Cyber Threat Intelligence Practitioner

Cyber Threat Intelligence Practitioner

Learn the fundamental techniques and skills to shine in your career as a cyber threat intelligence analyst

100% Online • Self-Paced • Start Immediately

Intermediate
• 70,000+ students trained • 4.9/5 average rating

What's Included

  • 25+ hours of training content
  • CREST accredited CPTIA course
  • 48 units covering over 120 concepts
  • Includes 17+ hours of video training
  • arcX final exam with free re-test included
  • 100% Online and on-demand self-study course
  • 21 engaging exercises
  • 500+ practice questions
Secure checkout 12 months access

Trusted by leading organisations worldwide

Deloitte
United States Air Force
Cyber Security Agency of Singapore
Ernst and Young
UK Ministry of Defence
Barclays
Accenture
KPMG
Raytheon
Hiscox
Crowdstrike
ST Engineering

Turn raw data into decisions defenders can act on

A firewall log, a leaked credential dump and a boast on a criminal forum all land in your queue at once. Threat intelligence is deciding which one matters, and what it means.

1 course

Organisations are collecting more threat data than they have ever been able to read. Feeds, samples, forum chatter and telemetry pour in, but most of it is just noise until an analyst decides what it is worth and what a decision-maker should do about it. That decision is the whole job, and it is where careers are made.

This course takes you through the full intelligence cycle as a working practitioner does it: setting direction from the intelligence customer, collecting from technical and human sources, grading their reliability, testing competing hypotheses against your own bias, and delivering a finished product in language a stakeholder cannot misread.

You will work with the frameworks the field actually runs on, the Diamond Model, the Lockheed Martin Cyber Kill Chain, Analysis of Competing Hypotheses and Words of Estimative Probability, and apply them to real cases like APT1, Fancy Bear, Carbanak and Avaddon ransomware. Built around the CREST CPTIA syllabus, it turns semi-military jargon into skills you can use on Monday morning.

Product Overview

Are you ready to venture into the dynamic realm of cyber threat intelligence (CTI)? Look no further than the arcX Cyber Threat Intelligence Practitioner course – your ultimate gateway to this exciting field and your optimal preparation for the CPTIA exam. Designed to cater to both novices and individuals possessing a foundational understanding of CTI, this comprehensive course aims to demystify the role of a CTI analyst while equipping you with the essential knowledge and competencies to excel within a Threat Intelligence team.

Experience a transformative learning opportunity as you acquire crucial proficiencies, including intelligence requirement gathering, strategic collection planning, information analysis, and the creation of actionable intelligence.

The arcX Cyber Threat Intelligence Practitioner course is the world's leading CREST accredited preparatory course for the CREST Practitioner Threat Intelligence Analyst (CPTIA) exam. If you're still unsure whether this course is for you, take a look at our Cyber Threat Intelligence 101 course.

If you successfully complete the final arcX exam, you'll earn the esteemed arcX Practitioner Threat Intelligence Analyst certification. You can easily confirm this accomplishment on our website using a QR code.

Your Journey

This module separates Cyber Threat Intelligence from conventional 'bomb and bullet' intelligence and builds the vocabulary the field runs on. You will classify threat actors from white, grey and black hat hackers through to nation-states, hacktivists and cybercriminals, study the Mandiant APT1 report, and map real intrusions using the four-step intelligence cycle, the Diamond Model and the Lockheed Martin Cyber Kill Chain. Hands-on exercises put you inside the Avaddon ransomware and Carbanak cases, and you finish clear on the difference between threat, vulnerability and risk.

  • You will distinguish CTI from conventional intelligence and describe what it delivers to an organisation
  • You will categorise threat actors by motive, affiliation and common TTPs, from nation-state APTs to cybercriminals
  • You will map an intrusion across the four core features of the Diamond Model: adversary, capability, infrastructure and victim
  • You will break a real campaign down against the Cyber Kill Chain using the Avaddon and Carbanak cases
  • You will separate threat, vulnerability and risk and explain how they interact

Inside this module

  • Objectives of Threat Intelligence
  • What is Cyber Threat Intelligence?
  • Cyber Threat Intelligence in Context
  • What's in a Name?
  • How Organisations Use CTI
  • The Role of a CTI Analyst
  • Threat Actor Types
  • Introducing Threat Actors
  • Grey, White and Black Hat Hackers
  • Breaking Down Black Hat Hackers
  • Threat Vector Types and Vulnerabilities
  • The Intelligence Cycle

This module shows why intelligence answers to the customer who sets its direction, and how that direction flows through the strategic, operational and tactical levels of an organisation. You will learn the structure of Intelligence Requirements, Priority Intelligence Requirements and Requests For Information, and pull real requirements from a conversational email exchange with a fictional CISO. It also covers Terms of Reference, the CROSSCAT principles of intelligence, project review and how to handle intelligence gaps honestly.

