
Threat Intelligence Analyst — career path
StationX Advanced
Know the adversary before they arrive. Security+ first, then open-source intelligence tradecraft, the CTI models and frameworks, and the intelligence labs — CySA+ is the natural certification after it.
The path
Step 1 — Security foundation
The baseline virtually every CTI job spec requires.
follows a certification path
Learn
- PathFollow the CompTIA Security+ (SY0-701) path — the entry certification for every intelligence role
Step 2 — OSINT tradecraft
Find, verify and pivot on open sources without tipping anyone off.
3 courses
Learn
- CourseOSINT: Open-Source Intelligence 🔒 StationX Unlimited
21 sections · 140 lectures
- Training Overview 2
- Introduction 10
- Reporting 2
- Getting started 5
- About sock puppets 6
- Data collection 5
- Advance searching 8
- Reverse searches 7
- Employee and employer searches 1
- People searches 11
- Website OSINT 7
- The Darkweb 6
- Various browser plugins 5
- Social media 14
- OSINT Frameworks 1
- Miscellaneous 9
- Bringing it all together 14
- Additional content 8
- Bonus 6
- Additional Content 12
- Audio Version of Training 1
- CourseOSINT: Open-Source Intelligence Level 2 🔒 StationX Unlimited
32 sections · 106 lectures
- Training Overview 1
- Introduction 3
- Setting up our virtual machine with Virtualbox 1
- Checklist 2
- Website crawling tools 7
- Social Engineering 4
- Home ownership 2
- Encryption 4
- Canary Tokens 2
- Nmap/Zenmap 1
- Checking usernames 2
- Search code 2
- VPN 2
- Criminal checks 5
- Additional Twitter tools 5
- Additional Facebook tools 2
- Reddit 1
- Instagram 3
- Plagiarism Check 1
- Sock puppets 3
- Dating 5
- Other people search 8
- Politics 4
- Business 7
- Bitcoin 2
- Vehicle 5
- Darkweb 7
- Images 5
- Investigation 3
- Identifying and dealing with misinformation 2
- In closing and bonuses 4
- Audio Version of Training 1
- CourseThe Secrets of OSINT (Open-source Intelligence) 🔒 StationX Unlimited
8 sections · 36 lectures
- Training Overview 2
- Introduction 2
- Section 1 : Going undercover 4
- Section 2 : Recruiting Intelligence Sources 8
- Section 3 : How to Make Search Engines Talk 5
- Section 4 : How to Interrogate Social Networks 8
- Section 5 : Loading Heavy Guns 6
- Audio Version of Training 1
Step 3 — Cyber threat intelligence core
The Kill Chain, the Diamond Model, ATT&CK and how a CTI team actually runs.
3 courses · 29 labs
Learn
- CourseCyber Threat Intelligence - Basics & Fundamentals 🔒 StationX Unlimited
11 sections · 68 lectures
- Training Overview 2
- Introduction 4
- Definitions & Fundamentals 15
- Cyber Threat Intelligence Objectives 6
- CTI Specific Models 15
- CTI Reports - Examples 3
- Use case 1 - Ransomware group Primo-Analysis 8
- Use Case 2 - Darkweb Monitoring 8
- Use Case 3 - Adversary Controlled Infrastructure Hunting 5
- Conclusion 1
- Audio Version of the Training 1
- CourseHands-On Cyber Threat Intelligence (CTI) Team Building Series 🔒 StationX Unlimited
1 section · 2 lectures
- Hands-On Cyber Threat Intelligence (CTI) Team Building Series 2
- CourseMITRE ATT&CK Framework Essentials 🔒 StationX Unlimited
6 sections · 35 lectures
- Training Overview 2
- Section 1: Introduction 9
- Section 2: Tactics, Techniques, and Procedures (TTP's) 12
- Section 3: Other Learning Resources 4
- Section 4: Update - Adversarial Threat Landscape for AI Systems 7
- Audio Version of Training 1
Practise
- Labs+Security Threat Intelligence — 11 labs 🔒 StationX Labs+
- Assess Cybersecurity Templates and Benchmarks [Guided]
- Can You Discover Vulnerabilities Over a Network? [Advanced]
- Can You Establish Secure Communications by Using SSH and Wireshark? [Advanced]
- Can You Manage Threats by Using Source Code, Logs, and Security Templates? [Advanced]
- Can You Reduce Threats by Using Nmap, SSH, Source Code Analysis, and Security Templates? [Expert]
- Find Vulnerabilities [Guided]
- Perform Application Source Code Verification [Guided]
- Perform Log Analysis [Guided]
- Perform Network Scanning [Guided]
- Use SSH for Remote Access [Guided]
- Use Wireshark Filters to Explore Captured Network Traffic [Guided]
- LabsThreat Intelligence & Defense — 18 labs 🔒 StationX Unlimited
- Analyze Various Data Sources to Confirm Suspected Infection
- Assessing Vulnerabilities Post Addressal
- BitCoin Mining Web Application on Corporate Network
- Check for Indicators of Other Attack Activity (Debug PE File)
- Cyber Security Evaluation Tool (CSET)
- Entering Information into a CMDB
- Event Logs with Autopsy
- Internet History
- MITRE - Defend
- Nexpose: Red Team Exploitation
- Overview of Kibana
- Performing an Initial Attack Analysis
- Preparing Target Media
- Recover from Illegal Bitcoin Mining Incident
- Recover from Web-Based Flashpack Incident
- Report Writing for Presentation to Management
- Respond to and Validate Alerts from Antivirus Software
- WMI Event Persistence
Where this leads
- CompTIA CySA+ (CS0-003) — Intermediate
- CISSP — Certified Information Systems Security Professional — Advanced
Advanced · after the job
The AI-Driven Threat Intelligence Analyst
Senior roles are going to the people who can direct AI to build security solutions. When you're working in the role and ready for that step, the AI Master's Program is where it's taught — an advanced, application-only programme.
See the AI Master's Program →Application-only. A separate programme for when you're ready.