Operational Cyber Threat Intelligence: Investigations, Campaigns, and Defensive Action
About this course
An intermediate, vendor-neutral course for cyber threat intelligence analysts, incident responders, threat hunters, detection engineers, and security operations professionals. Learners practice translating operational decisions into investigation plans, constructing defensible evidence timelines, analyzing infrastructure and identity relationships, testing campaign hypotheses, producing time-sensitive intelligence assessments, and converting analytic judgments into hunts, detections, containment options, and measurable improvement. The course emphasizes provenance, uncertainty, alternative explanations, responsible handling, clear handoffs, and feedback-driven defensive operations through the fictional Project Lantern scenario.
What you'll learn
- ✓ Translate an operational security decision into scoped intelligence requirements, priority information needs, collection tasks, and explicit review triggers.
- ✓ Construct evidence timelines that preserve provenance, distinguish event time from knowledge time, expose visibility gaps, and support incident-scoping decisions.
- ✓ Analyze adversary infrastructure and behavior without overstating identity, independence, persistence, prevalence, or maliciousness.
- ✓ Define, test, and revise campaign hypotheses using discriminating evidence, confidence judgments, alternative explanations, and change conditions.
- ✓ Produce operational assessments and briefings that communicate current scope, likely next actions, defensive opportunities, uncertainty, and update triggers.
- ✓ Convert intelligence into bounded hunting, detection, containment, and remediation options, then measure operational use, outcomes, and learning.
Course Content
Module 1: 1. Operational Direction and Investigation Design
Frame active security problems as decision-centered intelligence work, establish coordination and review rhythms, and design bounded investigations that can adapt as evidence changes.
Scoping Operational Intelligence Requirements
Turn an active security concern into bounded, prioritized requirements that support specific operational decisions under time pressure.
Designing the Investigation and Coordination Rhythm
Build an adaptable investigation plan with explicit roles, evidence priorities, review gates, update cadences, escalation paths, and stopping conditions.
Module 2: 2. Evidence Timelines and Incident Reconstruction
Reconstruct activity across endpoint, identity, email, network, cloud, and human evidence while preserving provenance, multiple time concepts, uncertainty, gaps, and defender-generated changes.
Building a Defensible Evidence Timeline
Reconstruct events across multiple evidence sources while preserving provenance, timestamp meaning, transformations, uncertainty, and defender actions.
Reconstructing Scope, Sequence, and Alternative Explanations
Use timelines, entity relationships, negative evidence, and visibility analysis to estimate incident scope and compare plausible reconstructions.
Module 3: 3. Infrastructure, Identity, and Relationship Analysis
Analyze domains, addresses, certificates, hosting, accounts, tools, and other relationships as time-bounded evidence while distinguishing shared infrastructure, reuse, coincidence, coordination, and identity claims.
Analyzing Adversary Infrastructure in Time and Context
Evaluate domains, addresses, certificates, hosting, registration, and service relationships as volatile, time-bounded evidence rather than permanent malicious identities.
Identity, Tooling, and Relationship Hypotheses
Analyze accounts, personas, code, tools, language, infrastructure, and operational patterns without turning association into identity or attribution.
Module 4: 4. Campaign Analysis and Adversary Behavior
Determine when related observations support a campaign hypothesis, model behavior across incidents and time, compare alternative explanations, and identify likely objectives, changes, and defensive opportunities without forcing attribution.
Defining and Testing a Campaign Hypothesis
Determine whether related observations represent one campaign, several operations, copied behavior, shared services, or coincidental overlap.
Modeling Campaign Evolution and Defensive Opportunities
Track how adversary behavior, infrastructure, targeting, timing, and defensive reactions change across a campaign.
Module 5: 5. Operational Assessments and Intelligence Updates
Produce time-sensitive assessments that communicate current scope, leading explanations, likely next actions, confidence, alternatives, warning indicators, defensive opportunities, and clearly versioned updates.
Writing the Operational Intelligence Assessment
Write a time-sensitive assessment that communicates current scope, leading explanations, likely next actions, confidence, alternatives, and decision implications.
Briefing, Updating, and Correcting Under Time Pressure
Deliver preliminary judgments responsibly, manage versions and information cutoffs, incorporate challenge, and correct operational intelligence without obscuring change.
Module 6: 6. From Intelligence to Defensive Operations
Translate operational intelligence into bounded hunts, detections, containment and remediation choices, build feedback into handoffs, and measure whether the work improved decisions and defensive outcomes.
Designing Intelligence-Led Hunts and Detections
Translate campaign and behavior judgments into testable hunt hypotheses and detection analytics with explicit evidence, coverage, limitations, and lifecycle controls.
Operational Handoffs, Outcomes, and Learning
Turn intelligence into accountable containment and remediation options, preserve context through handoffs, and measure decision use, operational results, and durable improvement.