Cyber Threat Intelligence Practitioner
The foundation stage. You learn the four-step intelligence cycle, the Diamond Model, the Lockheed Martin Cyber Kill Chain and the Analysis of Competing Hypotheses, then apply them to real cases like Avaddon ransomware and the Carbanak Group. It grounds you in source grading, Boolean and Maltego collection, cognitive bias, dissemination language and UK legislation such as the Computer Misuse Act, all mapped to the CREST CPTIA syllabus.
A firewall log, a leaked credential dump and a boast on a criminal forum all land in your queue at once. Threat intelligence is deciding which one matters, and what it means.
- Run the full intelligence cycle from direction through collection, analysis and dissemination
- Map real intrusions using the Diamond Model and the Lockheed Martin Cyber Kill Chain
- Categorise threat actors by motive, affiliation and TTPs, from nation-state APTs to cybercriminals












