Group Purchasing
Group Purchasing
MAJOR UPDATES

FOR578: Cyber Threat Intelligence

FOR578Digital Forensics and Incident Response
  • 6 Days (Instructor-Led)
  • 36 Hours (Self-Paced)
Course authored by:
Rebekah BrownRobert M. Lee
Rebekah Brown & Robert M. Lee
FOR578: Cyber Threat Intelligence
Course authored by:
Rebekah BrownRobert M. Lee
Rebekah Brown & Robert M. Lee
  • GIAC Cyber Threat Intelligence (GCTI)
  • 36 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 20 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Master tactical, operational, and strategic cyber threat intelligence skills. Improve analytic processes and incident response effectiveness to support your detection and response programs.

Course Overview

Cyber threat intelligence training is essential for countering today’s flexible, persistent human threats and targeted attacks. In FOR578 Cyber Threat Intelligence, you’ll learn to assess complex scenarios and develop skills in tactical, operational, and strategic-level threat intelligence. This course empowers you to expand your existing knowledge and establish new best practices for security teams. 

There Is No Teacher But The Enemy!

Cyber threat intelligence represents a force multiplier for organizations looking to deal with increasingly sophisticated advanced persistent threats. Malware is an adversary's tool but the real threat is the human one, and cyber threat intelligence focuses on countering those flexible and persistent human threats with empowered and trained human defenders. During a targeted attack, an organization needs a top-notch and cutting-edge threat hunting, security operations, and incident response team armed with the threat intelligence necessary to understand how adversaries operate and to counter the threat. FOR578: Cyber Threat Intelligence will train you and your team in the tactical, operational, and strategic level cyber threat intelligence skills and tradecraft required to make security teams better, threat hunting more accurate, incident response more effective, and organizations more aware of the evolving threat landscape.

All security practitioners should attend FOR578: Cyber Threat Intelligence to sharpen their analytical skills. This course is unlike any other technical training you have ever experienced. It focuses on structured analysis in order to establish a solid foundation for any security skillset and to amplify existing skills. The course will help practitioners from across the security spectrum:

  • Develop analysis skills to better comprehend, synthesize, and leverage complex scenarios
  • Identify and create intelligence requirements through practices such as threat modeling
  • Understand and develop skills in tactical, operational, and strategic-level threat intelligence
  • Generate threat intelligence to detect, respond to, and defeat focused and targeted threats
  • Learn the different sources to collect adversary data and how to exploit and pivot off of those data
  • Validate information received externally to minimize the costs of bad intelligence
  • Create Indicators of Compromise (IOCs) in formats such as YARA and STIX/TAXII
  • Understand and exploit adversary tactics, techniques, and procedures, and leverage frameworks such as the Kill Chain, Diamond Model, and MITRE ATT&CK
  • Establish structured analytical techniques to be successful in any security role

It is common for security practitioners to call themselves analysts. But how many of us have taken structured analysis training instead of simply attending technical training? Both are important, but very rarely do analysts focus on training on analytical ways of thinking. This course exposes analysts to new mindsets, methodologies, and techniques to complement their existing knowledge and help them establish new best practices for their security teams. Proper analysis skills are key to the complex world that defenders are exposed to on a daily basis.

The analysis of an adversary's intent, opportunity, and capability to do harm is known as cyber threat intelligence. Intelligence is not a data feed, nor is it something that comes from a tool. Intelligence is actionable information that addresses an organization's key knowledge gaps, pain points, or requirements. This collection, classification, and exploitation of knowledge about adversaries gives defenders an upper hand against adversaries and forces defenders to learn and evolve with each subsequent intrusion they face.

Cyber threat intelligence thus represents a force multiplier for organizations looking to establish or update their response and detection programs to deal with increasingly sophisticated threats. Malware is an adversary's tool, but the real threat is the human one, and cyber threat intelligence focuses on countering those flexible and persistent human threats with empowered and trained human defenders.

Knowledge about the adversary is core to all security teams. The red team needs to understand adversaries' methods in order to emulate their tradecraft. The Security Operations Center needs to know how to prioritize intrusions and quickly deal with those that need immediate attention. The incident response team needs actionable information on how to quickly scope and respond to targeted intrusions. The vulnerability management group needs to understand which vulnerabilities matter most for prioritization and the risk that each one presents. The threat hunting team needs to understand adversary behaviors to search out new threats.

