Course

Cyber Threat Intelligence Foundations: From Evidence to Decision

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.
Difficulty Beginner
Modules 6
Lessons 12
Time 8 hr 15 min
Language en
Created by Threat Intelligence Lab
Updated 11 September 2026
Cyber Threat Intelligence Foundations: From Evidence to DecisionA light-theme course map showing the actual learning modules.BEGINNER • ENCyber Threat Intelligence Foundations:From Evidence to DecisionCourse path through 6 focused modules11. Intelligence ThatServes a Decision22. Requirements and theIntelligence Workflow33. Collection, Sources,and Evidence44. Structured Analysis ofAdversary Behavior55. Intelligence Writingand Briefing66. Dissemination, Action,and Improvement

About this course

A practical, vendor-neutral introduction to cyber threat intelligence (CTI) for aspiring analysts, defenders, security leaders, and adjacent professionals. Students learn how to define intelligence requirements, distinguish data from intelligence, evaluate sources and evidence, reason under uncertainty, model adversary behavior, produce clear assessments, and share intelligence responsibly. The course emphasizes transferable analytical habits, transparent judgment, and outcomes that help real people make better security decisions.

What you'll learn

  • ✓ Explain how cyber threat intelligence differs from raw data, information, security reporting, and unsupported opinion.
  • ✓ Translate stakeholder decisions into clear, prioritized intelligence requirements and an ethical collection plan.
  • ✓ Evaluate source reliability, information credibility, relevance, timeliness, bias, and corroboration before drawing conclusions.
  • ✓ Apply structured analytical techniques and behavior-centered models to develop, challenge, and compare hypotheses.
  • ✓ Write concise intelligence assessments that separate evidence, assumptions, judgments, confidence, implications, and recommended decisions.
  • ✓ Plan responsible dissemination, feedback, and measurement so intelligence improves security decisions without exposing sensitive information.

Before you begin

You will get more from this course if these foundations are already familiar.

  • Basic cybersecurity literacy — You should recognize common concepts such as assets, vulnerabilities, controls, logs, incidents, networks, and identity. No prior intelligence-analysis experience or specific product knowledge is required.

Course content

Module 1: 1. Intelligence That Serves a Decision

Establish the purpose and boundaries of CTI. Learners distinguish evidence, information, and intelligence; identify the people CTI serves; and connect intelligence work to risk and security decisions.

Keep building