  • You will identify the intelligence customer and how their questions set investigative priority
  • You will distinguish IRs, PIRs and RFIs and decide what is in and out of scope
  • You will extract Priority Intelligence Requirements from a realistic CISO email exercise
  • You will apply the CROSSCAT principles to judge whether an intelligence product is fit for purpose
  • You will recognise intelligence gaps and choose how to address them

Inside this module

  • Intelligence Requirements
  • Terms of Reference
  • Introducing Intelligence Requirements
  • Mini Quiz
  • The Importance of Project Review
  • Intelligence Gaps
  • Intelligence Gaps and How to Deal With Them
  • SandA to PIRs
  • Mini Quiz
  • End of Module Test

This module maps where CTI data comes from, technical sources like logs and feeds alongside human sources like forums and reports, and how to record it all on a collection worksheet. You will grade reliability using the 5x5x5 National Intelligence Model and the Admiralty (NATO) system, practise pivoting through investigations, and get hands-on with Maltego Community Edition against the APT1 report. It also covers Boolean and advanced Google search operators, spotting deliberate misdirection, and maintaining operational security.

  • You will classify technical and non-technical sources and log them on a collection worksheet
  • You will grade source reliability and information credibility using the 5x5x5 and Admiralty systems
  • You will use Maltego Community Edition to pivot through an investigation using the APT1 report
  • You will build precise Boolean search strings with operators like AND, OR, NOT, quotation marks and wildcards
  • You will recognise deliberate misdirection and apply OPSEC to protect a collection effort

Inside this module

  • Introduction to Collection
  • Use of a Collection Worksheet
  • Types of Sources
  • Introduction to Types of Sources
  • Integrating Sources with the Collection Worksheet
  • Mini Quiz
  • Sources, Reliability and Grading
  • CTI Specific Sources
  • Introducing CTI Specific Sources
  • Pivoting
  • The Power of Tools
  • A Closer Look at Maltego

This is the module where intelligence most often breaks, and where you learn to catch your own mind before it reaches a confident, wrong conclusion. You will apply Analysis of Competing Hypotheses to weigh explanations for an event, separate facts from assumptions, premises and inferences, and use Words of Estimative Probability so your confidence is never overstated. It also tackles circular reporting, cognitive bias, information reliability and structured analytical techniques such as SWOT and PESTAL, with the WannaCry ACH analysis as a worked example.

  • You will run Analysis of Competing Hypotheses to evaluate multiple explanations against the evidence
  • You will separate facts, assumptions, premises and inferences before drawing conclusions
  • You will apply Words of Estimative Probability to communicate confidence honestly
  • You will identify circular reporting and cognitive bias in your own analysis
  • You will apply structured techniques including SWOT and PESTAL to reduce bias

Inside this module

  • Hypothesis Testing
  • Introducing Hypothesis Generation and Testing
  • Analysis of Competing Hypothesis (ACH)
  • Mini Quiz
  • Facts and Assumptions
  • Understanding Information Reliability
  • Information Reliability Summarised
  • Expressing the Likelihood of Certainty
  • Circular Reporting
  • Cognitive Bias
  • Bias in Detail
  • Data Analysis and Handling Errors

This module covers the last mile of intelligence: getting a finished product to the right person in a form they will read and act on. You will contrast structured machine-readable intelligence with unstructured human-readable reporting, apply security markings and analytical language so a judgement is never mistaken for a fact, and tailor delivery format to the customer. It also works through the 'need to know versus need to share' tension that shapes how intelligence is distributed.

