This three-day course explains how to apply the discipline of intelligence analysis to the cyber domain. The course covers strategic subjects such as the organizational role of cyber threat intelligence (CTI) and stakeholder analysis, as well as analytic practitioner skills development topics, such as understanding the intelligence lifecycle, developing raw data into minimally viable intelligence, and an introduction to cyber intelligence attribution.
A working understanding of basic information security principles. A general understanding of threat intelligence and indicators of compromise (IoCs). Experience conducting forensic analysis, network traffic analysis, log analysis, security assessments and penetration testing, security architecture and system administration duties are a plus, but not required.
After completing this course, learners should be able to: • Understand various definitions of threat intelligence and attribution • Distinguish between tactical, operational and strategic threat intelligence • Use tactical intelligence in the early stages of a cyber attack to evaluate data and correctly identify indicators that can be grouped into a set of related activity and attributed to a threat group • Gain insight into common errors that can occur when analyzing common forensic artifacts and interpreting information presented from various sources • Examine operational and strategic intelligence to determine the attribution and sponsorship of an attack operation • Understand how attribution analysis can provide crucial context to threat activity that enables more informed decisions and improved resource allocation • Understand why attributing cyber operations to a threat group can have significant implications — and even affect geopolitical dynamics • Consider attribution from a threat group’s point of view
The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):
If you would like to provide feedback on this course, please e-mail the NICCS team at NICCS@mail.cisa.dhs.gov. Please keep in mind that NICCS does not own this course or accept payment for course entry. If you have questions related to the details of this course, such as cost, prerequisites, how to register, etc., please contact the course training provider directly. You can find course training provider contact information by following the link that says “Visit course page for more information...” on this page.