Course Outline
Foundations of Cyber Threat Intelligence (CTI)
- Defining CTI and its significance
- Categories of CTI: Tactical, Operational, Strategic, and Technical
- Essential concepts and terminology
- Recognizing various cyber threats such as malware, phishing, and ransomware
- Historical context of cyber threats and attacks
- Current developments in the threat landscape
- Phases of the intelligence lifecycle
Methods for Data Collection
- Origins of intelligence data (open sources, dark web, internal feeds)
- Strategies for acquiring data
- Tools and technologies employed in collection
Data Processing and Enhancement
- Techniques for processing data
- Normalizing and enriching data sets
- Automating processing tasks with specialized tools
Analytical Methods for Intelligence
- Analytical approaches: link analysis, trend analysis, and behavioral analysis
- Instruments for conducting intelligence analysis
- Practical drills focusing on data evaluation
Overview of Threat Intelligence Platforms (TIPs)
- Introduction to leading TIPs (e.g., MISP, ThreatConnect, Anomali)
- Primary features and capabilities of TIPs
- Integrating TIPs with other security solutions
Practical Application of Threat Intelligence Platforms
- Session on configuring and utilizing a TIP
- Managing data ingestion and correlation
- Personalizing alerts and generating reports
Automation within Threat Intelligence
- The role of automation in CTI workflows
- Techniques and tools for automating intelligence processes
- Exercises involving automation scripts
The Value of Information Sharing
- Advantages and hurdles in sharing threat intelligence
- Frameworks and models for sharing (e.g., STIX/TAXII, OpenC2)
Establishing an Information Sharing Community
- Best practices for creating a sharing network
- Legal and ethical factors to consider
- Case studies highlighting successful sharing initiatives
Joint Threat Intelligence Activities
- Carrying out collaborative threat analysis
- Simulated scenarios for intelligence exchange
- Formulating strategies for effective teamwork
Sophisticated Threat Intelligence Approaches
- Applying machine learning and AI within CTI
- Advanced techniques for threat hunting
- Developing trends in the CTI sector
Analysis of Cyber Attack Case Studies
- In-depth review of significant cyber incidents
- Key takeaways and intelligence perspectives
- Exercises in drafting intelligence reports
Creating a CTI Program
- Procedures for establishing and maturing a CTI initiative
- Metrics and KPIs for assessing CTI performance
Recap and Future Directions
Requirements
- Fundamental grasp of cybersecurity principles and protocols
- Proficiency in network and information security concepts
- Background experience with IT systems and infrastructure
Target Audience
- Cybersecurity professionals
- IT security analysts
- Security Operations Center (SOC) personnel
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.