Skip to content
Intermediate8-10 hours· Last reviewed 20 Aug 2026

Threat Intelligence Analyst

Collect, analyse and disseminate threat intelligence. Covers OSINT, dark web monitoring, IOC lifecycle, MISP, STIX/TAXII and strategic intelligence production.

Prerequisites

  • ·Working knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, routing)
  • ·Familiarity with common attack techniques and malware behaviour
  • ·Comfort reading technical security reports and vendor threat advisories
  • ·Basic command-line and scripting literacy (useful for OSINT tooling, not mandatory)
  • ·Prior exposure to SOC, DFIR or vulnerability management concepts is helpful but not required

You’ll be able to

  • ✓Apply the intelligence cycle to plan, collect, process and disseminate CTI products aligned to stakeholder requirements
  • ✓Use David Bianco's Pyramid of Pain to prioritise indicators by the cost they impose on an adversary
  • ✓Run OSINT and dark web collection with sound tradecraft, source evaluation and operational security discipline
  • ✓Apply structured analytic techniques, including Analysis of Competing Hypotheses, to reduce cognitive bias in assessments
  • ✓Model and share threat data using MISP's Event, Attribute and Object structure
  • ✓Distinguish STIX as a data format from TAXII as a transport protocol and describe how they interoperate
  • ✓Write BLUF-style intelligence reports graded with the Admiralty/NATO system and marked for handling with the Traffic Light Protocol

Course Modules

Intelligence cycleStrategic vs operational vs tacticalPIRsStakeholder requirements

Data, information, intelligence

A raw IP address in a log file is data. Knowing that IP address was seen beaconing from a compromised host is information. Knowing that the IP belongs to infrastructure a specific ransomware affiliate rotates every few weeks, and what that means for how long a block list entry stays useful, is intelligence. Threat intelligence is the product of analysis: evidence-based knowledge, including context, mechanisms, indicators and implications, about an existing or emerging threat, produced to support a decision. If a report does not help someone decide something — block a domain, brief an executive, prioritise a patch, change a control — it is not really intelligence yet, no matter how many indicators it contains.

CTI is usually described at three levels. Strategic intelligence is long-range and non-technical, aimed at executives and boards: which threat actors and trends matter to this organisation's sector and geography over the next year, and what should that mean for budget and risk appetite. Operational intelligence sits in the middle, tracking specific campaigns, actor TTPs and infrastructure over weeks and months, and is consumed by security managers and incident responders planning defences. Tactical (sometimes called technical) intelligence is the most granular and short-lived: the IOCs, signatures and detection content that SOC analysts load into SIEM and EDR tooling today. A mature CTI function produces all three, because a board member and a SOC analyst need answers to different questions from the same underlying threat.

The intelligence cycle

Almost every intelligence discipline, from military intelligence to CTI, is organised around the same six-phase cycle. It is drawn as a loop because the output of one run feeds the requirements of the next.

  • •Direction (Planning & Direction) — stakeholders define Priority Intelligence Requirements (PIRs): the specific questions intelligence needs to answer, such as "are we likely to be targeted by initial access brokers selling VPN access in our sector?"
  • •Collection — analysts gather raw data against those requirements from OSINT, closed sources, telemetry, paid feeds and internal logs
  • •Processing — raw collection is normalised, deduplicated, decrypted, translated or otherwise converted into a form analysts can work with
  • •Analysis (Analysis & Production) — analysts evaluate, correlate and interpret processed information to produce an assessment that answers the original requirement
  • •Dissemination — the finished product is delivered to the stakeholder who asked for it, in a format and at a classification they can use
  • •Feedback — stakeholders tell the CTI function whether the product answered the question, which reshapes the next cycle's requirements

Why requirements come first

Programmes that skip the Direction phase tend to collect whatever is easiest — usually a firehose of open-source IOC feeds — and call the resulting noise "intelligence." Well-run CTI functions start every cycle from a small set of PIRs owned by named stakeholders, and they measure success by whether those stakeholders made better decisions, not by feed volume or indicator counts. The rest of this course follows the cycle in order: collection tradecraft, analytic technique, and the platforms and standards used to process, structure and disseminate the result.

References

Primary sources for the material above. Standards are cited by identifier so they stay findable as publishers reorganise their sites.

  1. attack.mitre.org
  2. activeresponse.org/wp-content/uploads/2013/07/dia…
  3. first.org/tlp
  4. oasis-open.github.io/cti-documentation
  5. misp-project.org
  6. cia.gov/resources/csi/books-monographs…