Advanced Cyber Threat Intelligence Analyst

Advanced Cyber Threat Intelligence Analyst

Develop advanced knowledge and skills to become a dominant force in cyber threat intelligence.

100% Online • Self-Paced • Start Immediately

Advanced
• 70,000+ students trained • 4.9/5 average rating

What's Included

  • 40+ hours of training content
  • CREST Aligned CRTIA course
  • 87 units covering an extraordinary amount of content
  • Includes 27+ hours of video training
  • arcX final exam with free re-test included
Secure checkout 12 months access

Trusted by leading organisations worldwide

Deloitte
United States Air Force
Cyber Security Agency of Singapore
Ernst and Young
UK Ministry of Defence
Barclays
Accenture
KPMG
Raytheon
Hiscox
Crowdstrike
ST Engineering

For the analyst who already names the adversary

A breach hits and the headline writes itself: a famous nation-state, a familiar group, a confident verdict. A week later three rival hypotheses have splintered the story and none can be proven.

1 course

Naming an attacker is judgment, not proof. And knowing who an actor is still does not answer the question your stakeholders actually care about: do they genuinely threaten us, and what should we do first? A world-class APT with no reason to touch your network can matter less than a bored opportunist hammering an exposed login that happens to be yours.

This course sharpens the reads that separate a frightening name from a defensible assessment. You will weigh capability, intent and opportunity as three moving axes, measure motivation by intensity rather than category, rank indicators by how much they cost the adversary to abandon, and hand your judgment to a decision-maker who understands exactly how sure you are.

You get there by working real intrusions, not abstractions: the Conti attack on a national health service, a LockBit threat assessment, an APT41 report laid across the Diamond Model, the Phineas Fisher classification puzzle, and a Hammertoss command-and-control exercise. It is CREST aligned, building directly on the Practitioner course, and it treats attribution as a tool rather than a trap.

Product Overview

Designed to provide you with advanced knowledge and practical skills necessary to become a dominant force as a cyber threat intelligence analyst. Throughout this course, you will advance your understanding of cyber threat intelligence best practises and learn to apply techniques like OODA Loop and F3EAD Cycle to real-world scenarios.

You will be frequently tested and engage in practical exercises, including threat assessments and research of well-known cyber criminal groups like the Conti Ransomware Group and Lockbit.

This course is designed to build upon the foundational knowledge gained in our arcX Cyber Threat Intelligence Practitioner course (prerequisite course) and take your skills to the next level. By the end of this course, you will have the confidence and expertise needed to excel in a fast-paced and ever-evolving cybersecurity landscape.

This is a CREST accredited training course for the CREST Registered Threat Intelligence Analyst (CRTIA) examination. Combined with our cyber threat intelligence practitioner course, there is no better preparation for your CPTIA and CRTIA exams. If you successfully complete the final arcX exam, you'll earn the esteemed arcX Advanced Threat Intelligence Analyst certification. You can easily confirm this accomplishment on our website using a QR code.

Your Journey

This is the largest part of the course, and it turns 'who is this?' into 'do they threaten us, and what do we do first?'. You work through attribution at technical, operational and strategic levels, the motivation-capability-intent trinity and the role of opportunity, then apply it all to real cases: classifying Phineas Fisher, reconstructing the Conti ransomware attack on a health service, running a LockBit threat assessment, and mapping an APT41 intrusion across the Cyber Kill Chain and Diamond Model. You also learn to rank indicators of compromise on the Pyramid of Pain and manage their freshness so a stale IP block never poisons your detections.

  • You will distinguish technical, operational and strategic attribution and attach calibrated confidence bands to each claim
  • You will apply the capability, intent and opportunity trinity to decide which actor and which exposure to prioritise first
  • You will read motivation by intensity, not category, using observed persistence, investment and adaptation as proxies
  • You will lay a real intrusion across both the Kill Chain and the Diamond Model to build a single correlatable activity thread
  • You will rank IOCs as atomic, computed or behavioural, and assign first-seen dates and confidence decay so indicators age out before they harm legitimate traffic

Inside this module

  • Threat Actors and Attribution
  • Introduction
  • Threat Actors and the Unholy Trinity
  • Phineas Fisher Exercise Question
  • Phineas Fisher Exercise Answer
  • 'The Inbetweeners'
  • Motivation
  • Measuring Motivation
  • Intent
  • Capability
  • Conti Attack Exercise Question
  • Conti Attack Exercise Answer

This module covers the direction and review stage of the intelligence cycle, with the focus squarely on taking requirements from the customer. You learn to gather and shape intelligence requirements, prioritise them, and distinguish Priority Intelligence Requirements from ordinary IRs using weighted scoring models. It closes with project planning and review so a CTI engagement stays on brief, on time and genuinely useful to the person who commissioned it.