In other words, cyber threat intelligence informs all security practices that deal with adversaries. FOR578: Cyber Threat Intelligence will equip you, your security team, and your organization with the level of tactical, operational, and strategic cyber threat intelligence skills and tradecraft required to better understand the evolving threat landscape and accurately and effectively counter those threats.

Author Statement

"When considering the value of threat intelligence, most individuals and organizations ask themselves three questions: What is threat intelligence? When am I ready for it? How do I use it? This class answers these questions and more at a critical point in the development of the field of threat intelligence in the wider community. The course will empower analysts of any technical background to think more critically and be prepared to face persistent and focused threats."

- Robert M. Lee

"Threat intelligence is a powerful tool in the hands of a trained analyst. It can provide insight to all levels of a security program, from security analysts responding to tactical threats against the network to executives reporting strategic-level threats to the Board of Directors. This course will give students an understanding of the role of threat intelligence in security operations and how it can be leveraged as a game-changing resource to combat an increasingly sophisticated adversary."

- Rebekah Brown

What You’ll Learn

  • Develop advanced analysis skills for complex scenarios
  • Master intelligence requirements gathering (e.g., threat modeling)
  • Understand threat intelligence at all levels (tactical, operational, strategic)
  • Generate actionable threat intelligence for threat detection and response
  • Become proficient in adversary data collection and exploitation
  • Validate intelligence sources and create high-fidelity IOCs (e.g., YARA, STIX/TAXII)
  • Understand and leverage analytic models (e.g., Kill Chain, Diamond Model, MITRE ATT&CK) across all security roles

Business Takeaways:

  • Understand the everchanging cyber threat landscape and what it means for your organization
  • Practice analytic techniques to inform key business leaders on how to most effectively defend themselves and the organization against targeted threats
  • Identify cost-effective ways of leveraging open-source and community threat intelligence tools, along with familiarity with some of the most impactful commercial tools available.
  • Effectively communicate threat intelligence at tactical, operational, and strategic levels
  • Become a force multiplier for other core business functions, including security operations, incident response, and business operations.

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in FOR578: Cyber Threat Intelligence.

Section 1Cyber Threat Intelligence and Requirements

This section introduces students to the most important concepts of intelligence, analysis tradecraft, and levels of threat intelligence, as well as the value they can add to organizations.

Topics covered

  • Intelligence Cycle, Tradecraft, and Analytical Techniques
  • Cyber Threat Definitions, Risk, Actors, and Threat Models
  • Threat Intelligence Collection and Generation

Labs

  • Evaluating Your Analytical Approach
  • Structured Analytical Techniques
  • Enriching and Understanding Limitations
  • Strategic Threat Modeling
  • Building a Collection Plan

Overview

Cyber threat intelligence is a rapidly growing field. However, intelligence was a profession long before the word "cyber" entered the lexicon. Understanding the key points regarding intelligence terminology, tradecraft, and impact is vital to understanding and using cyber threat intelligence. This section introduces students to the most important concepts of intelligence, analysis tradecraft, and levels of threat intelligence, as well as the value they can add to organizations. It also focuses on getting your intelligence program off to the right start with planning, direction, and the generation of intelligence requirements. As with all sections, this course section includes immersive hands-on labs to ensure that students have the ability to turn theory into practice.

Full Lab Details

  • Evaluating Your Analytic Approach
  • Structured Analytical Techniques
  • Consuming Along the Sliding Scale
  • Strategic Threat Modeling
  • Building a Collection Plan

Full Topic Details

  • Case Study: MOONLIGHT MAZE
  • Understanding Intelligence
    • Intelligence Lexicon and Definitions
    • Traditional Intelligence Cycle
    • Richards Heuer, Jr., Sherman Kent, and Intelligence Tradecraft
    • Structured Analytical Techniques
  • Mental Models and Structured Analytic Techniques
  • Case Study: Operation Aurora
  • Understanding Cyber Threat Intelligence
    • Defining Threats
    • Understanding Risk
    • Cyber Threat Intelligence and Its Role
    • Expectation of Organizations and Analysts
    • Diamond Model and Activity Groups
    • Four Types of Threat Detection
  • Case Study: Promethium and Neodymium
  • Threat Intelligence Consumption
    • Sliding Scale of Cybersecurity
    • Consuming Intelligence for Different Goals
    • Enabling Other Teams with Intelligence
  • Preparing the Team to Generate Intelligence
    • Building an Intelligence Team
    • Positioning the Team in the Organization
    • Prerequisites for Intelligence Generation
  • Case Study: Operational Technology (OT) Cybersecurity
  • Planning and Direction (Developing Requirements)
    • Intelligence Requirements
    • Priority Intelligence Requirements
    • Beginning the Intelligence Lifecycle
    • Threat Modeling
  • Collection Sources, Plans, and Frameworks

Section 2The Fundamental Skillset: Intrusion Analysis

In this section, students will be walked through and participate in multi-phase intrusions from initial notification of adversary activity to the completion of analysis of the event. The section also highlights the importance of this process in terms of structuring and defining adversary campaigns.

