Home/Training/Certified Threat Intelligence Analyst

Programme Detail

Certified Threat Intelligence Analyst

The Certified Threat Intelligence Analyst programme develops the ability to collect, process, analyse, produce, and communicate cyber threat intelligence. It addresses...

Threat IntelligenceRegistration Open

Programme overview

The Certified Threat Intelligence Analyst programme develops the ability to collect, process, analyse, produce, and communicate cyber threat intelligence. It addresses intelligence requirements, sources, threat actors, campaigns, indicators, TTPs, analysis methods, platforms, sharing, reporting, and operational integration. Participants will work with representative logs, alerts, intelligence, cases, and analyst workflows to improve monitoring, investigation, threat hunting, and reporting skills.

Programmes can be delivered via

HRD Corp Claimable
Yayasan Peneraju aligned
EC-Council

At a glance

Course code
EC-022
Provider
EC-Council
Category
Threat Intelligence
Status
Registration Open
Duration
3 days
Price
RM 4,700

What participants should gain

  • Plan intelligence requirements aligned with organisational needs
  • Collect and validate intelligence from technical and human sources
  • Analyse threat actors, campaigns, indicators, and TTPs
  • Produce actionable intelligence products for different audiences
  • Integrate intelligence with SOC, incident response, risk, and threat hunting

Participant readiness

  • Cybersecurity, SOC, incident response, or risk experience is recommended
  • Understanding of common attacks and security controls
  • Basic analytical and research skills

Who this course is for

  • SOC analysts, threat-intelligence analysts, incident responders, and threat hunters
  • Security analysts responsible for monitoring, investigation, detection, or reporting
  • Cybersecurity professionals seeking structured blue-team and intelligence skills

How the course is delivered

This programme will be conducted through interactive lectures, SOC workflow demonstrations, log and alert analysis, guided investigations, threat-intelligence activities, case-management exercises, reporting, and knowledge checks.

This programme will be conducted through interactive lectures, SOC workflow demonstrations, log and alert analysis, guided investigations, threat-intelligence activities, case-management exercises, reporting, and knowledge checks | By enquiry

Course outline

Module and topic breakdown

Module 1: Introduction to Cyber Threat Intelligence

Strategic, operational, tactical, and technical intelligence and their audiences

Module 2: Threat Intelligence Planning and Direction

Strategic, operational, tactical, and technical intelligence and their audiences

Module 3: Cyber Threat Landscape and Adversary Profiling

Current threat categories, adversary motivations, capabilities, targets, and operating patterns

Module 4: Intelligence Collection Sources and Methods

Open-source, technical, human, commercial, internal, community, and partner sources

Module 5: Data Processing, Validation, and Enrichment

Core concepts, terminology, and purpose of Data Processing, Validation, and Enrichment

Module 6: Indicators, TTPs, and Attack Framework Analysis

Preconditions, attack paths, tools, techniques, and indicators associated with Indicators, TTPs, and Attack Framework Analysis

Module 7: Threat Actor, Campaign, and Malware Analysis

Actor motivation, objectives, capabilities, resources, constraints, targeting, and risk tolerance

Module 8: Analytical Techniques and Structured Intelligence

Core concepts, terminology, and purpose of Analytical Techniques and Structured Intelligence

Module 9: Threat Intelligence Platforms and Automation

Strategic, operational, tactical, and technical intelligence and their audiences

Module 10: Threat Hunting and Operational Integration

Hypothesis-driven, intelligence-led, anomaly-driven, and baseline-driven hunting approaches

Module 11: Intelligence Sharing, Standards, and Communities

Sharing communities, trust groups, traffic-light protocol, standards, and information-handling rules

Module 12: Reporting, Dissemination, and Measuring Intelligence Value

Defining baseline measures, business outcomes, operational metrics, adoption indicators, and risk measures

Assessment and completion

  • Continuous knowledge checks and facilitator feedback throughout the programme
  • Completion of guided exercises, scenarios, labs, or case-study activities applicable to the course
  • Final review or practical activity to confirm understanding of the stated course objectives
  • Official EC-Council examination and certification requirements depend on the selected training package and current exam version

Availability

This programme has a public intake path. Use the enquiry form below to confirm the next available session or a private cohort.

Programme enquiry

Discuss pricing, delivery, or corporate customisation

Use this form to confirm availability, request pricing clarification, or discuss a private cohort for your organisation.