Triage and evaluate threat information: Review multiple sources of simulated threat intelligence, determine relevance, assess reliability and credibility, and identify information requiring further investigation.
Analyze threats and adversary behavior: Assess simulated threat actors, including their motivations, capabilities, targeting patterns, tactics, techniques, and procedures (TTPs), and determine their potential relevance to an organization.
Assess indicators in context: Evaluate indicators of compromise alongside supporting evidence rather than treating individual indicators as definitive proof of malicious activity.
Identify intelligence gaps: Determine what critical information is missing and define the additional intelligence required to improve security decision-making.
Develop intelligence requirements: Create or refine priority intelligence questions based on organizational assets, threat exposure, business priorities, and stakeholder needs.
Prioritize threats: Compare competing threats according to relevance, likelihood, potential impact, available evidence, and organizational priorities.
Apply structured analytical reasoning: Evaluate competing hypotheses, weigh evidence, document assumptions, and communicate why one assessment may be better supported than another.
Produce actionable intelligence: Synthesize multiple information sources into assessments explaining what is happening, why it matters, and what defensive priorities should be considered.
Communicate analytical confidence: Clearly articulate confidence levels, evidence quality, assumptions, and factors that limit certainty.
Brief decision-makers: Translate technical threat intelligence into concise, business-relevant insights and recommendations for senior or non-technical stakeholders.
Update assessments: Reassess previous conclusions when new intelligence becomes available and clearly explain how additional evidence changes—or does not change—the original assessment.
Create professional intelligence outputs: Develop threat assessments, threat actor profiles, executive intelligence briefs, intelligence requirements documents, TTP assessments, indicator assessments, confidence statements, threat prioritization reports, and intelligence updates.
Requirements
Cybersecurity and threat intelligence interest: Suitable for aspiring CTI analysts, cybersecurity students or graduates, SOC professionals seeking CTI exposure, career changers, intelligence or security professionals transitioning into cyber, self-taught practitioners, and professionals with relevant cybersecurity certifications.
Analytical reasoning: Ability to examine incomplete or conflicting information, identify patterns, weigh evidence, develop hypotheses, and reach reasoned conclusions.
Threat intelligence fundamentals: Understanding of threat intelligence concepts, threat actors, indicators of compromise, TTPs, threat assessments, intelligence requirements, and risk prioritization.
Source evaluation: Ability to assess the reliability, credibility, relevance, and limitations of information sources and explain how these factors affect analytical confidence.
Critical thinking: Strong attention to context and the ability to distinguish meaningful evidence from isolated or inconclusive information.
Decision support: Ability to turn technical or complex security information into practical, decision-useful intelligence and proportionate defensive recommendations.
Communication skills: Strong written and verbal communication, with the ability to present technical findings clearly to both technical and non-technical audiences.
Professional documentation: Ability to produce structured intelligence products such as assessments, executive briefs, intelligence requirements, threat profiles, and analytical updates.
Adaptability: Comfortable revisiting assumptions and updating conclusions when new information becomes available.
Ethical judgment: Commitment to using cybersecurity knowledge exclusively for legitimate defensive, educational, and professional-development purposes.
Remote working: Ability to work independently, manage analytical tasks effectively, and communicate findings in a remote environment.