step course for learners who want to understand how useful security intelligence is made. You will move from vague threat awareness to clearly framed intelligence questions, lawful evidence collection, source evaluation, structured analysis, and concise reporting for real decision-makers.
The course uses a fictional organization and realistic defensive scenarios so you can practice without needing privileged systems or sensitive data. Each lesson adds one capability to the previous lesson. By the end, you will produce a short intelligence assessment that states what is known, what is uncertain, why it matters, and what a defender should do next.
You will get more from this course if these foundations are already familiar.
Learn what intelligence is, who uses it, and how to frame a useful requirement before collecting information.
Learn how to collect lawful public information, evaluate sources, and organize evidence so another analyst can reproduce your reasoning.
Apply structured reasoning to adversary behavior and indicators, then communicate a concise assessment with actionable next steps.
Use behavior, capability, and context to explain threats without treating attribution as certainty.
Learn what an IoC is, how common IoC types differ, and why context determines whether an indicator is useful.
Understand what domains, IPs, hashes, and patterns can tell you, and what they cannot prove alone.
Assemble evidence into a concise report that states the judgment, confidence, implications, and next actions.
Move from a finished assessment to a bounded defensive workflow, measurable outcomes, and a maintenance plan that keeps intelligence useful after publication.
Turn an intelligence judgment into a testable hunt hypothesis with known telemetry, limits, and an escalation path.
Add freshness, ownership, feedback, and review triggers so intelligence does not become stale background noise.
Apply the foundation workflow to vulnerability exposure, identity-driven social engineering, and malware or ransomware activity without losing evidence discipline.
Combine vulnerability facts, exposure, exploitation evidence, and business impact to support a defensible remediation priority.
Investigate phishing and account abuse as behavior chains rather than isolated messages or login events.
Describe malware behavior, delivery, impact, and defensive relevance without treating a family label as the whole assessment.
Build the habits that make an intelligence function dependable: stakeholder alignment, information governance, structured sharing, and safe automation.
Build trust by translating stakeholder concerns into useful requirements and communicating intelligence at the right level of detail.
Apply classification, access, retention, provenance, and privacy principles to intelligence work.
Use structured formats and automation to scale intelligence while preserving context, validation, and human accountability.