Cyber Threat Intelligence Bundle

Cyber Threat Intelligence Bundle

Become a Cyber Threat Intelligence (CTI) powerhouse with the ultimate CTI training bundle

100% Online • Self-Paced • Start Immediately

Intermediate to
Advanced
• 70,000+ students trained • 4.9/5 average rating

What's Included

  • 65+ hours of training content
  • CREST Accredited training courses
  • 135 units covered in 44+ hours of video content
  • Undertake the arcX final exams for both the Practitioner and Advanced course
  • 100% online and on-demand self-study courses
  • 49 engaging exercises
  • 1,400+ practice questions
Secure checkout 12 months access

Trusted by leading organisations worldwide

Deloitte
United States Air Force
Cyber Security Agency of Singapore
Ernst and Young
UK Ministry of Defence
Barclays
Accenture
KPMG
Raytheon
Hiscox
Crowdstrike
ST Engineering

The full arc, from first framework to named adversary

An intrusion leaves almost nothing behind: no fixed address, no face, just fragments in a log and a boast on a forum. Learning to read those fragments, then defend a verdict on who is behind them, is a craft you build in stages.

2 courses

This bundle is that craft in two deliberate stages. You begin as a practitioner learning the shape of the discipline: the intelligence cycle, the Diamond Model, the Cyber Kill Chain, and how a two-page brief aimed at the right question beats three weeks of unaimed brilliance. You learn to take direction from an intelligence customer, grade sources with the Admiralty and 5x5x5 systems, pivot leads in Maltego, and stress-test your own thinking with Analysis of Competing Hypotheses before a conclusion hardens.

From there the path turns technical and adversary-focused. You move past naming a threat actor to weighing their motivation, capability and intent; to picking apart the crossover between nation states, cybercriminals and hacktivists; and to grounding attribution in real cases like Conti, LockBit and Phineas Fisher. You add IP protocols, DNS and registration records, MITRE ATT&CK, command-and-control and exfiltration analysis, then wrap it in the management and reporting skills a real programme demands.

You start able to explain what threat intelligence is for. You finish able to run the investigation, defend the assessment, and deliver it in a form a decision-maker will act on. Two courses, one continuous route through the field.

Product Overview

Prepare to become a Cyber Threat Intelligence powerhouse with the Cyber Threat Intelligence training bundle! With this CTI bundle deal, you'll gain a comprehensive understanding of CTI from foundation to advanced level.

The Practitioner course is perfect for both beginners and those with basic knowledge of CTI, as it provides an in-depth overview of the role of a CTI analyst and equips you with the fundamental skills needed to operate within a Threat Intelligence team.

But that's just the beginning! With the Advanced course, you'll take your skills to the next level and become a dominant force in the field. You'll learn cutting-edge techniques and how to apply them. You'll engage in carefully crafted practical exercises, including researching well-known cyber criminal groups like the Conti Ransomware Group and Lockbit. By the end of this course, you'll have the confidence and expertise needed to excel in the fast-paced and ever-evolving cybersecurity landscape.

Get ready to take the CTI world by storm with the ultimate Cyber Threat Intelligence course collection from arcX. But remember, the Practitioner course is a prerequisite for the Advanced course, so make sure to start with the fundamentals before leveling up to become a CTI superstar.

What's Included

2 courses in this bundle

Cyber Threat Intelligence Practitioner

This is the foundation of the path, translating the discipline's semi-military language into practice you can apply at a desk. It walks the full intelligence cycle from direction through collection, analysis and dissemination: setting intelligence requirements from a customer's brief, grading sources, pivoting leads in Maltego, testing ideas with Analysis of Competing Hypotheses, guarding against bias and circular reporting, and reporting with honest estimative language. It also grounds you in the UK legal and ethical framework, from the Computer Misuse Act to the CREST code of conduct, and aligns to the CREST CPTIA syllabus.

A firewall log, a leaked credential dump and a boast on a criminal forum all land in your queue at once. Threat intelligence is deciding which one matters, and what it means.

  • Run the full intelligence cycle from direction through collection, analysis and dissemination
  • Map real intrusions using the Diamond Model and the Lockheed Martin Cyber Kill Chain
  • Categorise threat actors by motive, affiliation and TTPs, from nation-state APTs to cybercriminals
6 modules93 lessons Practitioner Level Threat intelligence Analyst
Explore the full course

Advanced Cyber Threat Intelligence Analyst

This stage builds directly on the Practitioner course and takes you into the hardest part of the job: attribution and technical depth. You dissect threat actors through motivation, capability and intent, explore the crossover 'inbetweeners' between nation states, criminals and hacktivists, and work real cases like Conti, LockBit and Phineas Fisher. You add technical fluency in IP protocols, DNS, document metadata, MITRE ATT&CK, command-and-control and exfiltration, apply methodologies such as the OODA loop, F3EAD and CBEST narrative structure, and cover the management, risk and regulator-mandated schemes that surround a real programme. It aligns to the CREST CRTIA syllabus.

