
This comprehensive 2-day course on Threat Intelligence Management is designed for cybersecurity professionals who aspire to master the art of analyzing and mitigating cyber threats effectively.
Course Length: 16 Hours
Includes a Certificate of Completion
					Next scheduled date:
								
												
						 
					
							
			Description
This comprehensive 2-day course on Threat Intelligence Management is designed for cybersecurity professionals who aspire to master the art of analyzing and mitigating cyber threats effectively.
The curriculum covers a broad spectrum of topics from the foundational concepts of threat intelligence to advanced applications in various organizational contexts. Through a mix of theoretical knowledge and practical exercises, participants will learn to develop, manage, and implement an effective threat intelligence program tailored to their organization’s needs.
This class is less about tools and more about learning frameworks, process, and logic tools to provide intelligence.
Syllabus
Syllabus
- 
- Introduction to Threat Intelligence
- 
- Defining Threat Intelligence: Understanding the nuances of threat intelligence and its application across various industries.
 
 - 
- Applications Across Sectors: Explore the unique applications of threat intelligence in different sectors such as finance, healthcare, and government.
 
 - 
- Data to Intelligence: Learn methodologies to transform raw data into actionable intelligence.
 
 - 
- Intelligence Types: Detailed discussion on Tactical, Strategic, Operational, and Technical intelligence.
 
 
- 
 
- Introduction to Threat Intelligence
- 
- Intelligence Frameworks and Protocols
- 
- Traffic Light Protocol: Guidelines for data sharing sensitivity.
 
 - 
- Cyber Kill Chain and Diamond Model: Understanding attacker engagement sequences and the facets of an intrusion.
 
 - 
- Pyramid of Pain and MITRE ATT&CK: Tactical approaches to understanding attacker behaviors and methodologies.
 
 
- 
 
- Intelligence Frameworks and Protocols
- 
- Structured Analytic Techniques
- 
- Identification and Mitigation: Learn to identify common cognitive biases and strategies to mitigate their impact on intelligence analysis.
 
 
- 
 
- Structured Analytic Techniques
- 
- Intelligence Life Cycle
- 
- Comprehensive Overview: From direction-setting to feedback integration, each phase of the intelligence lifecycle is explored, along with relevant tools and techniques for enhancement.
 
 
- 
 
- Intelligence Life Cycle
- 
- Inventory and Asset Management
- 
- Internal Assessment: Techniques to inventory critical organizational assets and understand the attack surface.
 
 - 
- Attack Surface Management Tools: Explore tools and techniques for effective management and threat assessment.
 
 
- 
 
- Inventory and Asset Management
- 
- Threat Modeling, Landscaping, and Profiling
- 
- Threat Modeling Techniques: Introduction to STRIDE, PASTA, and decision trees.
 
 - 
- Threat Landscaping and Actor Profiling: Learn to define the threat landscape and profile potential threat actors based on intent and capabilities.
 
 
- 
 
- Threat Modeling, Landscaping, and Profiling
- 
- Priority Intelligence Requirements (PIRs)
- 
- Development and Communication: Crafting effective PIRs and strategies for cross-departmental communication.
 
 
- 
 
- Priority Intelligence Requirements (PIRs)
- 
- AI and CTI
- 
- Language model usage for clustering, report generation
 
 - 
- Threats from AI-assisted phishing, deepfakes
 
 
- 
 
- AI and CTI
- 
- Threat Intelligence Sharing Models
- 
- ISACs,
 
 - 
- TLP application in trust groups
 
 - 
- Barriers to sharing and building information exchange networks
 
 
- 
 
- Threat Intelligence Sharing Models
- 
- Open Source Intelligence (OSINT)
- 
- Intro to passive OSINT for infrastructure discovery
 
 - 
- Tools: Spiderfoot, Maltego, Shodan, FOFA
 
 - 
- Ethical/legal boundaries in collection
 
 
- 
 
- Open Source Intelligence (OSINT)
- 
- Operational Security-
- 
- Understand the principles and importance of OPSEC in CTI work.
 
 - 
- Recognize situations where poor OPSEC can lead to attribution, compromise, or adversary adaptation.
 
 - 
- Apply safe practices when collecting, researching, or interacting with threat actor infrastructure or forums.
 
 
- 
 
- Operational Security-
- 
- Dark Web
- 
- Understand the structure and purpose of the dark web and deep web
 
 - 
- Identify common platforms, marketplaces, and forums used by threat actors.
 
 - 
- Learn safe, ethical, and legal methods for dark web monitoring.
 
 - 
- Recognize the value of dark web intelligence in threat profiling, credential monitoring, and early breach detection.
 
 
- 
 
- Dark Web
- 
- Advanced Intelligence Dissemination and Tools
- 
- Choosing Intelligence Vendors and Platforms: Criteria and best practices for selecting threat intelligence vendors and platforms.
 
 - 
- Tools and Techniques: Exploration of dark web analysis tools, deception technology, note-taking methodologies, visualization tools, and domain intelligence.
 
 
- 
 
- Advanced Intelligence Dissemination and Tools
About the Instructor
 
							Wade Wells
"Wondering in the logs"Bio
Wade Wells is the Lead Detection Engineer for a Fortune 30 financial company. He has worked for eight years in security operations, performing threat hunting, cyber threat intelligence, and detection engineering, primarily in the financial sector. Active in the cybersecurity community, Wade frequently speaks at prominent industry events and is involved with several security-focused organizations.
Related products
- 
	Bill McCauleyLive4 HrsWorkshop: Foundational Application Security Training with Bill McCauleyView Course This product has multiple variants. The options may be chosen on the product page
- 
	Wade WellsLiveOD8 HrsCyber Threat Intelligence 101 with Wade WellsView Course This product has multiple variants. The options may be chosen on the product page
- 
	Kevin KlingbileLiveOD16 HrsDefending M365 & Azure with Kevin KlingbileView Course This product has multiple variants. The options may be chosen on the product page
- 
	Hayden CovingtonLive4 HrsWorkshop: SOC Detection Engineering Crash Course with Hayden CovingtonView Course This product has multiple variants. The options may be chosen on the product page
