Back to course index
//PROG_THREAT·CLASS_INTERMEDIATE·Defensive_TRACK
// MISSION_BRIEFING / ACT_I
Threat Intelligence Essentials
// CURRICULUM_TIMELINE / ACT_II
Built around real engagements.
0Duration
0Modules
0Video Hours
0Lab Exercises
Each module ships with lab time, applied exercises, and a verifiable checkpoint. Modules deploy in sequence — the rail below shows the order of engagement.
- MODULE_01Introduction to Threat Intelligence — terminology; key differences between intelligence, information, and data; importance and integration into cyber operations; lifecycles and maturity models; roles, responsibilities, and use cases; standards and frameworks for measuring effectiveness; setting up SPLUNK Attack Range
- MODULE_02Types of Threat Intelligence — strategic, operational, tactical, and technical; use cases for each; generation process; informing regulatory compliance; augmenting vulnerability management; geopolitical and industry-related intelligence; integration with risk management
- MODULE_03Cyber Threat Landscape — overview of trends and challenges; emerging threats, threat actors, and attack vectors; Advanced Persistent Threats; the Cyber Kill Chain; vulnerabilities and Indicators of Compromise; geopolitical and economic impacts; emerging technology impact; MITRE ATT&CK and Splunk Attack Range IOC labs
- MODULE_04Data Collection and Sources — feeds, sources, and evaluation criteria; collection methods and techniques (OSINT, HUMINT, IoC analysis); bulk data collection considerations; normalising, enriching, and extracting intelligence; legal and ethical considerations
- MODULE_05Threat Intelligence Platforms (TIPs) — TIP roles and features; aggregation, analysis, and dissemination; automation and orchestration; evaluation and integration into existing infrastructure; collaboration, sharing, and threat-hunting features; customisation and visualisation; labs on AlienVault OTX and MISP
- MODULE_06Threat Intelligence Analysis — data analysis techniques; statistical analysis and Analysis of Competing Hypotheses; identifying threat-actor artifacts; threat prioritisation, profiling, and attribution; predictive and proactive intelligence; reporting and visualisation; threat-actor profile and MISP report-generation labs
- MODULE_07Threat Hunting and Detection — operational overview and process dissection; methodologies and frameworks; proactive threat hunting; using threat hunting for detection and response; tool selection and techniques; forming threat-hunting hypotheses; threat-hunting lab in SPLUNK ATT&CK Range
- MODULE_08Threat Intelligence Sharing and Collaboration — information-sharing initiatives; sharing platforms; building trust within intelligence communities; cross-industry and cross-sector sharing; building private and public sharing channels; legal and privacy implications; sharing via MISP and Anomali STAXX
- MODULE_09Threat Intelligence in Incident Response — integration into IR processes; role in prevention via workflows and playbooks; intelligence-driven triage and forensic analysis; adapting IR plans with new intelligence; coordinating with external partners; intelligence-driven handling and recovery; post-incident analysis and lessons learned; measurement and continuous improvement
- MODULE_10Future Trends and Continuous Learning — emerging threat-intelligence approaches; convergence of threat intelligence and risk management; continuous learning approaches; adapting professional skillsets; future challenges; community engagement; role in national security and defense; influence on future cybersecurity regulations
// OPERATOR_PROFILE / ACT_III
Before & after deployment
// ENTRY_REQUIREMENTS02 ITEMS
Entry Requirements
- requirement_01:No prior cybersecurity knowledge required
- requirement_02:No prior IT work experience required
// OPERATOR_OUTCOMES10 ITEMS
Operator Outcomes
- outcome_01:Essential threat-intelligence terminology and maturity models
- outcome_02:Evaluating strategic, operational, tactical, and technical intelligence types
- outcome_03:The cyber threat landscape — trends, threat actors, and ongoing challenges
- outcome_04:Data collection methods and credible threat-intelligence sources
- outcome_05:Working with Threat Intelligence Platforms (TIPs)
- outcome_06:Threat-intelligence analysis and threat-actor profiling
- outcome_07:Threat hunting and proactive detection
- outcome_08:Threat-intelligence sharing and collaboration
- outcome_09:Integrating threat intelligence into incident response
- outcome_10:Future trends and continuous-learning approaches
// DEPLOYMENT / ACT_IV
Ready to deploy on Threat Intelligence Essentials?
Apply for the next cohort, or send an enquiry and admissions will reach out within 24 hours with cohort dates, payment options, and the full week-by-week brief.
// enquiry_channel / openTHREAT_INTELLIGENCE

