Simulator
Practise a CTI interview and find out where it breaks
Real questions from a vetted bank, graded against an expert rubric across five dimensions. Difficulty adapts as you go, and every answer gets the probing follow-up an interviewer would actually ask next.
- 36 questions
- 6 tracks
- 6 behavioural
- 5 scenario / case
- 7 screening
- 18 technical
What the grading actually does
Every question in the bank has a vetted rubric behind it: the key points a good answer covers, an expert model answer, and the mistakes candidates commonly make. When you submit, a language model running on our own server grades your answer against that rubric — it is not asked what it thinks about threat intelligence.
That constraint is the whole design. The model is instructed not to assert technical facts outside the rubric, and never to invent CVEs, actor names or citations. If it returns something malformed, or the evaluator is unavailable, you get the vetted expert answer instead of a guess — the session degrades honestly rather than making something up.
You can read the whole approach on the about page, and the question library shows you the expert answers directly.
Practise by topic
Every topic links to the reference page that covers it.
- MITRE ATT&CK 2 Mapping observed behaviour to tactics, techniques and sub-techniques, and using the knowledge base for gap analysis rather than as a tagging exercise.
- Diamond Model 2 Adversary, capability, infrastructure and victim as pivot points, and the meta-features that turn single events into activity threads.
- Cyber Kill Chain 1 Phase-based intrusion analysis, where the model helps, and where its linear assumption breaks down against modern intrusions.
- Intelligence cycle & F3EAD 5 Requirements, collection, processing, analysis, dissemination and feedback — and the F3EAD variant that ties intelligence to operations.
- Attribution 3 What attribution claims actually rest on, the difference between clustering and naming, false-flag risk, and how to hedge honestly.
- Confidence & estimative language 3 Separating probability from confidence, using calibrated language, and avoiding the words that make a judgement unfalsifiable.
- Source grading & evaluation 4 Admiralty-code style reliability and credibility grading, circular reporting, and how to treat vendor blogs as sources.
- Structured analytic techniques 3 Analysis of Competing Hypotheses, key assumptions checks, and the cognitive biases they exist to counter.
- Reporting & stakeholders 3 Writing BLUF, pitching to the audience, and making a finished product that changes a decision instead of listing facts.
- OSINT & collection 1 Passive DNS, certificate transparency, scan data and malware repositories — plus the operational security of collecting at all.
- Malware triage 1 Static and dynamic triage to the point of an intelligence judgement: family, capability, configuration and infrastructure.
- Detection & threat hunting 3 Turning TTP-level intelligence into hypotheses, hunts and durable detections rather than indicator feeds.
- Standards & sharing 2 STIX and TAXII data models, TLP 2.0 handling, and what actually makes shared intelligence usable by the receiver.
- Career & motivation 3 Behavioural ground: why intelligence, how you handle being wrong, and how you work with stakeholders who disagree.