Get in Touch

Course Outline

Overview of Cyber Threat Intelligence (CTI)

  • Definition and strategic value of CTI
  • Categorization of CTI: Tactical, Operational, Strategic, and Technical
  • Core concepts and standard terminology
  • Classification of cyber threats including malware, phishing, and ransomware
  • Historical context of cyber incidents
  • Current developments in the threat landscape
  • Phases of the intelligence lifecycle

Data Acquisition Methods

  • Intelligence data sources (open source, dark web, and internal repositories)
  • Data collection methodologies
  • Tools and technologies for acquisition

Data Processing and Enrichment

  • Data processing techniques
  • Normalization and enrichment processes
  • Automating data processing workflows

Intelligence Analysis Methodologies

  • Analytical frameworks: link analysis, trend analysis, and behavioral analysis
  • Analysis tools for CTI
  • Practical exercises in data analysis

Introduction to Threat Intelligence Platforms (TIPs)

  • Survey of leading TIPs (e.g., MISP, ThreatConnect, Anomali)
  • Core features and functionalities of TIPs
  • Integration of TIPs with broader security infrastructure for government operations

Practical Application of Threat Intelligence Platforms

  • Configuration and utilization of a TIP
  • Data ingestion and correlation techniques
  • Customization of alerts and reporting mechanisms

Automation in Threat Intelligence

  • Rationale for automation in CTI
  • Tools and methods for automating intelligence workflows
  • Practical application of automation scripts

Strategic Information Sharing

  • Advantages and challenges of sharing threat intelligence
  • Information-sharing models and frameworks (e.g., STIX/TAXII, OpenC2)

Establishment of Information-Sharing Communities

  • Best practices for community development
  • Legal and ethical compliance requirements
  • Case studies of effective information-sharing initiatives

Collaborative Threat Intelligence Operations

  • Joint threat analysis procedures
  • Role-playing scenarios for intelligence dissemination
  • Strategies for enhancing collaboration

Advanced Threat Intelligence Techniques

  • Application of machine learning and AI in CTI
  • Advanced threat-hunting methodologies
  • Emerging developments in the field

Cyber Attack Case Studies

  • In-depth analysis of significant cyber incidents
  • Key lessons and intelligence insights derived from past events
  • Practical exercises in intelligence report development

Development of a CTI Program

  • Steps to establish and mature a CTI capability
  • Metrics and key performance indicators (KPIs) for evaluating program effectiveness

Conclusion and Future Directions

Requirements

  • Fundamental knowledge of cybersecurity principles and operational practices
  • Comprehension of network and information assurance concepts
  • Practical experience managing IT systems and infrastructure

Audience

  • Cybersecurity practitioners
  • Information technology security analysts
  • Personnel within Security Operations Centers (SOCs) engaged in government missions
 35 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories