Cyber Threat Intelligence Feeds
Learn what threat intelligence feeds contain, where defenders use them, and how to turn a stream of indicators into meas...
3 lessons · 2 hrBuilt for service-desk responders, SOC analysts, and security generalists who handle suspicious messages, this course teaches a repeatable investigation that starts with preserved evidence and ends with proportionate action. Learners examine sender identities, Received fields, SPF, DKIM, DMARC, URLs, attachments, delivery scope, and user interaction without treating any single signal as a verdict. The course emphasizes safe handling, evidence limits, escalation boundaries, and concise case notes. Completion means the learner can triage a reported message, explain what the evidence proves and does not prove, identify affected recipients and interactions, and recommend containment without live-clicking attacker content or overstating confidence.
You will get more from this course if these foundations are already familiar.
Build a safe evidence-first workflow, then learn to separate user-visible claims from transport evidence recorded by mail systems.
Turn a user report into a bounded investigation while preserving the original message and avoiding attacker-controlled interactions.
Read Received fields from the first trusted mail boundary and compare visible, envelope, return, and signing identities.
Interpret domain authentication as scoped evidence, then examine destinations and files without turning analysis into execution.
Use Authentication-Results correctly and avoid treating a pass or failure as a complete message verdict.
Parse destinations, expand the investigation through approved passive evidence, and distinguish suspicious appearance from observed behavior.
Handle attachments as potentially active evidence, expand the investigation to affected people and systems, and close with a reviewable decision.
Identify file type, preserve hashes and metadata, and escalate active-content analysis into an isolated environment.
Find related delivery and interaction, distinguish message risk from incident impact, and record evidence-linked containment.