Eyes on the Enemy:
Threat Intelligence Analyst Training
Course Overview
Eyes on the Enemy: Threat Intelligence Analyst Training
Eyes on the Enemy is a rigorous, immersive 6-week training program designed to equip cybersecurity professionals with specialized skills in cyber threat intelligence (CTI). This intensive course provides participants with comprehensive, real-world training in all phases of the intelligence lifecycle - from initial data collection to strategic analysis and operational deployment of threat intelligence.Through a carefully structured curriculum blending expert instruction with hands-on, scenario-based training, students will develop the analytical tradecraft needed to identify emerging threats, track sophisticated adversaries, and produce actionable intelligence that enhances organizational security.
🎯 Course Objectives
By the end of this course, students will be able to:
- Collect intelligence from OSINT, dark web, and technical sources
- Analyze threats using the MITRE ATT&CK® framework and Diamond Model
- Produce actionable reports for different organizational audiences
- Track advanced adversaries (APT groups, cybercriminals)
- Operate intelligence platforms (MISP, ThreatConnect, Recorded Future)
Who Is This Course For?
-
This course is ideal for:
- SOC analysts transitioning to threat intelligence roles
- Security professionals seeking to specialize in CTI
- Military/intelligence personnel moving into cybersecurity
- Incident responders wanting to enhance threat context
- IT risk managers responsible for threat assessments
Course Outline
Threat Intelligence Foundations
Covers the intelligence lifecycle (collection to dissemination) and core frameworks (MITRE ATT&CK, Diamond Model). Labs: Set up OSINT tools (Maltego, SpiderFoot) and analyze APT case studies.
Adversary Research & Tracking
Focuses on threat actor profiling (APT groups, cybercriminals) and TTP analysis. Labs: Map real attacks to ATT&CK and track dark web threats.
Technical Intelligence Gathering
Teaches malware analysis for IOCs and log-based threat detection. Labs: Analyze ransomware samples and correlate IOCs with SIEM alerts.
Operationalizing Intelligence
Hands-on training with MISP/ThreatConnect platforms and STIX/TAXII standards. Labs: Create actionable reports and automate IOC feeds.
Intelligence-Driven Defense
Applies CTI to incident response and threat hunting. Labs: Simulated breach investigation using live intelligence.
Capstone & Reporting
Students complete a full intelligence cycle (from collection to briefing) on an active threat campaign. Includes career coaching.