First Response to an Account, Device, or Data Compromise
Take calm, prioritized action after suspicious access, malware, device loss, or data exposure while preserving trustworthy recovery options.
Find practical guides for building CTI capability, improving analysis, developing your career, and turning intelligence into action.
Choose a topic to see its complete collection.
Newest resources are shown first.
Take calm, prioritized action after suspicious access, malware, device loss, or data exposure while preserving trustworthy recovery options.
Reduce unnecessary data exposure, share deliberately, manage permissions and retention, and maintain backups that can actually restore what matters.
Use modern connection security, trustworthy destinations, careful downloads, and bounded app permissions without relying on security myths.
Protect phones, laptops, tablets, and smart devices through supported software, trusted apps, secure configuration, encryption, and loss preparation.
Use assets, threats, vulnerabilities, likelihood, impact, and defense in depth to make practical everyday security decisions.
Test telemetry, logic, enrichment, alert delivery, and analyst outcomes with safe, repeatable malicious and benign scenarios.
Control credentials across source, build, deployment, and runtime with scoped identities, short lifetimes, safe injection, monitoring, and rehearsed rotation.
Coordinate isolation, evidence, identity containment, business continuity, restoration, and extortion decisions during a ransomware incident.
Recognize impersonation and mailbox compromise, verify sensitive requests independently, and coordinate fast action after a fraudulent payment.
Use unique credentials safely, protect password vaults, recognize credential stuffing, and respond proportionately when passwords may be exposed.
Understand delegated access, consent grants, scopes, tokens, connected-app risk, and the evidence needed to investigate or revoke access safely.
Understand how identities prove who they are, receive permissions, and carry reusable authority through sessions.
Use provenance, signing, verification, and protected CI/CD identities to decide whether a software artifact can be trusted.
Translate cloud shared responsibility into testable ownership for identity, configuration, workloads, SaaS integrations, evidence, and recovery.
Read CVE and NVD records as evolving evidence about a vulnerability, affected products, severity, exploitation, and remediation.
Design, test, deploy, tune, and maintain detections as evidence-producing security controls.
Use DNS questions, answers, resolution paths, timing, and multiple vantage points as bounded investigation evidence.
Preserve security evidence with enough context, integrity, and proportionality to support reliable investigation and action.
Use independent verification and consequence-based decisions to resist urgent requests across email, chat, voice, video, and QR codes.
Understand how infostealers collect valuable access artifacts and how defenders contain, scope, and recover from exposure.
Use OSI and TCP/IP layers as practical reasoning tools for encapsulation, addressing, protocols, and troubleshooting.
Investigate suspicious email safely by separating message identity, authentication results, content, delivery path, and impact.
Compare authentication factors, recovery paths, and operational controls that resist phishing and help-desk abuse.
Plan public-source research with clear authority, minimization, researcher safety, provenance, retention, and escalation boundaries.
Make deliberate decisions about data, outputs, connectors, prompt injection, retention, and accountability when using generative AI.
Use software bills of materials as maintained inventory evidence for component analysis, vulnerability triage, and supplier decisions.
Turn an unfamiliar security alert into a bounded evidence claim, justified disposition, and useful responder handoff.
Evaluate whether security telemetry has the coverage, context, timing, and stability needed for investigation and detection.
Learn how sessions are created, stolen, replayed, detected, revoked, and investigated across browsers and cloud services.
Follow an evidence-led incident response lifecycle from preparation and triage through recovery and durable improvement.
Analyze traffic distribution systems as conditional routing layers without confusing dual-use technology, infrastructure, and criminal operations.
Correlate Windows sign-in, Kerberos, NTLM, and local session evidence across identity and endpoint systems.
Interpret Windows process creation, command lines, lineage, files, and effects without treating a suspicious tree as proof.
A practical method for turning cloud telemetry and threat reporting into prioritized intelligence about identities, control-plane activity, workloads, and business impact.
Simulation mode is one of the most important safety mechanisms in Microsoft Purview. Learn what it can reveal, what it cannot prove, the advantages and limitations, and how to turn simulatio...
Understand how Microsoft Purview Data Map discovers and organizes enterprise metadata, how data sources are registered and scanned, and how to build a reliable governance foundation across c...