A breach hits and the headline writes itself: a famous nation-state, a familiar group, a confident verdict. A week later three rival hypotheses have splintered the story and none can be proven.

  • Attribute malicious activity at technical, operational and strategic levels and attach an honest confidence band to every claim
  • Assess an actor with the capability, intent and opportunity trinity and defend which threat and which exposure to prioritise first
  • Measure motivation by intensity, reading persistence, investment and adaptation from behaviour rather than stated feelings
7 modules96 lessons Advanced Level Threat Intelligence Analyst
Explore the full course

Who This Course Is For

This bundle suits anyone who wants the complete route through cyber threat intelligence in one purchase, rather than buying each stage separately and deciding later whether to continue.

  • Newcomers to CTI who want a foundation and a clear onward path in a single commitment
  • Analysts already working in threat intelligence who want to formalise and extend their skills
  • Incident responders, SOC analysts and penetration testers broadening into intelligence work
  • Learners preparing for both the CREST CPTIA and CRTIA examinations in sequence
  • Professionals who want attribution, technical analysis and programme-management skills built on a solid foundation

The two courses in this bundle carry their own certifications: the Practitioner Level Threat Intelligence Analyst (PTIA) and, at the advanced stage, the Advanced Level Threat Intelligence Analyst (ATIA). The Practitioner course is built around the CREST CPTIA syllabus and the Advanced course covers nearly every element of the CREST CRTIA syllabus, with identical legal and ethical requirements across both.

Student Reviews

Trusted by Security Professionals

Join 70,000+ professionals who have advanced their careers with arcX training

Advanced Career

"The courses provided by arcX are the best in terms of content and structure I have come across, that are aligned to CREST's CPTIA and CRTIA exams. An absolute must for anyone wanting to pursue these certifications but also anyone wanting to gain a solid baseline knowledge set for a career in CTI."

C

Chris

Cyber Threat and Risk Manager

Earned Certification

"Great content and fantastic customer service. Put me in a great position to gain my qualification. 10/10 recommend."

D

Dan

Cyber Security Project Manager

Promoted to Senior

"I have done courses in offensive security, networking, forensics and malware. All from prestigious training vendors. None compare to arcX. I secured a straight transition into a senior CTI role. The platform provided me with insights into my strengths and weaknesses and allowed me to track changes. Very grateful to the guys for this!"

P

Pat

Senior Threat Intelligence Analyst

Frequently Asked Questions

About This Course

Yes. The Cyber Threat Intelligence Practitioner course is the intended starting point and is a prerequisite for the Advanced course, which explicitly builds on the frameworks, intelligence cycle and analysis techniques introduced first. Working through them in sequence is how the path is designed.
Yes. The Practitioner course is designed to lower the barrier to entry, translating concepts like the kill chain and the pyramid of pain into relatable, applicable ideas, and starting from beginner-level key concepts. The Advanced course then takes you into deeper attribution and technical material once that foundation is in place.
The Practitioner course is based around the CREST CPTIA syllabus, and the Advanced course covers nearly every element of the CREST CRTIA syllabus. The legal and ethical requirements are identical across both examinations. The courses prepare you for these exams; the exams themselves are administered by CREST.
Plenty. You research infamous threat actor groups, map evidence to the Diamond Model and Cyber Kill Chain using real reports on Avaddon ransomware and the Carbanak Great Bank Robbery, pull intelligence requirements from a customer email, and use tools like Maltego and Boolean search operators. The Advanced course adds threat assessments of groups such as Conti and LockBit and technical exercises on geofencing and Hammertoss.
If you already know you want the full route into CTI, including attribution, technical analysis with MITRE ATT&CK, DNS and metadata, and the management side of running a programme, the bundle commits you to the whole path in one purchase. If you only want to test the foundations first, the Practitioner course stands on its own.
The courses aim to stay software-agnostic, but Maltego comes up repeatedly and is worth learning; the free Community Edition is used for exercises. The Advanced course also demonstrates the MITRE ATT&CK framework as part of its technical material.

General Course FAQs

Click your avatar in the top right corner and select Contact Support, or email us directly at [email protected]. We typically respond within 24-hours.

You will have 12 months access after activating your course in accordance with our Terms & Conditions. You can work through your course at a pace that suits you. Once you have completed your course you will retain access and be able to refresh your knowledge anytime within the access period.

Our courses are delivered on-demand. This means you can start and stop learning whenever you like. There is no time limit and no restriction on how many times you can access course content.

No. CREST exam vouchers need to be purchased separately through CREST or Pearson VUE. You can find further information on our CREST Accreditation page.

Absolutely! Demonstrating your dedication to professional development in cyber security is always valuable. Our certifications are recognised by partner organisations who value our training.

Yes! You can create individual accounts and purchase courses through our portal for instant access. For multiple employees, please contact us for volume pricing.

Yes! We're always happy to speak with industry experts interested in producing high-quality training courses. Become an instructor and help make a positive impact on someone's career.

If you bought a course before this change, you keep lifetime access to it. The new terms only apply to new purchases.

Can't find what you're looking for? Get in touch