Reference
Learn cyber threat intelligence
Everything here is written to be used in an interview or on the job. Each page names the frameworks precisely, says where they break down, and links to the questions that test whether you can actually apply them.
15 pages · updated continuously
Start here
The roadmap, end to end.
Frameworks
The models interviews test you on applying, not defining.
- MITRE ATT&CK for CTI analysts ATT&CK is a knowledge base of adversary behaviour organised by tactic and technique. Most candidates can recite that. Fewer can map an ambiguous artefact correctly, or explain what a heat map does not tell you.
- The Diamond Model of intrusion analysis The Diamond Model exists to make pivoting explicit. Its four vertices are not a taxonomy to recite — they are the four places you can be standing when you ask "what else touches this?"
- The Cyber Kill Chain A 2011 model that is still the clearest way to talk about intrusion sequence and defensive coverage — provided you can also say where its linear assumption fails.
- The intelligence cycle and F3EAD Every intelligence failure in a CTI team traces back to the first step. If nobody can state the requirement, everything downstream is expensive noise.
- STIX, TAXII and TLP STIX is the data model, TAXII is the transport, TLP is the handling rule. Mixing these up is a common and very visible interview error.
Tradecraft
The analytic habits that separate intelligence from reporting.
- Attribution and its limits Attribution is the fastest way to fail a scenario interview. The skill is not naming the actor — it is knowing what your evidence can and cannot support, and saying so.
- Analytic confidence and estimative language These are two different axes. You can be highly confident that something is unlikely. If you cannot say that sentence and explain it, you will lose points in every scenario round.
- Source grading for analysts A reliable source can report something false. An unreliable source can be right. Grading them on one axis loses the information that matters.
- Structured analytic techniques ACH is not a spreadsheet ritual. It is a discipline for finding the evidence that would prove you wrong, which is the only kind that carries much information.
- Writing intelligence reports You will be judged on your writing more than your tooling. The bar is a judgement up front, evidence behind it, and an explicit "so what" for someone you have named.
- OSINT for CTI The sources are easy to list. The skills that get tested are knowing what each one actually proves, and not tipping off the adversary while you look.
- Malware triage for CTI You are not being asked to reverse the sample. You are being asked what it can do, who it talks to, and what that means for the organisation.
- From intelligence to detection Handing detection engineering a list of IP addresses is not intelligence-driven detection. This is the handoff that makes a CTI team worth funding.
Certifications
What each credential actually signals, and when to skip it.
Reading about the Diamond Model and pivoting across it under questioning are different skills. The simulator asks real interview questions, grades your answer against a vetted rubric, and asks the follow-up an interviewer would actually ask next.