Understand the technical, operational, collaboration, recovery, and classification checks that should be completed before sensitivity labels automatically encrypt Microsoft 365 content.
Design Microsoft Purview DLP policies that protect sensitive information across Microsoft 365, endpoints, browsers, and collaboration workflows without creating unnecessary disruption for us...
Build a practical sensitivity-labeling model in Microsoft Purview that users can understand, automation can enforce, and security teams can use across Microsoft 365.
Translate investigation experience into intelligence requirements, source evaluation, analytic judgments, writing, and decision-focused portfolio evidence.
Compare role reality, management, decision access, workload, development, ethics, compensation, and organizational support before accepting.
Select training or certification from the role you want, the skill gap you can demonstrate, delivery quality, total cost, and employer relevance.
Create a lawful, reproducible project that begins with a decision, shows evidence and uncertainty, and ends with a useful intelligence product.
Prepare evidence-backed answers, analyze a realistic case, and ask questions that reveal whether the CTI role supports real decisions.
Use threat intelligence to test external exposure, targeting, critical dependencies, incident claims, and integration assumptions without replacing authorized diligence.
Connect political change to plausible cyber pathways, exposed business dependencies, warning indicators, and proportionate decisions.
Give directors the judgments, business exposure, choices, evidence, and warning they need without turning the briefing into a technical activity report.
Turn plausible threat futures into observable indicators, thresholds, owners, and advance decisions without pretending to predict one certain outcome.
Define scope, compare relevant threat changes, connect them to business exposure, and recommend choices instead of producing a catalog of actors.
Define purpose, participants, permitted use, handling, liability, privacy, security, correction, withdrawal, and exit before sensitive intelligence moves.
Evaluate a sharing community through decision fit, peer relevance, trust, contribution expectations, speed, handling, workload, and demonstrated outcomes.
Choose STIX to represent threat intelligence, TAXII to exchange it through an API, and both only when the use case justifies structured interoperability.
Choose TLP:CLEAR, TLP:GREEN, TLP:AMBER, TLP:AMBER+STRICT, or TLP:RED from the source's intended sharing boundary.
Move from a supplier vulnerability headline to an evidence-based decision using dependency, access, data, exploit activity, controls, and recovery options.
Compare remediation options through exposure, consequence, exploit evidence, control effectiveness, operational cost, reversibility, and residual risk.
Evaluate exploit claims, prerequisites, reliability, weaponization, affected versions, and local reachability without running untrusted code casually.
Assess relevance, exposure, exploitation evidence, consequence, and reversible controls when a newly disclosed vulnerability has no complete fix.
Use CVSS for technical severity, EPSS for near-term exploitation probability, KEV for confirmed exploitation, and local context for the remediation decision.
Decide where AI can assist CTI, protect sensitive evidence, verify every consequential claim, and retain human ownership of analytic judgments.
Design ingestion, normalization, enrichment, curation, publication, expiry, and feedback around traceable evidence and defined intelligence uses.
Decide whether relationship-heavy CTI questions justify a graph, then design entities, evidence-backed edges, time, identity, and analyst workflows.
Design intelligence flows around specific decisions, preserve context and expiry, and stop one unreliable artifact from causing action everywhere.
Choose CTI automation by repeatability, evidence quality, reversibility, and consequence while preserving judgment, accountability, and review.
Decide which CTI work to retain, co-source, or outsource by testing accountability, access, context, quality, response, portability, and full cost.
Tie CTI investment to priority decisions, service options, full operating cost, measurable assumptions, and staged commitments.
Measure service reliability, decision use, risk reduction signals, and learning without rewarding report volume or unexamined indicator counts.
Define CTI services by consumer, decision, input, output, timing, owner, and boundary so people know what to request and what to expect.
Choose the first CTI hires from priority services, existing capability, workload, and decision relationships instead of searching for one impossible all-rounder.
Choose a CTI operating model from decision proximity, consistency, scale, and available expertise rather than copying another organization chart.
Decide where language and regional collection matter, measure source imbalance, and build coverage that reflects your actual operations and suppliers.
Trace online claims, screenshots, copied reports, and social posts to evidence, test context and independence, and choose a proportionate response.
Decide whether dark web monitoring fits a real intelligence requirement, and define safe collection, validation, escalation, and service expectations.