Topics covered

  • Intrusion Analysis
  • Kill Chain Deep Dive
  • Handling Multiple Kill Chains

Labs

  • Collecting Indicators from Reconnaissance and Delivery
  • Pivoting to Network Data with Indicators
  • Pivoting to Memory with Indicators
  • Understanding the Actions on Objective in an Intrusion
  • Satisfying Priority Intelligence Requirements

Overview

Intrusion analysis is at the heart of threat intelligence. It is a fundamental skillset for any security practitioner who wants to use a more complete approach to addressing security. Three of the most commonly used models for assessing adversary intrusions are the Kill Chain, the Diamond Model, and MITRE ATT&CK. These models serve as a framework and structured scheme for analyzing intrusions and extracting patterns such as adversary behaviors and malicious indicators. In this section students will be walked through and participate in multi-phase intrusions from initial notification of adversary activity to the completion of analysis of the event. The section also highlights the importance of this process in terms of structuring and defining adversary campaigns.

Full Lab Details

  • Collecting Indicators from Reconnaissance and Delivery
  • Pivoting to Network Data with Indicators
  • Pivoting to Memory with Indicators
  • Understanding the Actions on Objective in an Intrusion
  • Satisfying Priority Intelligence Requirements

Full Topic Details

  • Primary Collection Source: Intrusion Analysis
    • Intrusion Analysis as a Core Skillset
    • Methods to Performing Intrusion Analysis
    • Intrusion Kill Chain
    • MITRE ATT&CK
    • Diamond Model
  • Kill Chain Courses of Action
    • Passively Discovering Activity in Historical Data and Logs
    • Detecting Future Threat Actions and Capabilities
    • Denying Access to Threats
    • Delaying and Degrading Adversary Tactics and Malware
  • Kill Chain Deep Dive
    • Scenario Introduction
    • Notification of Malicious Activity
    • Pivoting Off of a Single Indicator to Discover Adversary Activity
    • Identifying and Categorizing Malicious Actions
    • Using Network and Host-Based Data
    • Interacting with Incident Response Teams
    • Interacting with Malware Reverse Engineers
    • Effectively Leveraging Requests for Information
  • Handling Multiple Kill Chains
    • Identifying Different Simultaneous Intrusions
    • Managing and Constructing Multiple Kill Chains
    • Linking Related Intrusions
    • Extracting Knowledge from the Intrusions for Long-Term Tracking

Section 3Collection Sources

In this section students will learn to seek and exploit information from domains, external datasets, malware, Transport Layer Security/Secure Sockets Layer (TLS/SSL) Certificates, and more. Students will also structure the data to be exploited for purposes of sharing internally and externally.

Topics covered

  • Collection Sources
  • Different Styles of Analysis

Labs

  • Domain Pivoting
  • Aggregating and Pivoting in Excel with Malware Samples
  • Open-Source Intelligence Pivoting
  • TLS Certificate Pivoting
  • Visual Analysis with Maltego

Overview

Cyber threat Intelligence analysts must be able to interrogate and fully understand their collection sources. As an example, analysts do not have to be malware reverse engineers, but they must at least understand that work and know what data can be sought. This section continues from the previous one in identifying key collection sources for analysts. The considerable amount of what is commonly referred to as open-source intelligence (OSINT) is also presented. In this section students will learn to seek and exploit information from domains, external datasets, malware, Transport Layer Security/Secure Sockets Layer (TLS/SSL) Certificates, and more. Students will also structure the data to be exploited for purposes of sharing internally and externally.

