# Cyber Threat Intelligence: Building and Running an Intel Function Course

Canonical URL: <https://www.graduateschool.edu/courses/cyber-threat-intelligence-course>

## Overview

Cyber threat intelligence is often taught as a set of hunting techniques. This course treats it as the broader discipline that hunting sits inside, covering the full intelligence lifecycle.

Learners set intelligence requirements, evaluate sources, apply the Diamond Model and MITRE ATT&CK, and package findings for different audiences, applying the Traffic Light Protocol before sharing. The course closes with how intelligence is routed to hunting and incident response teams. No hands-on lab is required.

## What you'll learn

- Explain how cyber threat intelligence differs from threat hunting and where each fits in a security program.
- Set intelligence requirements that reflect an organization's actual risks and decision needs.
- Evaluate open source, technical, and closed source collection sources for reliability and relevance.
- Apply structured analytic techniques, including the Diamond Model of Intrusion Analysis, to reduce analytic bias.
- Map adversary behavior to the MITRE ATT&CK framework to support consistent analysis and reporting.
- Assign confidence levels to intelligence judgments and communicate uncertainty clearly.
- Write intelligence products suited to executive, operational, and tactical audiences.
- Apply the Traffic Light Protocol to control how shared intelligence is handled and redistributed.
- Identify the information-sharing bodies and mechanisms relevant to a given sector.
- Design the staffing, tooling, and workflow of a cyber threat intelligence function.
- Select metrics that show whether an intelligence function is producing usable analysis.
- Route finished intelligence to threat hunting, incident response, and vulnerability management teams so it drives action.
- Build a feedback loop that keeps intelligence requirements current as the threat environment changes.

## Prerequisites

Familiarity with basic networking and security operations concepts, equivalent to [Networking Fundamentals for Security](/courses/networking-fundamentals-for-security-course).

## Curriculum

#### Module 1: Foundations of Cyber Threat Intelligence

- Lessons: 
  - What Cyber Threat Intelligence Is and Is Not
  - The Four Levels of Intelligence: Strategic, Operational, Tactical, Technical
  - Threat Intelligence and Threat Hunting: Parent and Consumer
  - The Intelligence Lifecycle at a Glance

- Applied activity: Learners sort a set of sample intelligence products, such as an executive briefing, a SOC alert, an indicator feed, and a hunting hypothesis, by intelligence level and justify each placement.

#### Module 2: Planning and Collection

- Lessons: 
  - Setting Intelligence Requirements
  - Open Source and Technical Collection
  - Closed Source and Commercial Feeds
  - Evaluating Collection Sources

- Applied activity: Learners draft a set of priority intelligence requirements for a hypothetical organization and select which collection sources would satisfy each requirement.

#### Module 3: Processing and Analysis

- Lessons: 
  - Structured Analytic Techniques
  - The Diamond Model of Intrusion Analysis
  - Mapping Adversary Behavior to MITRE ATT&CK
  - Confidence Levels and Analytic Bias

- Applied activity: Learners take a short incident narrative, plot it on the Diamond Model, map the observed behavior to MITRE ATT&CK, and assign a confidence level to their conclusion.

#### Module 4: Dissemination and Sharing

- Lessons: 
  - Writing Intelligence Products for Different Audiences
  - The Traffic Light Protocol
  - Information Sharing Organizations and Mechanisms
  - Handling Sensitive and Shared Intelligence

- Applied activity: Learners take one analytic finding from Module 3 and produce two versions of it, an executive summary and a technical bulletin, each correctly labeled with a Traffic Light Protocol marking.

#### Module 5: Building and Running the Intel Function

- Lessons: 
  - Team Structure and Roles
  - Threat Intelligence Platforms and Tooling
  - Integrating Intelligence with the Security Program
  - Measuring Program Value

- Applied activity: Learners sketch a staffing and workflow plan for a small intelligence function supporting a stated organization, including how intelligence reaches the security operations center.

#### Module 6: From Intelligence to Action

- Lessons: 
  - Handing Intelligence to Threat Hunting
  - Handing Intelligence to Incident Response
  - The Hunting Ladder as One Consumer of Intelligence
  - Closing the Feedback Loop and Maturing the Function

- Applied activity: Learners take the finished intelligence product from Module 4 and draft one hunting hypothesis and one incident response question it should answer, then propose a feedback update to the original intelligence requirement.

## Schedule
- Jan 12, 2027 – Jan 13, 2027 — Live Online
- Jun 14, 2027 – Jun 15, 2027 — Live Online
- Sep 9, 2027 – Sep 10, 2027 — Live Online

## Pricing

**Tuition:** $1049