  • You will develop and document intelligence requirements from a customer brief
  • You will prioritise competing requirements using weighted scoring models
  • You will explain how PIRs differ from standard intelligence requirements and when each applies
  • You will plan and review a CTI project so it answers the question it was set

Inside this module

  • Introduction to Direction and Review
  • Intelligence Requirements
  • Prioritising Intelligence Requirements
  • PIRs and Weighted Scoring Models
  • Project Planning and Review
  • End of Module Test

This module builds on foundational collection and pushes into the technical craft of gathering data. You practise advanced search techniques, site scraping and bulk collection, and dig into web infrastructure through registration records, DNS and document metadata, learning the power of the pivot to move from one artefact to the next. It also covers CTI sharing communities, judging data reliability, handling human sources, and the legal, ethical and operational-security constraints that keep collection defensible.

  • You will use advanced search and site-scraping techniques to collect at scale
  • You will pivot across registration records, DNS and document metadata to expand on a single lead
  • You will assess the reliability of collected data and the risks of handling human sources
  • You will apply legal, ethical and operational-security guardrails to your collection activity

Inside this module

  • Google Sphere / Google-Fu
  • Web Content
  • Site Scraping and Bulk Data Collection
  • Web Infrastructure
  • Introduction to Web Infrastructure
  • Registration Records
  • Domain Name Server (DNS)
  • Power of the Pivot
  • Document Metadata
  • CTI Sharing Communities
  • Data Reliability
  • Human Sources

This module deepens core analytic tradecraft and aligns to the CREST syllabus. You work through idea and hypothesis generation and testing, scenarios and indicators, and the disciplined assessment of cause and effect, then learn to spot misinformation, run challenge analysis and support decisions. It finishes with decomposition and visualisation so complex findings become something a stakeholder can read and act on.

  • You will generate and test competing hypotheses against the evidence
  • You will assess and deconstruct cause and effect rather than assuming it
  • You will run structured and unstructured challenge analysis to stress-test your own conclusions
  • You will decompose and visualise findings to support a decision-maker

Inside this module

  • Introduction to Data Analysis
  • Idea Generation
  • Scenarios and Indicators
  • Hypothesis Generation and Testing
  • Cause and Effect
  • Assessment of Cause and Effect
  • Deconstructing Cause and Effect
  • Misinformation
  • Challenge Analysis
  • Decision Support
  • Decomposition and Visualisation
  • Data Analysis Conclusion

This module explains the dissemination phase of the intelligence cycle and how finished products actually reach their consumers. You examine forms of delivery, get an introduction to threat intelligence platforms, and study intelligence-sharing initiatives, including standards such as STIX and TAXII for exchanging threat data between organisations.

  • You will match forms of delivery to different consumer audiences
  • You will describe how a threat intelligence platform supports dissemination
  • You will explain how STIX and TAXII enable structured sharing between organisations
  • You will position dissemination correctly within the intelligence cycle

Inside this module

  • Forms of Delivery
  • Threat Intelligence Platform Introduction
  • Intelligence Sharing Initiatives
  • End of Module Test

This module covers the managerial considerations behind a CTI programme and the aspects that need oversight. You learn to understand, manage and explain risk, including the use of structured risk scales, and study regulator-mandated threat intelligence schemes in depth. It closes with reporting, connecting managerial oversight to the products the programme delivers.