Full Lab Details

  • Domain Pivoting
  • Aggregating and Pivoting in Excel with Malware Samples
  • Open-Source Intelligence Pivoting
  • TLS Certificate Pivoting
  • Visual Analysis with Maltego

Full Topic Details

  • Case Study: Carbanak
  • Collection Source: Domains
    • Domain Deep Dive
    • Different Types of Adversary Domains
    • Pivoting Off of Information in Domains
  • Case Study: HEXANE
    • Collection Source: Malware
    • Data from Malware Analysis
    • Key Data Types to Analyze and Pivot On
    • VirusTotal and Malware Parsers
    • Identifying Intrusion Patterns and Key Indicators
  • Collection Source: Malware
  • Case Study: Mid Campaign Changes
  • Collection Source: External Datasets
    • Building Repositories from External Datasets
    • Open-Source Intelligence Collection Tools and Frameworks
  • Collection Source: TLS Certificates
    • TLS/SSL Certificates
    • Tracking New Malware Samples and C2 with TLS
    • Pivoting off of Information in TLS Certificates
  • Case Study: Poison Carp and the I-Soon Leaks
  • Leveraging Different Styles of Analysis
  • Case Study: The Panama Papers

Section 4Analysis Production of Intelligence

In this section students will learn how to structure and store their information; how to leverage analytical tools to identify logical fallacies and cognitive biases; how to perform structured analytic techniques in groups such as analysis of competing hypotheses; and how to cluster intrusions into threat groups.

Topics covered

  • Human-Operated Ransomware
  • Storing and Structuring Data
  • Logical Fallacies and Cognitive Biases
  • Clustering Intrusions and Creating Activity Groups

Labs

  • Storing Threat Data in MISP
  • Leveraging Research in Threat Analysis
  • Identifying Cognitive Biases
  • Analysis of Competing Hypotheses
  • The Rule of 2

Overview

With great data comes great analysis expectations. Now that students are familiar with different sources of intrusions and collection, it is important to apply analytical rigor to how this information is used in order to satisfy intelligence requirements for long-term analysis. Taking a single intrusion and turning it into a group, and tracking the adversary’s campaigns, are critical to staying ahead of adversaries.

Full Lab Details

  • Storing Threat Data in MISP
  • Leveraging Research in Threat Analysis
  • Identifying Cognitive Biases
  • Analysis of Competing Hypotheses
  • The Rule of 2

Full Topic Details

  • Case Study: Human-Operated Ransomware
  • Exploitation: Storing and Structuring Data
    • Storing Threat Data
    • Threat Information Sharing
    • MISP as a Storage Platform
  • Secondary Research and Cyber Threat Intelligence
  • Analysis: Logical Fallacies and Cognitive Biases
    • Logical Fallacies
    • Cognitive Biases
    • Common Cyber Threat Intelligence Informal Fallacies
  • Analysis: Exploring Hypotheses
    • Analysis of Competing Hypotheses
    • Hypotheses Generation
    • Understanding and Identifying Knowledge Gaps
  • Analysis: Clustering Intrusions
    • Visual Analysis
    • Data Analysis
    • Temporal Analysis
    • Case Study: Panama Papers
    • Analysis: Clustering Intrusions
    • Style Guide
    • Names and Clustering Rules
  • Case Study: APT10 and APT31
  • Activity Groups and Diamond Model for Clusters
    • Style Guide
    • Names and Clustering Rules
    • ACH for Intrusions
    • Activity Groups and Diamond Model for Clusters

Section 5Dissemination and Attribution

Intelligence is useless if not disseminated and made useful to the consumer. In this section students will learn about dissemination at the various tactical, operational, and strategic levels.

Topics covered

  • Tactical Dissemination
  • Operational Dissemination
  • Strategic Dissemination
  • Attribution

Labs

  • Developing IOCs in YARA
  • Operational Writing
  • Using Visuals for Operational Impact
  • Creating and Defending an Attribution Model

Overview

Labs will expose students to creating YARA rules, leveraging STIX/TAXII, building campaign heat maps for tracking adversaries over the long term, and analyzing intelligence reports. Students will also learn about state adversary attribution, including when it can be of value and when it is merely a distraction. We'll cover state-level attribution from previously identified campaigns, and students will take away a more holistic view of the Cyber Threat Intelligence industry to date. The section will finish with a discussion on consuming threat intelligence and actionable takeaways so that students will be able to make significant changes in their organizations once they complete the course.