  • You will produce structured machine-readable and unstructured human-readable intelligence
  • You will apply security markings and handling codes to control who can see a product
  • You will use analytical language that signals confidence and uncertainty accurately
  • You will balance 'need to know' against 'need to share' when distributing intelligence

Inside this module

  • Structured Machine Readable
  • Unstructured Human Readable
  • Intelligence Sharing
  • End of Module Test

This module maps the legal and ethical boundaries that turn instinctive defensive work into defensible practice under British common law. You will work through the legislation that shapes a CTI analyst's decisions, including the Data Protection Act, the Computer Misuse Act, the Police and Justice Act, the Bribery Act, RIPA, the Proceeds of Crime Act, the Official Secrets Act, the Telecommunications Act and the Human Rights Act. It also covers handling classified information, resolving legal and ethical uncertainty, and the CREST Code of Conduct.

  • You will identify the UK legislation that constrains how intelligence is collected, handled and shared
  • You will judge where authorisation, purpose and jurisdiction place an action either side of the Computer Misuse Act
  • You will handle classified information in line with British standards and the CREST syllabus
  • You will apply the CREST Code of Conduct and your own ethical guidelines to grey-zone decisions

Inside this module

  • Introduction to Legal and Ethical Practices
  • Applying Law and Ethics to CTI
  • Law and Ethics in Practice
  • Handling Classified Information
  • Key Legislation
  • Key Legislation Introduction
  • Data Protection Act
  • Computer Misuse Act
  • Police and Justice Act
  • Bribery Act
  • Regulation of Investigative Powers Act
  • Proceeds of Crime Act

What You'll Learn

Run the full intelligence cycle from direction through collection, analysis and dissemination
Map real intrusions using the Diamond Model and the Lockheed Martin Cyber Kill Chain
Categorise threat actors by motive, affiliation and TTPs, from nation-state APTs to cybercriminals
Grade source reliability and information credibility using the 5x5x5 and Admiralty systems
Extract Intelligence Requirements, PIRs and RFIs from a customer's tasking
Apply Analysis of Competing Hypotheses to test explanations against evidence
Communicate confidence accurately using Words of Estimative Probability
Produce machine-readable and human-readable intelligence with correct security markings
Use Maltego and advanced Boolean search operators to advance an investigation
Work within UK law and the CREST Code of Conduct when collecting and sharing intelligence

Skills You'll Gain

Cyber threat intelligence analysisIntelligence cycle managementDiamond Model of intrusion analysisCyber Kill Chain mappingThreat actor profilingSource reliability gradingAnalysis of Competing HypothesesCognitive bias recognitionWords of Estimative ProbabilityIntelligence requirements and PIRsOSINT collection with MaltegoBoolean and advanced searchIntelligence reporting and disseminationOperational securityUK cyber law and ethics

How This Course Is Delivered

This course is delivered through a combination of interactive content and practical exercises.

Video Content

Immerse yourself in the arcX Cyber Threat Intelligence Practitioner training course through its core delivery method: video. You'll have access to a comprehensive series of videos, collectively spanning over 17 hours of content.

Practical Exercises

You'll engage in numerous micro-exercises, requiring just a few minutes to complete, and more extensive research projects that extend over hours. Each exercise is structured to gauge your comprehension of various concepts.

Quizzes

Our bespoke testing engine will ensure you experience a combination of free-form and adaptive tests. These are thoughtfully integrated to reinforce your learning and consistently evaluate your skills.

Reading Material

Included in the course are downloadable intelligence reports and research papers, strategically provided to enhance your understanding of the taught concepts and expand upon them.

Who This Course Is For

This course is built for anyone entering Cyber Threat Intelligence or looking to formalise experience they already have, translating the field's semi-military language into practical workplace skills.

  • Novices stepping into a CTI analyst role for the first time
  • Professionals studying towards the CREST Practitioner Threat Intelligence Analyst (CPTIA) exam
  • Incident responders wanting to add intelligence to their work
  • Existing threat intelligence analysts consolidating their tradecraft
  • Penetration testers and wider security professionals broadening their skill set

Course Details

Stewart K Bertram

Instructor

Stewart K Bertram

Stewart has worked within the field of Intelligence and Security for the past 20 years with experience across both the private and public sector. Starting his career in 2004 in the Intelligence Corps of the British Army, Stewart entered the private sector in 2009 and has held a number of roles in Cyber Threat Intelligence (CTI) since then. These have included product development, service delivery and consulting, with his most recent roles involving the management of specialist teams involved in research into the cyber criminal underground and nation state threat actors. Holding both a Masters in Computing and a Master of Letters in Terrorism Studies from St. Andrews University. Stewart was also among the first in the world to pass the CREST Certified Threat Intelligence Manager (CCTIM) examination. Stewart’s research interests and work have always sat at the intersection of technology, security and people focused issues. These unique areas of focus are bought to bare within his role at arcX, where he is responsible for the design and delivery of the core CREST related CTI courses and oversight of the wider Cyber Threat Intelligence stream.

