Cyber Threat Intelligence Foundations: From Evidence to Decision
About this course
A practical, vendor-neutral introduction to cyber threat intelligence (CTI) for aspiring analysts, defenders, security leaders, and adjacent professionals. Students learn how to define intelligence requirements, distinguish data from intelligence, evaluate sources and evidence, reason under uncertainty, model adversary behavior, produce clear assessments, and share intelligence responsibly. The course emphasizes transferable analytical habits, transparent judgment, and outcomes that help real people make better security decisions.
What you'll learn
- ✓ Explain how cyber threat intelligence differs from raw data, information, security reporting, and unsupported opinion.
- ✓ Translate stakeholder decisions into clear, prioritized intelligence requirements and an ethical collection plan.
- ✓ Evaluate source reliability, information credibility, relevance, timeliness, bias, and corroboration before drawing conclusions.
- ✓ Apply structured analytical techniques and behavior-centered models to develop, challenge, and compare hypotheses.
- ✓ Write concise intelligence assessments that separate evidence, assumptions, judgments, confidence, implications, and recommended decisions.
- ✓ Plan responsible dissemination, feedback, and measurement so intelligence improves security decisions without exposing sensitive information.
Course Content
Module 1: 1. Intelligence That Serves a Decision
Establish the purpose and boundaries of CTI. Learners distinguish evidence, information, and intelligence; identify the people CTI serves; and connect intelligence work to risk and security decisions.
What Cyber Threat Intelligence Is—and Is Not
Build a precise mental model of CTI by separating observations, data, information, evidence, judgments, and decision-relevant intelligence.
Consumers, Decisions, and Levels of Intelligence
Understand who uses CTI, which decisions it supports, and how strategic, operational, and tactical perspectives connect.
Module 2: 2. Requirements and the Intelligence Workflow
Turn stakeholder needs into answerable intelligence requirements and manage a feedback-driven workflow that prioritizes effort, exposes gaps, and adapts as decisions change.
From Stakeholder Need to Intelligence Requirement
Convert vague security concerns into prioritized, answerable requirements tied to a decision, scope, and time horizon.
The Intelligence Workflow as a Learning Loop
Use direction, collection, processing, analysis, dissemination, and feedback as an adaptive workflow rather than a rigid conveyor belt.
Module 3: 3. Collection, Sources, and Evidence
Build lawful, ethical collection plans; handle observables in context; evaluate source reliability and information credibility; and preserve provenance so conclusions can be reviewed.
Collection Planning and Provenance
Select proportionate sources, document where evidence came from, and preserve the context required for later verification and lawful use.
Evaluating Sources, Evidence, and Indicators
Judge source reliability and information credibility, distinguish observables from indicators, and avoid treating context-free artifacts as conclusions.
Module 4: 4. Structured Analysis of Adversary Behavior
Develop and challenge hypotheses, reason explicitly under uncertainty, recognize common cognitive traps, and use behavior-centered models to organize what is known without forcing the evidence.
Reasoning Under Uncertainty
Recognize assumptions and cognitive bias, use estimative language consistently, and make confidence judgments that reflect evidence quality and analytic agreement.
Behavior Models and Competing Hypotheses
Organize adversary activity with behavior-centered models and compare alternative explanations against evidence to reduce premature conclusions.
Module 5: 5. Intelligence Writing and Briefing
Create assessments for technical and executive audiences by separating fact from judgment, expressing confidence and alternatives, explaining implications, and designing clear visual and verbal communication.
Writing Defensible Intelligence Assessments
Write bottom-line-up-front assessments that distinguish sourced facts, assumptions, analytic judgments, confidence, alternatives, and implications.
Briefing and Visualizing for Understanding
Adapt intelligence to technical and executive audiences, choose honest visual forms, and brief in a way that supports questions and decisions.
Module 6: 6. Dissemination, Action, and Improvement
Deliver intelligence to the right people with appropriate handling, translate findings into defensive action, gather feedback, and measure whether CTI changes decisions and reduces uncertainty.
Responsible Sharing and Information Handling
Balance utility with privacy, sensitivity, legal authority, and partner trust when deciding what to share, with whom, and under which conditions.
From Intelligence to Action and Measurable Improvement
Translate assessments into defensive choices, build feedback into operations, and measure CTI through outcomes, learning, and decision quality.