Group Purchasing
Group Purchasing
AI SKILLS

FOR478: Cyber Threat Intelligence Foundations

FOR478Digital Forensics and Incident Response, Artificial Intelligence
  • 2 Days (Instructor-Led)
  • 16 Hours (Self-Paced)
Course authored by:
John DoyleAndreas SfakianakisJosh Darby MacLellan
John Doyle, Andreas Sfakianakis & Josh Darby MacLellan
FOR498: Digital Acquisition and Rapid Triage
Course authored by:
John DoyleAndreas SfakianakisJosh Darby MacLellan
John Doyle, Andreas Sfakianakis & Josh Darby MacLellan
  • 12 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Essential Skill Level

    Course material is for individuals with an understanding of IT or cyber security concepts

  • 8 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Build core CTI skills through expert-led instruction, labs, and panel discussions on program architecture, research, workflows, and stakeholder support.

Course Overview

FOR478 provides a foundational understanding of Cyber Threat Intelligence (CTI) and its role within enterprise, government, and vendor contexts. It focuses on CTI program architecture, operationalized workflows, and delivering actionable insights to stakeholders. Students learn how to incorporate AI into analytic workflows that expand individual capacity while safeguarding against deskilling and tradecraft erosion.

Students taking the FOR478 course gain a unique competitive advantage that no other SANS course to date offers, providing exclusive access to five recorded panels featuring 15 premier Cyber Threat Intelligence (CTI) experts. These sessions seamlessly augment the courseware, reinforcing core concepts while immersing students in the unvarnished industry "truths" that reflect the realities of its practitioners.

About FOR478

FOR478 is an immersive, two-day course designed to explore the Cyber Threat Intelligence (CTI) discipline and its application across enterprise, government, and vendor environments. Engineered for both aspirant and seasoned CTI practitioners, the course demystifies CTI program structure, stakeholder support, and common threat research and analysis workflows. Instruction and hands-on labs are uniquely augmented with expert panel discussions, providing direct exposure to industry thought leaders, prevailing discourse, evolving best practices, and institutional lessons learned.

  • The course takes a structured approach to help students develop a fulsome understanding of CTI operational realities while building core skills essential for navigating a career in CTI.
  • The course labs replicate professional workforce expectations, requiring students perform threat research and develop finished intelligence products that reflect realistic stakeholder requests.
  • Students will also be provided a library of production-ready CTI program templates, ensuring immediate utility for analysts upon returning from training.
  • Students will gain a unique competitive advantage that no other SANS course to date offers, providing exclusive access to five recorded panels featuring 15 premier Cyber Threat Intelligence (CTI) experts. These sessions seamlessly augment the courseware, reinforcing core concepts while immersing students in the unvarnished industry "truths" that reflect the realities of its practitioners.

Day 1: Foundational Elements of a CTI Program

Day 1 establishes CTI as a customer-centric service designed to drive organizational decision-making against cyber security and business objectives, moving beyond the reductive notion that threat intelligence is solely a data feed. The material then grounds CTI research and analytic production in core frameworks including the Intelligence Lifecycle and the OODA loop before deconstructing CTI program elements, the evolution of the discipline, and the analyst's operational workbench. Students learn about the evolution of Generative AI (GenAI) and related models then practical application on how GenAI can be incorporated into analytic workflows that expand individual capacity while safeguarding against deskilling and tradecraft erosion.

  • Students explore how CTI programs are often architected with an emphasis placed on the need for governing policy documents that grant the function the authority to operate. This material also examines how organizations assess CTI program performance, utilizing specific metrics and frameworks to illustrate how intelligence directly influences scaling, resource allocation, and organizational investment.
  • Students are exposed to core CTI analyst job expectations spanning knowledge, skills, and abilities (KSAs) requirements. Students are asked to perform a self-inventory of their KSAs, assessing strengths and growth areas, ultimately creating a career roadmap that aligns professional aspirations with current business needs.

The course exposes students to the operational expectations and frequent pain points when supporting cybersecurity and risk stakeholder teams. By analyzing common stakeholder objectives, workflows, and vernacular, students gain the critical framing necessary to anticipate customer needs. This alignment empowers analysts, and the broader intelligence program, to develop strategic partnerships and deliver high-impact support across the organization.

  • Students are provided with guidance on how to conduct stakeholder analysis, covering how to prepare for a stakeholder discovery meeting, navigate conversational nuances, implement follow-up actions, and avoid common pitfalls. Students also learn to capture, structure, and manage intelligence requirements, ensuring the program's output directly addresses those identified needs.
  • Students practice collection management by building an ICP that converts stakeholder requirements into Essential Elements of Information. They also learn to leverage internal telemetry, mapping log data to CTI use cases to ground their intelligence products in the organization's specific threat environment.
  • This section provides a deep dive into the CTI analyst’s workflow, equipping students with the tools, methodologies, and processes necessary for each stage of the intelligence lifecycle from initial research through dissemination. Students navigate the CTI workflow by learning exactly where and how to engage key technologies like a ticketing system, case management software, Threat Intelligence Platform (TIP), content management system (CMS), and visualization tools. By blending these workflows with intelligence tradecraft and AI integration, students have a clear blueprint on how CTI analysts operate.

The day concludes with the last hands-on lab of the day–data pivoting–where students practice navigating disparate data sources to uncover links and expand their threat research workflows.

Day 2: Cyber Threats and Stakeholder Workflows

Students develop a baseline for analyzing threat actor activity with an immersion into threat operation trends dating back to the mid-2000s to modern day where AI is transforming adversary operations while learning about the risks and rewards of publicly publishing threat research. This includes understanding personal security considerations with potential societal impact. This section also covers effective approaches for collaborating with journalists to amplify research, build personal brand, and drive thought leadership. The course concludes with a deep dive into the specific roles and responsibilities of security and risk teams that comprise strategic, operational, and tactical stakeholder audiences.

  • The course explores how cyber operations have evolved into a formidable, asymmetric capability used by states, criminal enterprises, and non-state actors for high-impact, low-risk objectives like intelligence gathering, financial profit, and strategic influence. It further breaks down the organizational structure of offensive cyber programs into distinct roles.
  • Students are exposed to how and what to expect for cyber actions and impact to their baselines when countries move from peacetime operations to rising tensions to full-blown conflict before immersing in the components, phases, and steps adversaries take during cyber operations.
  • The material pivots to an uncomfortable topic often not addressed by most organizations or first line managers: the personal and professional risks to threat researchers who publish public intelligence products on threat actors.

The day concludes by revisiting stakeholder types, focusing on the role profiles for each team within the strategic, operational, and tactical stakeholder categorization. Job profiles are created outlining their remit, workflows, and integration points for CTI analysts.

  • Special consideration is given to the tactical audience, assisting students in understanding how to extract insights from malware using sandboxes, extract indicators of compromise, and spot unique constructs in strings output to begin fingerprinting threat activities associated with intrusion clusters.

What You'll Learn

  • Architect an effective CTI program that aligns service support to organizational needs
  • Manage requirements and build an actionable ICP that maps telemetry to stakeholder needs
  • Baseline threat actor history to contextualize evolving adversary goals and tactics
  • Analyze how geopolitical drivers and past adversary operations shape your threat landscape
  • Produce finished intelligence products that meet the standards employers and stakeholders expect
  • Apply intelligence tradecraft, CTI frameworks, and AI-assisted workflows used by working analysts
  • Map your professional skills to a career plan aligned with current industry needs

Business Takeaways

  • Return to work with a library of production-ready CTI program templates for immediate use
  • Reduce onboarding time for new CTI hires by grounding them in operational realities
  • Contextualize cyber news by identifying commonalities with past adversary operations
  • Anticipate stakeholder needs by mapping their workflows to drive high-impact CTI support
  • Confidently conduct stakeholder interviews to align CTI outputs with common pain points
  • Improved threat research workflows through AI integration and intelligence tradecraft best practices during 8 hands-on labs
  • Extract insights from malware and logs to predict adversary actions and mitigate risk

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in FOR478: Cyber Threat Intelligence Foundations.

Section 1Foundational Elements of a CTI Program

Day 1 builds the foundational elements of a CTI program, covering the evolution of the CTI discipline, program structure, analyst KSA development and career planning, stakeholder analysis, collection management, and the CTI analyst workbench. The day features four hands-on labs.

Topics covered

  • Introduction to Cyber Threat Intelligence
  • The Evolution of the CTI Field and the Defining Characteristics of CTI
  • CTI Program Structure, Stakeholder Analysis, Intelligence Requirements, and Collection Management
  • The Intelligence Collection Plan, Collection Management, and Supporting CTI Data Sets
  • CTI Mechanics and Analytic Approaches

Labs

  • Lab 1.1: Building a CTI Career Plan
  • Lab 1.2: Drafting a CTI Program Charter
  • Lab 1.3: Developing Intelligence Requirements
  • Lab 1.4: Pivoting Between Data Sources

Section 2Cyber Threats and Stakeholder Workflows

Day 2 deconstructs the anatomy of cyber operations, tracing how state and non-state actor tradecraft evolves during geopolitical tensions and conflict. After baselining adversary behavior, students navigate the professional perils of threat research and media engagement. The day concludes by mapping workflows to various stakeholder audiences.

