Course Outline
Overview of Cyber Threat Intelligence (CTI)
- Definition and strategic value of CTI
- Categorization of CTI: Tactical, Operational, Strategic, and Technical
- Core concepts and standard terminology
- Classification of cyber threats including malware, phishing, and ransomware
- Historical context of cyber incidents
- Current developments in the threat landscape
- Phases of the intelligence lifecycle
Data Acquisition Methods
- Intelligence data sources (open source, dark web, and internal repositories)
- Data collection methodologies
- Tools and technologies for acquisition
Data Processing and Enrichment
- Data processing techniques
- Normalization and enrichment processes
- Automating data processing workflows
Intelligence Analysis Methodologies
- Analytical frameworks: link analysis, trend analysis, and behavioral analysis
- Analysis tools for CTI
- Practical exercises in data analysis
Introduction to Threat Intelligence Platforms (TIPs)
- Survey of leading TIPs (e.g., MISP, ThreatConnect, Anomali)
- Core features and functionalities of TIPs
- Integration of TIPs with broader security infrastructure for government operations
Practical Application of Threat Intelligence Platforms
- Configuration and utilization of a TIP
- Data ingestion and correlation techniques
- Customization of alerts and reporting mechanisms
Automation in Threat Intelligence
- Rationale for automation in CTI
- Tools and methods for automating intelligence workflows
- Practical application of automation scripts
Strategic Information Sharing
- Advantages and challenges of sharing threat intelligence
- Information-sharing models and frameworks (e.g., STIX/TAXII, OpenC2)
Establishment of Information-Sharing Communities
- Best practices for community development
- Legal and ethical compliance requirements
- Case studies of effective information-sharing initiatives
Collaborative Threat Intelligence Operations
- Joint threat analysis procedures
- Role-playing scenarios for intelligence dissemination
- Strategies for enhancing collaboration
Advanced Threat Intelligence Techniques
- Application of machine learning and AI in CTI
- Advanced threat-hunting methodologies
- Emerging developments in the field
Cyber Attack Case Studies
- In-depth analysis of significant cyber incidents
- Key lessons and intelligence insights derived from past events
- Practical exercises in intelligence report development
Development of a CTI Program
- Steps to establish and mature a CTI capability
- Metrics and key performance indicators (KPIs) for evaluating program effectiveness
Conclusion and Future Directions
Requirements
- Fundamental knowledge of cybersecurity principles and operational practices
- Comprehension of network and information assurance concepts
- Practical experience managing IT systems and infrastructure
Audience
- Cybersecurity practitioners
- Information technology security analysts
- Personnel within Security Operations Centers (SOCs) engaged in government missions
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.