Cyber Threat Intelligence Feeds
Learn what threat intelligence feeds contain, where defenders use them, and how to turn a stream of indicators into meas...
3 lessons · 2 hrAn intermediate, vendor-neutral course for cyber threat intelligence analysts, incident responders, threat hunters, detection engineers, and security operations professionals. Learners practice translating operational decisions into investigation plans, constructing defensible evidence timelines, analyzing infrastructure and identity relationships, testing campaign hypotheses, producing time-sensitive intelligence assessments, and converting analytic judgments into hunts, detections, containment options, and measurable improvement. The course emphasizes provenance, uncertainty, alternative explanations, responsible handling, clear handoffs, and feedback-driven defensive operations through the fictional Project Lantern scenario.
You will get more from this course if these foundations are already familiar.
Frame active security problems as decision-centered intelligence work, establish coordination and review rhythms, and design bounded investigations that can adapt as evidence changes.
Turn an active security concern into bounded, prioritized requirements that support specific operational decisions under time pressure.
Build an adaptable investigation plan with explicit roles, evidence priorities, review gates, update cadences, escalation paths, and stopping conditions.
Reconstruct activity across endpoint, identity, email, network, cloud, and human evidence while preserving provenance, multiple time concepts, uncertainty, gaps, and defender-generated changes.
Reconstruct events across multiple evidence sources while preserving provenance, timestamp meaning, transformations, uncertainty, and defender actions.
Use timelines, entity relationships, negative evidence, and visibility analysis to estimate incident scope and compare plausible reconstructions.
Analyze domains, addresses, certificates, hosting, accounts, tools, and other relationships as time-bounded evidence while distinguishing shared infrastructure, reuse, coincidence, coordination, and identity claims.
Evaluate domains, addresses, certificates, hosting, registration, and service relationships as volatile, time-bounded evidence rather than permanent malicious identities.
Analyze accounts, personas, code, tools, language, infrastructure, and operational patterns without turning association into identity or attribution.
Determine when related observations support a campaign hypothesis, model behavior across incidents and time, compare alternative explanations, and identify likely objectives, changes, and defensive opportunities without forcing attribution.
Determine whether related observations represent one campaign, several operations, copied behavior, shared services, or coincidental overlap.
Track how adversary behavior, infrastructure, targeting, timing, and defensive reactions change across a campaign.
Produce time-sensitive assessments that communicate current scope, leading explanations, likely next actions, confidence, alternatives, warning indicators, defensive opportunities, and clearly versioned updates.
Write a time-sensitive assessment that communicates current scope, leading explanations, likely next actions, confidence, alternatives, and decision implications.
Deliver preliminary judgments responsibly, manage versions and information cutoffs, incorporate challenge, and correct operational intelligence without obscuring change.
Translate operational intelligence into bounded hunts, detections, containment and remediation choices, build feedback into handoffs, and measure whether the work improved decisions and defensive outcomes.
Translate campaign and behavior judgments into testable hunt hypotheses and detection analytics with explicit evidence, coverage, limitations, and lifecycle controls.
Turn intelligence into accountable containment and remediation options, preserve context through handoffs, and measure decision use, operational results, and durable improvement.