  • You will understand and communicate risk using a structured risk scale
  • You will explain regulator-mandated threat intelligence schemes and their purpose
  • You will identify which parts of a CTI programme require management oversight
  • You will link reporting to programme-level decision-making

Inside this module

  • Risk
  • Understanding and Managing Risk
  • Explaining Risk
  • Regulator Mandated Threat Intelligence Schemes
  • Introduction
  • Regulator Mandated TI Schemes In Depth
  • Reporting
  • End of Module Test

This module grounds your analysis in the technical layer. You cover IP protocols, cryptography and vulnerabilities and intrusion vectors, with a MITRE ATT&CK demonstration, then move into command and control and exfiltration techniques. Hands-on exercises include a geofencing task and a Hammertoss command-and-control analysis, so you can read technical tradecraft and describe it precisely to a stakeholder.

  • You will interpret IP protocols and apply cryptography concepts to your analysis
  • You will map adversary behaviour with MITRE ATT&CK
  • You will work through the Hammertoss exercise to analyse command-and-control tradecraft
  • You will identify vulnerabilities, intrusion vectors and exfiltration techniques in an intrusion

Inside this module

  • IP Protocols
  • Geofencing Exercise Question
  • Geofencing Exercise Answer
  • Cryptography
  • Vulnerabilities
  • Intro to Vulnerabilities and Intrusions Vectors
  • MITRE ATT&CK Demonstration
  • Vulnerabilities and Intrusion Vectors
  • Command and Control
  • Hammertoss Exercise Question
  • Hammertoss Exercise Answer
  • Exfiltration Techniques

What You'll Learn

Attribute malicious activity at technical, operational and strategic levels and attach an honest confidence band to every claim
Assess an actor with the capability, intent and opportunity trinity and defend which threat and which exposure to prioritise first
Measure motivation by intensity, reading persistence, investment and adaptation from behaviour rather than stated feelings
Reconstruct a real intrusion across the Cyber Kill Chain and Diamond Model to produce a single correlatable activity thread
Rank indicators of compromise on the Pyramid of Pain and manage their freshness with first-seen dates and confidence decay
Gather and prioritise intelligence requirements from a customer, distinguishing PIRs with weighted scoring models
Generate and test competing hypotheses, assess cause and effect, and stress-test conclusions with challenge analysis
Map adversary behaviour with MITRE ATT&CK and describe command-and-control and exfiltration tradecraft precisely

Skills You'll Gain

Cyber threat actor attributionCapability, intent and opportunity assessmentMotivation intensity analysisDiamond Model of Intrusion AnalysisCyber Kill Chain analysisPyramid of Pain and IOC managementMITRE ATT&CK mappingIntelligence requirements and PIR prioritisationHypothesis generation and challenge analysisOSINT collection and pivotingSTIX and TAXII intelligence sharingRisk communication and CTI reporting

How This Course Is Delivered

This course is delivered through a combination of interactive content and practical exercises.

Video Content

Immerse yourself in the arcX Advanced Cyber Threat Intelligence training course through its core delivery method: video. You'll have access to a comprehensive series of videos, collectively spanning over 27 hours of content.

Quizzes

Our bespoke testing engine will ensure you experience a combination of free-form and adaptive tests. These are thoughtfully integrated to reinforce your learning and consistently evaluate your skills.

Practical Exercises

You'll engage in numerous micro-exercises, requiring just a few minutes to complete, and more extensive research projects that extend over hours. Each exercise is structured to gauge your comprehension of various concepts.

Reading Material

Included in the course are downloadable intelligence reports and research papers, strategically provided to enhance your understanding of the taught concepts and expand upon them.

Who This Course Is For

This is an advanced course for people already working in, or moving deeper into, cyber threat intelligence. It builds directly on the ArcX Cyber Threat Intelligence Practitioner course, which is a prerequisite.

  • Analysts who have completed the ArcX Cyber Threat Intelligence Practitioner course
  • Candidates studying towards the CREST Registered Threat Intelligence Analyst (CRTIA) exam
  • Serving threat intelligence professionals wanting to sharpen attribution and assessment tradecraft
  • Security practitioners looking to enrich their daily work with deeper analytic technique and structured judgment

Course Details

Stewart K Bertram

Instructor

Stewart K Bertram

Stewart has worked within the field of Intelligence and Security for the past 20 years with experience across both the private and public sector. Starting his career in 2004 in the Intelligence Corps of the British Army, Stewart entered the private sector in 2009 and has held a number of roles in Cyber Threat Intelligence (CTI) since then. These have included product development, service delivery and consulting, with his most recent roles involving the management of specialist teams involved in research into the cyber criminal underground and nation state threat actors. Holding both a Masters in Computing and a Master of Letters in Terrorism Studies from St. Andrews University. Stewart was also among the first in the world to pass the CREST Certified Threat Intelligence Manager (CCTIM) examination. Stewart’s research interests and work have always sat at the intersection of technology, security and people focused issues. These unique areas of focus are bought to bare within his role at arcX, where he is responsible for the design and delivery of the core CREST related CTI courses and oversight of the wider Cyber Threat Intelligence stream.

Difficulty Level

Advanced

Language

en

Available Subtitles

EnglishArabicHindiSpanishChinese (simplified)FrenchGermanPortuguese

On completion you earn the ArcX Advanced Level Threat Intelligence Analyst (ATIA) credential. The course is CREST aligned and covers nearly every element of the CREST Registered Threat Intelligence Analyst (CRTIA) examination.

Student Reviews

Trusted by Security Professionals

Join 70,000+ professionals who have advanced their careers with arcX training

Advanced Career

"The courses provided by arcX are the best in terms of content and structure I have come across, that are aligned to CREST's CPTIA and CRTIA exams. An absolute must for anyone wanting to pursue these certifications but also anyone wanting to gain a solid baseline knowledge set for a career in CTI."

C

Chris

Cyber Threat and Risk Manager

Earned Certification

"Great content and fantastic customer service. Put me in a great position to gain my qualification. 10/10 recommend."

D

Dan

Cyber Security Project Manager

Promoted to Senior

"I have done courses in offensive security, networking, forensics and malware. All from prestigious training vendors. None compare to arcX. I secured a straight transition into a senior CTI role. The platform provided me with insights into my strengths and weaknesses and allowed me to track changes. Very grateful to the guys for this!"

P

Pat

Senior Threat Intelligence Analyst

Frequently Asked Questions

About This Course

No. There are no hosted virtual labs. Every tool and technique demonstrated, from search and scraping to DNS and metadata pivoting, is practised on your own operating system, so you will need to work through them in your own environment.
Yes. The ArcX Cyber Threat Intelligence Practitioner course is a prerequisite. This Advanced course assumes that foundation and builds on it, revisiting concepts such as the motivation, capability and intent model before pushing them much further.
Yes. The course is CREST aligned and covers nearly every element of the CREST Registered Threat Intelligence Analyst (CRTIA) examination, including the shared legal and ethical requirements of the CREST syllabus. Completing it also earns the ArcX Advanced Level Threat Intelligence Analyst (ATIA) credential.
Both. Alongside the concepts, you work practical exercises on real material: classifying Phineas Fisher, reconstructing the Conti ransomware attack on a health service, a LockBit threat assessment, an APT41 report against the Diamond Model, a geofencing task and a Hammertoss command-and-control analysis. Many exercises include a walkthrough of the instructor's own answer for comparison.
It is built for real work. The course treats attribution as calibrated confidence rather than false certainty, and shows how knowing the likely actor sharpens defensive prioritisation, threat modelling, expected TTPs and incident response. You learn to hold uncertainty and usefulness together.

General Course FAQs

Click your avatar in the top right corner and select Contact Support, or email us directly at [email protected]. We typically respond within 24-hours.

You will have 12 months access after activating your course in accordance with our Terms & Conditions. You can work through your course at a pace that suits you. Once you have completed your course you will retain access and be able to refresh your knowledge anytime within the access period.

Our courses are delivered on-demand. This means you can start and stop learning whenever you like. There is no time limit and no restriction on how many times you can access course content.

No. CREST exam vouchers need to be purchased separately through CREST or Pearson VUE. You can find further information on our CREST Accreditation page.

Absolutely! Demonstrating your dedication to professional development in cyber security is always valuable. Our certifications are recognised by partner organisations who value our training.

Yes! You can create individual accounts and purchase courses through our portal for instant access. For multiple employees, please contact us for volume pricing.

Yes! We're always happy to speak with industry experts interested in producing high-quality training courses. Become an instructor and help make a positive impact on someone's career.

If you bought a course before this change, you keep lifetime access to it. The new terms only apply to new purchases.

Can't find what you're looking for? Get in touch