Defensive Security

CA303: Cyber Threat Intelligence

Course authored by:

Drinor Selmanaj, Perparim Mjeku, Rinor Shehu, Altin Gashi

25 Hours of Instruction

Includes lectures, guest speakers, and Q&A sessions

Hands-on
labs

13 Labs

Live Online or On-Demand Access

Join weekly synchronous sessions or access all material and recorded lectures anytime

Intermediate

Developing practical skills and deepening understanding of core concepts

Prerequisite

  • CA401 Linux Operations

Course Overview

Most organizations drown in data and still get surprised by attacks. This course builds practical CTI and OSINT capability for proactive security operations — working through the full intelligence lifecycle from requirements definition to collection, analysis, and dissemination. You analyze threat actors, their motivations, and real-world attack methodologies across tactical, operational, and strategic levels. OSINT techniques are applied under realistic constraints, and frameworks including MITRE ATT&CK and the Diamond Model are used to map and interpret adversary behavior. By the end, you can produce actionable intelligence that drives defensive decisions.

What You’ll Learn

* Understand the threat intelligence lifecycle and differentiate data from actionable intelligence
* Analyze threat actors, motivations, and TTPs at tactical, operational, and strategic levels
* Apply MITRE ATT&CK and the Diamond Model to map adversary behavior
* Conduct OSINT investigations using structured methodologies and tools
* Integrate threat intelligence into SOC, SIEM, and incident response workflows

Business Takeaways

* Shift from reactive security to proactive threat anticipation
* Improve incident detection and response with contextual intelligence
* Reduce alert fatigue by focusing on relevant, high-signal threats
* Prioritize risk based on real-world adversary activity and behavior

Syllabus: 4 Sections to Transformation

The CA303 program develops your ability to think like an intelligence analyst, turning raw information into actionable insight. You progress from understanding how intelligence works to conducting real-world investigations using OSINT and analytical frameworks.

syllabus overview

Justify Training to Your Manager

section 1

THREAT INTELLIGENCE FOUNDATIONS

Focuses on threat intelligence fundamentals, intelligence analysis methodologies, attacker profiling, and frameworks used to understand, track, and contextualize cyber threats.

TOPICS COVERED

  • What threat intelligence really is (context and actionable insight, not raw data).
  • Intelligence lifecycle (requirements, collection, analysis, dissemination, feedback).
  • Tactical vs Operational vs Strategic intelligence (pyramid on page 24).
  • Intelligence frameworks (MITRE ATT&CK, Kill Chain, Diamond Model).
  • Threat actors: types, motivations, and profiling.

LABS

  • Threat Intelligence Mapping
  • Kill Chain
  • Diamond Model

Section 2

MALWARE & INTELLIGENCE OPERATIONS

Focuses on malware analysis, detection methodologies, threat hunting, and integrating cyber threat intelligence into operational security environments such as SOCs and detection workflows.

TOPICS COVERED

  • Malware types (ransomware, spyware, rootkits).
  • Static vs dynamic vs behavioral analysis.
  • YARA rules and detection logic.
  • Integrating CTI into SOC (SIEM, SOAR, detection engineering).
  • Threat hunting vs detection vs investigation.
  • OPSEC for analysts (very important, often skipped).

LABS

  • Reverse Engineering Malware
  • Static vs Dynamic Malware Analysis Comparison

section 3

OSINT FOUNDATIONS & TECHNIQUES

Focuses on open-source intelligence collection, source validation, digital footprint analysis, social engineering techniques, and investigative methodologies used in real-world intelligence gathering.

TOPICS COVERED

  • OSINT lifecycle aligned with intelligence lifecycle.
  • Source validation and reliability scoring.
  • Legal & ethical boundaries (critical for real-world use).
  • Social engineering techniques (phishing, pretexting, baiting).
  • Doxing and digital footprint tracking.

LABS

  • Social Engineering Toolkit
  • TOR Browser
  • Google Dorking
  • Phishing

section 4

OSINT SOURCES, TOOLS & APPLICATION

Focuses on practical OSINT collection using public data sources and intelligence tools for threat monitoring, attack surface discovery, reputation analysis, and real-world investigative operations.

TOPICS COVERED

  • OSINT sources:
    Social media, public records, forums, leaks.
  • Threat monitoring & early warning indicators.
  • External attack surface discovery.
  • OSINT tools:
    Search engines, scraping tools, Maltego, IntelX.
  • Business use:
    Competitive intelligence
    Reputation monitoring
    Industrial espionage basics

LABS

  • OSINT Tools
  • Maltego
  • IntelX
  • Shodan

Course Schedule
& Pricing

Looking for Group Purchase Options? See below

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Frequently Asked Questions

Mission-critical information for prospective operatives

What is Cyber Threat Intelligence (CTI)?

Cyber Threat Intelligence is analyzed and contextualized information about threats that helps organizations make informed security decisions. Instead of just listing indicators, it explains attacker behavior and provides clear guidance on how to detect, prevent, and respond to attacks.

Raw data includes indicators like IP addresses or domains, but on its own it has limited value. Threat intelligence adds context, analysis, and relevance, turning that data into something actionable. Without this context, security teams often face false positives and unnecessary workload.

Protect vital IT resources. Review real exploits and master Windows/Linux security functionality.

OSINT, or Open-Source Intelligence, is information collected from publicly available sources such as social media, forums, and leaked data. It allows organizations to monitor threats outside their environment, identify exposed assets, and detect attacks before they impact internal systems.

Indicators like IPs and file hashes change quickly and are easy for attackers to replace. Modern threat intelligence focuses on attacker behavior, such as tactics and techniques, which are much harder to hide. This allows defenders to detect attacks even when specific indicators are no longer valid.