Difficulty Level

Intermediate

Language

en

Available Subtitles

EnglishArabicHindiSpanishChinese (simplified)FrenchGermanPortuguese

This course is built around the CREST Practitioner Threat Intelligence Analyst (CPTIA) syllabus and prepares you for the Practitioner Level Threat Intelligence Analyst (PTIA) credential, covering the frameworks, tradecraft and UK legal foundations the syllabus expects.

Student Reviews

Trusted by Security Professionals

Join 70,000+ professionals who have advanced their careers with arcX training

Advanced Career

"The courses provided by arcX are the best in terms of content and structure I have come across, that are aligned to CREST's CPTIA and CRTIA exams. An absolute must for anyone wanting to pursue these certifications but also anyone wanting to gain a solid baseline knowledge set for a career in CTI."

C

Chris

Cyber Threat and Risk Manager

Earned Certification

"Great content and fantastic customer service. Put me in a great position to gain my qualification. 10/10 recommend."

D

Dan

Cyber Security Project Manager

Promoted to Senior

"I have done courses in offensive security, networking, forensics and malware. All from prestigious training vendors. None compare to arcX. I secured a straight transition into a senior CTI role. The platform provided me with insights into my strengths and weaknesses and allowed me to track changes. Very grateful to the guys for this!"

P

Pat

Senior Threat Intelligence Analyst

Frequently Asked Questions

About This Course

No. This course does not include virtual labs. All tools and techniques, including Maltego and the search and analysis exercises, are practised on your own operating system. Where a tool is needed, such as Maltego Community Edition, the course points you to the free download so you can follow along.
No. The course is designed to lower the barrier to entry into CTI. It starts at beginner depth with key concepts and vocabulary, then builds to intermediate analysis, dissemination and legal material, so both newcomers and those formalising existing experience can follow it.
Yes. The course is based around the CREST Practitioner Threat Intelligence Analyst (CPTIA) syllabus and prepares learners for that exam, including areas such as classified information handling covered to British standards in line with the syllabus.
You will work with the Diamond Model, the Lockheed Martin Cyber Kill Chain, the intelligence cycle, the 5x5x5 and Admiralty grading systems, Analysis of Competing Hypotheses, Words of Estimative Probability and Maltego, applied to real cases including APT1, Fancy Bear, Carbanak and Avaddon ransomware.
Yes. A full module covers the UK legal and ethical foundations of CTI, including the Computer Misuse Act, the Data Protection Act, RIPA, the Proceeds of Crime Act, the Official Secrets Act and the CREST Code of Conduct, so you know where the lawful edge lies.

General Course FAQs

Click your avatar in the top right corner and select Contact Support, or email us directly at [email protected]. We typically respond within 24-hours.

You will have 12 months access after activating your course in accordance with our Terms & Conditions. You can work through your course at a pace that suits you. Once you have completed your course you will retain access and be able to refresh your knowledge anytime within the access period.

Our courses are delivered on-demand. This means you can start and stop learning whenever you like. There is no time limit and no restriction on how many times you can access course content.

No. CREST exam vouchers need to be purchased separately through CREST or Pearson VUE. You can find further information on our CREST Accreditation page.

Absolutely! Demonstrating your dedication to professional development in cyber security is always valuable. Our certifications are recognised by partner organisations who value our training.

Yes! You can create individual accounts and purchase courses through our portal for instant access. For multiple employees, please contact us for volume pricing.

Yes! We're always happy to speak with industry experts interested in producing high-quality training courses. Become an instructor and help make a positive impact on someone's career.

If you bought a course before this change, you keep lifetime access to it. The new terms only apply to new purchases.

Can't find what you're looking for? Get in touch