Course Overview
Threat intelligence is no longer a feed subscription or an automated enrichment layer. Senior practitioners are expected to produce finished intelligence products that drive strategic and operational decisions, apply rigorous attribution methodology that can withstand executive and diplomatic scrutiny, and manage intelligence programmes that continuously improve organisational defensive posture. This four-day advanced programme develops precisely those capabilities.
Across four mentor-led days, participants apply the intelligence cycle to cyber threat analysis, master Structured Analytic Techniques for reducing cognitive bias, execute attribution methodology across technical, operational, and strategic dimensions, operate across OSINT and dark web intelligence sources, build link analysis using Maltego and STIX/TAXII intelligence sharing protocols, and produce finished intelligence products calibrated to executive and government audiences.
The programme culminates in a four-hour capstone: given a live threat dataset, participants produce a complete intelligence assessment attributing a campaign, assessing actor intent and capability, and forecasting likely next moves. They then brief a simulated senior leadership panel. This course is aligned with STIX 2.1 and TAXII standards, structured analytic techniques used by Western intelligence agencies, and NCSC threat intelligence guidance.
Hands-On Learning
Structured attribution exercises using live threat datasets, Maltego link analysis lab, STIX 2.1 intelligence structuring practical, dark web collection simulation, and a four-hour finished intelligence capstone.
Mentor-Led Sessions
Practitioner-led instruction across all intelligence tradecraft sessions, with live attribution methodology demonstration, SAT application workshops, and instructor-led critique of every intelligence product produced.
Career-Ready Skills
Finished intelligence production, structured attribution methodology, SAT application, OSINT and dark web collection, STIX/TAXII intelligence sharing, Maltego link analysis, and strategic intelligence briefing.
Learning Outcomes
Produce finished intelligence products from raw threat data using structured analytical methodology.
Apply technical, operational, and strategic attribution methodology to nation-state cyber campaigns.
Operate across OSINT, dark web, and technical intelligence sources with appropriate tradecraft.
Brief executive and government stakeholders on threat actor intent, capability, and likely next moves.
Structure intelligence assessments in STIX 2.1 format for machine-readable sharing via TAXII
Build and manage a threat intelligence programme that drives organisational security decision-making.
Apply Structured Analytic Techniques to reduce cognitive bias and improve intelligence product quality.
Prerequisites
Minimum three years of professional experience in threat intelligence, SOC operations, or incident response.
Solid understanding of nation-state threat actor groups, MITRE ATT&CK, and cyber threat analysis fundamentals.
Completion of Nation-State Threat Actor Profiles (X-CWTA-F) or APT Detection and Threat Hunting (X-CWAPT-P) recommended.
Detailed Syllabus
Step-by-step learning journey from basics to professional practice
Topics Covered
- Pre-reading: STIX 2.1 specification overview, NCSC threat intelligence guidance, and SAT primer
- Setting up Maltego community edition and accessing course threat dataset environments
- Intelligence requirements template: defining PIRs and IRs for the capstone organisation scenario
- Course objectives, skill baseline assessment, and individual development pathway alignment
Skills You'll Gain
Master these in-demand skills through hands-on practice
Career Progression
A clear view of the roles this programme supports, what typically comes next, and where learners progress over time
Ways to Learn
Choose the learning format that works best for you and your team
Live Online
Instructor-Led Training
Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.
- Live instructor interaction (real-time)
- Trainer-led walkthroughs and real examples
- Guided resources and session notes provided
- Structured Q&A and practical discussion
Price per person
Group enrolments and early planning options available.
All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.
Prefer a Faster, Personalised Route into IT?
Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.
"Many learners choose 1-to-1 when they want understanding, not memorisation."
Exam & Certification Information
Everything you need to know about the certification exams
Important Information
You will receive an Xcademia certificate of completion based on participation and successful completion of labs and scenario simulations.
Credential
Certificate of Completion
On successful completion of Threat Intelligence Analysis and Attribution Tradecraft, learners receive an Xcademia Certificate of Completion. This standalone certificate is issued directly by Xcademia and is aligned with globally recognised frameworks and best practices.
Frequently Asked Questions
Everything you need to know about this course
Senior threat intelligence analysts, CTI team leads, government intelligence professionals, and CISO advisory teams responsible for producing and directing finished intelligence products that drive strategic security decisions.
Ready to Start Your Learning Journey?
Take the next step in your professional development