Full Lab Details

  • Developing IOCs in YARA
  • Operational Writing
  • Using Visuals for Operational Impact
  • Creatig and Defending an Attribution Model

Full Topic Details

  • Case Study: Axiom
  • Dissemination: Tactical
    • Understanding the Audience and Consumer
    • Threat Data Feeds and Their Limitations
    • YARA
    • YARA Concepts and Examples
  • Case Study: Hacking Team
  • Dissemination: Operational
    • Different Methods of Campaign Correlation
    • Understanding Perceived Adversary Intentions
    • Leveraging the Diamond Model for Campaign Analysis
    • STIX and TAXII
    • Government and Partner Collaboration
  • Dissemination: Strategic
    • Report Writing Pitfalls
    • Report Writing Best Practices
    • Different Types of Strategic Output
  • Case Study: APT10 and Cloud Hopper
    • A Specific Intelligence Requirement: Attribution
    • Identifying and Remedying New Intelligence Requirements
    • Tuning the Collection Management Framework
    • Types of Attribution
    • Building an Attribution Model
    • Conducting Attribution Assessments
  • A Specific Intelligence Requirement: Attribution
  • Case Study: Lazarus Group

Section 6Cyber Threat Intelligence Capstone

The FOR578 capstone focuses on analysis. Students will be placed on teams, given outputs of technical tools and cases, and work to piece together the relevant information from a single intrusion that enables them to unravel a broader campaign.

Overview

Students will get practical experience satisfying intelligence requirements ranging from helping the incident response team to satisfying state-level attribution goals. This analytical process will put the students' minds to the test instead of placing a heavy emphasis on using technical tools. At the end of the day the teams will present their analyses on the multi-campaign threat they have uncovered.

Things You Need To Know

Important! Bring your own system configured according to these instructions. 

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system that meets all of the specified requirements. 

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data. 

Mandatory System Hardware Requirements

  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class.
  • CRITICAL: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot in any way be used for this course.
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 16GB of RAM or more is required.
  • 100GB of free storage space or more is required.
  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration and Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Local Administrator Access is required. (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.
  • Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled or you must have the administrative privileges to disable it.
  • Microsoft Office (any version) installed on your host, as several exercises require Microsoft Excel. Note that you can download Office Trial Software online (free for 30 days).
  • Download and install VMware Workstation Pro 16.2.X+ or VMware Player 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ or VMware Player 17.0.0+ (for Windows 11 hosts), or VMWare Fusion Pro 12.2+ or VMware Fusion Player 11.5+ (for macOS hosts) prior to class beginning. If you do not own a licensed copy of VMware Workstation Pro or VMware Fusion Pro, you can download a free 30-day trial copy from VMware. VMware will send you a time-limited serial number if you register for the trial at their website. Also note that VMware Workstation Player offers fewer features than VMware Workstation Pro. For those with Windows host systems, Workstation Pro is recommended for a more seamless student experience.
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials.
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.

Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files. 

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions. 

Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs. 

If you have questions about the laptop specifications, please contact customer service

This course is perfect match for security practitioners of any skill set, from red teamers to incident responders. The course is focused on analysis skills.

Those serving in specific roles who may benefit from FOR578 training include:

  • Incident Response Team Members
  • Those who respond to complex security incidents/intrusions and need to know how to detect, investigate, remediate, and recover from compromised systems across an enterprise
  • Threat Hunters who are seeking to understand threats more fully and how to learn from them to be able to more effectively hunt threats and counter the tradecraft behind them
  • Security Operations Center Personnel and Information Security Practitioners who support hunting operations that seek to identify attackers in their network environments
  • Digital Forensic Analysts and Malware Analysts who want to consolidate and expand their understanding of filesystem forensics, investigations of technically advanced adversaries, incident response tactics, and advanced intrusion investigations
  • Federal Agents and Law Enforcement Officials who want to master advanced intrusion investigations and incident response, as well as expand their investigative skills beyond traditional host-based digital forensics
  • Technical Managers who are looking to build intelligence teams or leverage intelligence in their organizations building off of their technical skillsets
  • SANS Alumni looking to take their analytical skills to the next level

The GIAC Cyber Threat Intelligence (GCTI) certification validates practitioners have demonstrated requisite fundamental strategic, operational, and tactical cyber threat intelligence knowledge and skills.

  • Strategic, operational, and tactical cyber threat intelligence application & fundamentals
  • Open source intelligence and campaigns
  • Intelligence applications and intrusion analysis
  • Analysis of intelligence, attribution, collecting and storing data sets
  • Kill chain, diamond model, and courses of action matrix
  • Malware as a collection source, pivoting, and sharing intelligence

More Certification Details

FOR578 is a good course for anyone who has had security training or prior experience in the field. Students should be comfortable with using the command line in Linux for a few labs (though a walkthrough is provided) and be familiar with security terminology.

Some of the courses that lead in to FOR578:

Students who have not taken any of the above courses but have real-world experience or have attended other security training, such as any other SANS class, will be comfortable in the course. New students and veterans will be exposed to new concepts given the unique style of the class focused on analysis training.