Topics covered

  • The Evolution of Cyber Operations
  • The Ethics and Perils of Threat Research
  • The Role of the Media and Journalists in CTI
  • Supporting Stakeholders by Audience Type: Strategic, Operational, and Tactical

Labs

  • Lab 2.1: Identifying Emergent Threats for Leadership
  • Lab 2.2: Creating a Weekly Threat Intelligence Newsletter
  • Lab 2.3: Contextualizing Intrusion Data and Visualizing Adversary Playbooks
  • Lab 2.4: Generating Adversary Intelligence from Malware

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system that meets all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class.
  • CRITICAL: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot in any way be used for this course.
  • BIOS settings must be set to enable virtualization technology, such as “Intel-VTx” or “AMD-V” extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 16GB of RAM or more is required.
  • 100GB of free storage space or more is required.
  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration and Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Local Administrator Access is required. (Yes, this is absolutely required. Don’t let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.
  • Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled or you must have the administrative privileges to disable it.
  • Microsoft Office (any version) installed on your host, as several exercises require Microsoft Excel. Note that you can download Office Trial Software online (free for 30 days).
  • Download and install VMware Workstation Pro 16.2.X+ or VMware Player 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ or VMware Player 17.0.0+ (for Windows 11 hosts), or VMWare Fusion Pro 12.2+ or VMware Fusion Player 11.5+ (for macOS hosts) prior to class beginning. If you do not own a licensed copy of VMware Workstation Pro or VMware Fusion Pro, you can download a free 30-day trial copy from VMware. VMware will send you a time-limited serial number if you register for the trial at their website. Also note that VMware Workstation Player offers fewer features than VMware Workstation Pro. For those with Windows host systems, Workstation Pro is recommended for a more seamless student experience.
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials.
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.

Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.

Your course materials include a “Setup Instructions” document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course’s labs.

If you have additional questions about the laptop specifications, please contact customer service.

FOR478 is built for a wide range of professionals who want to develop or sharpen their CTI skills:

  • Aspirant or current CTI analysts who want to understand industry state of play, how CTI programs are structured, and how to shore up foundational practices, methodologies, or tool use
  • Incident Responders who want to understand how CTI can assist their hunt efforts and work better with CTI peers
  • SOC Analysts who want to understand how geopolitical dynamics impact cyber threat activities and explore natural career pathways into CTI
  • Military, civilian intelligence, and law enforcement agents who require a baseline understanding of working cyber threats in public or private sector roles
  • Business, systems, and risk (GRC) analysts who want to expand their job prospects in CTI and understand which skills are transferable
  • Data scientists and intelligence engineers who need to understand CTI data, tooling, and which workflow elements can be automated

  • A personalized CTI career roadmap built during the course
  • A library of production-ready CTI program templates for immediate use after training
  • Direct exposure to industry thought leaders through expert panel discussions
  • 8 hands-on labs designed to replicate professional CTI research and analysis expectations
  • A SIFT VM pre-configured with tools consistent with the FOR578 course environment

FOR478 does not have any prerequisites.

The FOR478 course is part of the Digital Forensics, Malware Analysis, & Threat Intelligence Learning Path, designed to impart the specialized investigative skills you will need to perform forensics, threat intelligence, and malware analysis. This course should be viewed as a pre-requisite for advanced intelligence courses FOR578: Cyber Threat Intelligence and FOR589: Cybercrime Investigations and complementary to SEC497: Practical Open-Source Intelligence (OSINT) and SEC587: Advanced Open-Source Intelligence (OSINT) Gathering and Analysis.

Other courses that are part of this Focus Area and Learning Path include:

As cyber operations continue to evolve into a formidable capability used by states, criminal enterprises, and non-state actors, the ability to understand and communicate threat realities has become a critical organizational function. Cyber Threat Intelligence (CTI) is a customer-centric service function that applies domain expertise in cybersecurity, intelligence, and cyber threat activity and threat actor research to provide decision-support for organizational stakeholders. Rather than simply delivering a data feed, CTI analysts research adversary capabilities, intentions, and activities to produce finished intelligence products that drive better decision-making across security and risk teams.

Those decisions result in mitigating cyber risk, reducing the exposed attack surface, protecting brand reputation, and demonstrating measurable return on investment for cyber security programs.

FOR478 transforms aspirant analysts into qualified practitioners by closing knowledge gaps in CTI operations and historical adversary tradecraft. By understanding the evolution of adversary tradecraft and shifts in their decision calculus, analysts can rapidly contextualize emerging threats, cyber news, and intrusion activities by drawing on historical commonality.

  • Students leave FOR478 with a working understanding of CTI program structure, stakeholder management, threat research workflows, and the analytic tradecraft required to succeed in a fast-growing, high-demand field.
  • Students learn how to use cybersecurity and external data in tandem to support stakeholders needs, learning how to pivot between various disparate data sources as part of their research - something CTI analysts do on a daily basis.
  • Students are exposed to key industry players and their expert insights to include lessons learned that can be immediately integrated into your analytic workflows and career planning.
  • Students are provided with the time, space, and guidance to develop a career plan that maps to current CTI industry needs.
  • A library of production-ready CTI program templates for immediate use after training to help drive the current state of your CTI program, making you look like a rockstar to your leadership team.

Course Schedule and Pricing

Looking for Group Purchasing Options?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $3,505 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS DFIR Summit & Training 2026

    Arlington, VA, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $3,505 USD*Prices exclude applicable local taxes
    Registration Options
Showing 2 of 2

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources