Advanced Cyber Threat Intelligence Training Course

Turn evaluated threat information into ATT&CK mappings, detection priorities, incident enrichment, and controlled intelligence sharing.
Advanced Cyber Threat Intelligence Training Course

At a glance

Duration
5 days
Format
Classroom
Cities
Barcelona, Athens, Accra, Istanbul, Abu Dhabi, Dubai and more
Next session
12 – 16 October 2026
Average fee
5,800 €

Overview

Advanced Cyber Threat Intelligence and Response Training Course is a five-day advanced course for intelligence analysts, SOC teams, incident responders, security-operations leaders, risk specialists, and technical managers who leave with a Cyber Threat Intelligence Response Playbook. Participants apply intelligence requirements management, source reliability evaluation, MITRE ATT&CK adversary mapping, STIX and TAXII intelligence exchange, and TLP 2.0 sharing controls to prioritize detection and enrich incident decisions. Agile Leaders Training Center develops operational cyber threat intelligence.

Who Should Attend

  • Threat-intelligence functions responsible for collection, analysis, and production
  • SOC teams responsible for detection priorities and alert enrichment
  • Incident-response teams responsible for triage, scope, and defensive action
  • Security-operations leaders responsible for intelligence platforms and workflows
  • Risk and technical-management functions responsible for threat-informed decisions

The course assumes participants work with security alerts, threat reports, or incident cases and leaves out introductory cybersecurity, malware reverse engineering, forensic acquisition, penetration testing, and certification preparation.

Departments and Industries

The course supports departments and industries that need evaluated threat information converted into timely defensive decisions.

  • Security operations and threat intelligence
  • Incident response and cyber-risk functions
  • Financial services and telecommunications
  • Healthcare and digital-service organizations
  • Industrial, logistics, and professional-service operations

Learning Objectives

By the end of this course, participants will be able to:

  • Build intelligence requirements and collection plans
  • Evaluate source reliability and information credibility
  • Analyze actors, campaigns, indicators, and observables
  • Apply MITRE ATT&CK to detection and response priorities
  • Use STIX, TAXII, and TLP 2.0 for controlled sharing
  • Build a Cyber Threat Intelligence Response Playbook

Course Agenda

Day 1: Intelligence Direction and Collection

  • Priority Intelligence Requirements Register
  • Intelligence Consumer and Decision Map
  • Collection Source Coverage Plan
  • Source Reliability and Credibility Matrix
  • Intelligence Gap and Collection Task Board

Day 2: Threat Analysis and Adversary Mapping

  • Threat Actor and Campaign Analysis Profile
  • Indicator and Observable Validation Checklist
  • MITRE ATT&CK Tactic and Technique Map
  • Competing Hypotheses Analysis Matrix
  • Intelligence Confidence and Assumption Record

Day 3: Structuring and Sharing Intelligence

  • STIX 2.1 Object and Relationship Model
  • TAXII 2.1 Collection Exchange Workflow
  • TLP 2.0 Information Handling Matrix
  • Threat Intelligence Platform Data Quality Rules
  • Intelligence Dissemination and Feedback Plan

Day 4: Detection and Incident Response Integration

  • Threat-Informed Detection Use-Case Backlog
  • Alert Enrichment and Triage Worksheet
  • Incident Scope and Attribution Evidence Map
  • Response Priority and Action Matrix
  • Operational and Executive Intelligence Report

Day 5: Intelligence-to-Response Practice

  • Exercise: Define Requirements and Evaluate Sources
  • Exercise: Map a Campaign with MITRE ATT&CK
  • Exercise: Structure and Mark Intelligence for Sharing
  • Exercise: Enrich an Incident and Prioritize Response
  • Capstone: Cyber Threat Intelligence Response Playbook

Practical Exercises

The course uses suggested activities drawn from financial services, telecommunications, healthcare, industrial operations, logistics, and digital services.

  • Suggested activity: define intelligence requirements and compare source reliability, credibility, and coverage.
  • Suggested activity: analyze an adversary campaign and map observed behavior to MITRE ATT&CK.
  • Suggested activity: structure intelligence relationships, apply handling markings, and design an exchange workflow.
  • Suggested activity: enrich an incident case, prioritize detection actions, and prepare consumer-specific reporting.

FAQs

Who suits advanced cyber threat intelligence and response training, and what does it assume?

Threat-intelligence, SOC, incident-response, security-operations, risk, and technical-management functions suit the training; it assumes participants work with alerts, threat reports, or incident cases.

How does cyber threat intelligence differ from general incident-response training?

Cyber threat intelligence focuses on requirements, collection, source evaluation, adversary analysis, structured exchange, and decision support, while incident-response training concentrates on managing the incident lifecycle.

How should teams evaluate cyber threat intelligence sources?

Teams should separately assess source reliability, information credibility, relevance, timeliness, corroboration, collection bias, confidence, and the decision the intelligence must support.

How can MITRE ATT&CK improve threat-informed response?

MITRE ATT&CK improves response by organizing observed adversary behavior into tactics and techniques that teams can connect to evidence, detection gaps, investigation priorities, and defensive actions.

What belongs in a Cyber Threat Intelligence Response Playbook?

A Cyber Threat Intelligence Response Playbook includes requirements, consumers, sources, validation rules, analysis methods, ATT&CK mappings, sharing controls, detection use cases, enrichment steps, priorities, reports, feedback, and owners.

Conclusion

Participants take back a Cyber Threat Intelligence Response Playbook supported by requirement registers, source matrices, ATT&CK maps, exchange workflows, sharing controls, enrichment worksheets, and reporting artifacts. It changes disconnected threat feeds into evaluated intelligence tied to detection and incident decisions. The playbook provides a repeatable basis for prioritization, controlled sharing, response coordination, and improvement.

credits: 5 credit per day

Course Mode: full-time

Provider: Agile Leaders Training Center

Showing 21-40 of 74 events
Image Location Dates Duration Mode Price Actions
Geneva Geneva Week 04, 2027
31 January – 4 February 2027
5 Days Onsite €6,200
Dubai Dubai Week 05, 2027
1 – 5 February 2027
5 Days Onsite €4,500
London London Week 06, 2027
8 – 12 February 2027
5 Days Onsite €5,700
Seoul Seoul Week 06, 2027
8 – 12 February 2027
5 Days Onsite €10,000
Trabzon Trabzon Week 06, 2027
14 – 18 February 2027
5 Days Onsite €6,800
Madrid Madrid Week 07, 2027
15 – 19 February 2027
5 Days Onsite €5,700
Marbella Marbella Week 07, 2027
21 – 25 February 2027
5 Days Onsite €5,700
Tokyo Tokyo Week 09, 2027
1 – 5 March 2027
5 Days Onsite €10,000
Jakarta Jakarta Week 09, 2027
1 – 5 March 2027
5 Days Onsite €5,700
Paris Paris Week 10, 2027
8 – 12 March 2027
5 Days Onsite €5,700
Johannesburg Johannesburg Week 10, 2027
14 – 18 March 2027
5 Days Onsite €4,500
Barcelona Barcelona Week 11, 2027
15 – 19 March 2027
5 Days Onsite €5,700
Abu Dhabi Abu Dhabi Week 12, 2027
22 – 26 March 2027
5 Days Onsite €4,700
Amsterdam Amsterdam Week 14, 2027
5 – 9 April 2027
5 Days Onsite €5,700
San Diego San Diego Week 14, 2027
5 – 9 April 2027
5 Days Onsite €14,000
Cairo Cairo Week 15, 2027
12 – 16 April 2027
5 Days Onsite €4,100
Singapore Singapore Week 15, 2027
12 – 16 April 2027
5 Days Onsite €5,700
Rome Rome Week 16, 2027
19 – 23 April 2027
5 Days Onsite €5,700
Muscat Muscat Week 16, 2027
25 – 29 April 2027
5 Days Onsite €5,700
Vienna Vienna Week 17, 2027
26 – 30 April 2027
5 Days Onsite €5,700

Frequently asked questions

What does this course cover?

OverviewAdvanced Cyber Threat Intelligence and Response Training Course is a five-day advanced course for intelligence analysts, SOC teams, incident responders, security-operations leaders, risk specialists, and technical managers who leave with a Cyber Threat Intelligence Response Playbook. Participants apply intelligence requirements management, source…

Are training dates available?

Yes. Available dates and destinations are listed in the course dates section on this page.

How can I register?

Choose an available date on this page and complete the registration form, or send a programme enquiry.

Can I download the course brochure?

Yes. Use the brochure download link provided on this page.

This course by city