Cyber Intelligence Foundations
Build a practical foundation in cyber threat intelligence, from intelligence questions and evidence collection to analys...
16 lessons · 8 hr 50 minA practical, vendor-neutral introduction to cyber threat intelligence (CTI) for aspiring analysts, defenders, security leaders, and adjacent professionals. Students learn how to define intelligence requirements, distinguish data from intelligence, evaluate sources and evidence, reason under uncertainty, model adversary behavior, produce clear assessments, and share intelligence responsibly. The course emphasizes transferable analytical habits, transparent judgment, and outcomes that help real people make better security decisions.
You will get more from this course if these foundations are already familiar.
Establish the purpose and boundaries of CTI. Learners distinguish evidence, information, and intelligence; identify the people CTI serves; and connect intelligence work to risk and security decisions.
Build a precise mental model of CTI by separating observations, data, information, evidence, judgments, and decision-relevant intelligence.
Understand who uses CTI, which decisions it supports, and how strategic, operational, and tactical perspectives connect.
Turn stakeholder needs into answerable intelligence requirements and manage a feedback-driven workflow that prioritizes effort, exposes gaps, and adapts as decisions change.
Convert vague security concerns into prioritized, answerable requirements tied to a decision, scope, and time horizon.
Use direction, collection, processing, analysis, dissemination, and feedback as an adaptive workflow rather than a rigid conveyor belt.
Build lawful, ethical collection plans; handle observables in context; evaluate source reliability and information credibility; and preserve provenance so conclusions can be reviewed.
Select proportionate sources, document where evidence came from, and preserve the context required for later verification and lawful use.
Judge source reliability and information credibility, distinguish observables from indicators, and avoid treating context-free artifacts as conclusions.
Develop and challenge hypotheses, reason explicitly under uncertainty, recognize common cognitive traps, and use behavior-centered models to organize what is known without forcing the evidence.
Recognize assumptions and cognitive bias, use estimative language consistently, and make confidence judgments that reflect evidence quality and analytic agreement.
Organize adversary activity with behavior-centered models and compare alternative explanations against evidence to reduce premature conclusions.
Create assessments for technical and executive audiences by separating fact from judgment, expressing confidence and alternatives, explaining implications, and designing clear visual and verbal communication.
Write bottom-line-up-front assessments that distinguish sourced facts, assumptions, analytic judgments, confidence, alternatives, and implications.
Adapt intelligence to technical and executive audiences, choose honest visual forms, and brief in a way that supports questions and decisions.
Deliver intelligence to the right people with appropriate handling, translate findings into defensive action, gather feedback, and measure whether CTI changes decisions and reduces uncertainty.
Balance utility with privacy, sensitivity, legal authority, and partner trust when deciding what to share, with whom, and under which conditions.
Translate assessments into defensive choices, build feedback into operations, and measure CTI through outcomes, learning, and decision quality.