Cyber Threat Intelligence Practitioner
This is the foundation of the path, translating the discipline's semi-military language into practice you can apply at a desk. It walks the full intelligence cycle from direction through collection, analysis and dissemination: setting intelligence requirements from a customer's brief, grading sources, pivoting leads in Maltego, testing ideas with Analysis of Competing Hypotheses, guarding against bias and circular reporting, and reporting with honest estimative language. It also grounds you in the UK legal and ethical framework, from the Computer Misuse Act to the CREST code of conduct, and aligns to the CREST CPTIA syllabus.
A firewall log, a leaked credential dump and a boast on a criminal forum all land in your queue at once. Threat intelligence is deciding which one matters, and what it means.
- Run the full intelligence cycle from direction through collection, analysis and dissemination
- Map real intrusions using the Diamond Model and the Lockheed Martin Cyber Kill Chain
- Categorise threat actors by motive, affiliation and TTPs, from nation-state APTs to cybercriminals