Use historical DNS and registration data for discovery and corroboration without mistaking co-location, privacy services, or stale records for shared control.
Run a decision-based trial that tests unique coverage, relevance, timeliness, provenance, integration effort, and measurable operational value.
Convert an intelligence requirement into lawful, safe, source-specific OSINT tasks with validation rules, stop conditions, and a clear owner.
Find confirmation bias, anchoring, mirror imaging, recency effects, and group pressure before they distort a consequential intelligence judgment.
Turn malware analysis into CTI by selecting findings that improve scoping, detection, containment, prioritization, or warning.
Investigate domains, IP addresses, certificates, hosting, and relationships while setting evidence thresholds that prevent false cluster expansion.
Analyze victim selection without confusing public visibility with adversary preference, then turn the pattern into a defensible warning decision.
Create a living actor profile that separates observed behavior, assessed capability, targeting, infrastructure, aliases, and uncertain attribution.
Build an evidence-backed timeline across reports, infrastructure, malware, and incidents without turning uncertain dates into a false narrative.
Choose the analytic framework that matches your question: relationships with the Diamond Model, intrusion progress with the Kill Chain, or observable behavior with ATT&CK.
Use ACH when several explanations fit the same evidence, compare them consistently, and show decision-makers what could change the leading judgment.
Understand what likelihood, analytic confidence, and business risk each mean so a threat assessment leads to a sound decision instead of a misleading score.
Decide whether a reported threat deserves attention by testing exposure, adversary intent, capability, opportunity, potential consequence, and the value of acting now.
Turn broad threat concerns into prioritized, answerable intelligence requirements with a named consumer, decision, scope, time horizon, collection questions, success criteria, and review tri...
Decide whether a security question belongs to Cyber Threat Intelligence, incident response, or a joint workflow—and design the handoffs that turn external context and incident evidence int...
Decide whether a security problem needs threat intelligence, threat hunting, or both by comparing their questions, evidence, workflows, outputs, staffing, and measures of success.
Choose the right level of Cyber Threat Intelligence by matching tactical, operational, and strategic products to the decision, audience, evidence, time horizon, and action required.
Write CTI reports that readers can use by defining the decision, separating evidence from judgment, leading with key assessments, expressing likelihood and confidence, tailoring depth, expla...
Produce strategic Cyber Threat Intelligence that leaders can use by connecting external threats to business exposure, scenarios, likelihood, impact, warning indicators, options, and clear de...
Make defensible threat-intelligence sharing decisions by defining purpose and audience, minimizing sensitive data, applying TLP correctly, choosing human and machine-readable formats, preser...
Turn vulnerability data into remediation decisions by combining technical severity, exploitation evidence, exposure, asset importance, likely impact, controls, and operational constraints—...
Decide whether your organization needs a threat intelligence platform, understand the capabilities a TIP should provide, compare build and buy options, evaluate vendors through real workflow...
Build a practical Cyber Threat Intelligence program from mission and requirements through services, staffing, sources, workflows, technology, governance, stakeholder integration, metrics, ma...
Learn how to build and evaluate a Cyber Threat Intelligence source portfolio, preserve provenance, distinguish source reliability from claim credibility, find original reporting, corroborate...
Learn how cyber threat attribution is built and communicated: the levels of attribution, evidence types, clustering, hypothesis testing, confidence, naming problems, deception, legal and pol...
Learn the difference between observables, indicators of compromise, and adversary tactics, techniques, and procedures—and how to preserve context, map behavior, engineer detections, manage...
Learn how the Cyber Threat Intelligence lifecycle works in practice, from defining intelligence requirements and planning collection through processing, analysis, dissemination, feedback, an...
Understand cyber threat intelligence from first principles: what it is, how it differs from threat data, the tactical, operational, and strategic layers, the intelligence lifecycle, core evi...
Understand how a cyber threat intelligence career develops after the first role. Learn what changes from junior analyst to senior analyst, principal, team lead, manager, and head of CTI, how...
Break into cyber threat intelligence with a practical, evidence-driven roadmap. Learn what entry-level CTI employers actually look for, how to build a portfolio without prior intelligence ex...
Step inside the real world of cyber threat intelligence work. Explore the roles, daily workflows, essential skills, career pathways, and the unique mindset that separates top CTI analysts fr...