The FOR578 course is part of the Threat Intel and Forensics Learning Path, designed to impart the specialized investigative skills you will need to perform forensics, threat intelligence, and malware analysis.

Other courses that are part of this Focus Area and Learning Path include:

Cyber Threat Intelligence, covered extensively in FOR578, is the process of gathering, analyzing, and sharing information about cyber threats and the adversaries behind them. This information encompasses the tactics, techniques, and procedures (TTPs) employed by threat actors, the vulnerabilities they exploit, and the potential impact of these threats on an organization.

Why is CTI Important?

CTI plays a vital role in enhancing an organization's cybersecurity posture. Here's why:

  • Organizations can proactively implement security measures to mitigate risks and prevent attacks.
  • CTI provides valuable context that enables faster and more effective responses to cyber incidents, minimizing downtime and potential damage.
  • CTI empowers security teams to make informed decisions regarding resource allocation, vulnerability prioritization, and the implementation of appropriate security controls.
  • Strong cybersecurity is essential for business continuity and maintaining a competitive edge. CTI helps organizations protect their valuable assets and build trust with stakeholders.
  • With CTI, organizations can significantly strengthen their defenses, reduce their exposure to cyber threats, and improve their overall security posture.

Cyber threat intelligence informs all security practices that deal with adversaries. FOR578: Cyber Threat Intelligence will equip you, your security team, and your organization with the tactical, operational, and strategic cyber threat intelligence skills and tradecraft required to better understand the threat landscape—and effectively counter those threats.

You’ll come away from this course with the ability to:

  • Understand the ever-changing cyber threat landscape and what it means for your organization
  • Practice analytic techniques to inform key business leaders on how to most effectively defend themselves and the organization against targeted threats
  • Identify cost-effective ways of leveraging open-source and community threat intelligence tools, along with familiarity with some of the most impactful commercial tools available.
  • Effectively communicate threat intelligence at tactical, operational, and strategic levels
  • Become a force multiplier for other core business functions, including security operations, incident response, and business operations.

Relevant Job Roles

Data Analysis (OPM 422)

NICE: Implementation and Operation

Responsible for analyzing data from multiple disparate sources to provide cybersecurity and privacy insight. Designs and implements custom algorithms, workflow processes, and layouts for complex, enterprise-scale data sets used for modeling, data mining, and research purposes.

Explore learning path

Threat Hunter Training, Salary, and Career Path

Digital Forensics and Incident Response

This expert applies new threat intelligence against existing evidence to identify attackers that have slipped through real-time detection mechanisms. The practice of threat hunting requires several skill sets, including threat intelligence, system and network forensics, and investigative development processes. This role transitions incident response from a purely reactive investigative process to a proactive one, uncovering adversaries or their footprints based on developing intelligence.

Explore learning path

All-Source Analyst (DCWF 111)

DoD 8140: Intelligence (Cyberspace)

Analyzes data from multiple sources to prepare environments, respond to information requests, and support intelligence planning and collection requirements.

Explore learning path

Threat Analysis (OPM 141)

NICE: Protection and Defense

Responsible for collecting, processing, analyzing, and disseminating cybersecurity threat assessments. Develops cybersecurity indicators to maintain awareness of the status of the highly dynamic operating environment.

Explore learning path

All-Source Collection Manager (DCWF 311)

DoD 8140: Intelligence (Cyberspace)

Identifies collection priorities, develops plans using available assets, and monitors execution to meet operational intelligence requirements.

Explore learning path

Cyber Intelligence Analyst Training, Salary, and Career Path

European Cybersecurity Skills Framework

Cyber Intelligence Analysts analyze evolving cyber threats, profile adversaries, and leverage intelligence platforms to proactively inform security decisions and mitigation strategies, bridging technical insights with strategic awareness.

Explore learning path

All-Source Collection Requirements Manager (DCWF 312)

DoD 8140: Intelligence (Cyberspace)

Evaluates collection strategies, develops and validates requirements, and assesses performance to optimize collection asset effectiveness.

Explore learning path

OSINT Investigator/Analyst

Cyber Defense

These resourceful professionals gather requirements from their customers and then, using open sources and mostly resources on the internet, collect data relevant to their investigation. They may research domains and IP addresses, businesses, people, issues, financial transactions, and other targets in their work. Their goals are to gather, analyze, and report their objective findings to their clients so that the clients might gain insight on a topic or issue prior to acting.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 24

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources