Cyber Threat Intelligence covers strategic, operational, tactical, and technical intelligence. It's the discipline of collecting, analyzing, and disseminating information about adversaries, their TTPs (Tactics, Techniques, and Procedures), infrastructure, and motivations so defenders can act on it. Standard frameworks: MITRE ATT&CK, the Cyber Kill Chain, the Diamond Model, and F3EAD.
- Intelligence-Driven Incident Response, 2nd Ed by Scott J. Roberts, Rebekah Brown (O'Reilly, 2023) - Canonical CTI + IR integration book.
- Practical Threat Intelligence and Data-Driven Threat Hunting by Valentina Costa-Gazcon (Packt)
- Psychology of Intelligence Analysis by Richards J. Heuer Jr. (CIA, free) - Required reading; covers cognitive biases.
- Structured Analytic Techniques for Intelligence Analysis by Heuer, Pherson - Practical analytic method reference.
- The Threat Intelligence Handbook by Recorded Future (free)
- Visual Threat Intelligence by Thomas Roccia (free)
- Operator Handbook: Red Team + OSINT + Blue Team Reference by Joshua Picolet
- The Cuckoo's Egg by Clifford Stoll - Classic CTI origin story.
- Countdown to Zero Day by Kim Zetter - Stuxnet deep-dive, still highly relevant.
- SANS CTI Summit archives
- MITRE ATT&CKcon conference talks
- Katie Nickels talks on threat intelligence
- Sergio Caltagirone - Diamond Model talks
- Mandiant / Google Cloud CTI webinars
- Recorded Future videos
- The Cyberwire / Hacking Humans podcasts (video versions)
- MITRE ATT&CK for CTI (free on MITRE)
- Arcanum Cyber Security Bot - free CTI training
- AttackIQ Academy - CTI and detection courses (free)
- Google Cybersecurity Certificate - covers CTI basics
- TryHackMe - Cyber Defense / Threat Intelligence paths
- OpenCTI documentation & tutorials
- MISP training materials (free)
- SANS FOR578: Cyber Threat Intelligence (GCTI) - Industry standard course.
- SANS FOR589: Cybercrime Intelligence
- EC-Council CTIA - Certified Threat Intelligence Analyst
- Mandiant Academy courses
- Recorded Future University
- Treadstone 71 CTI training
- ZeroFox CTI education
- TryHackMe - Threat Intelligence Tools, MISP, OpenCTI rooms
- CyberDefenders - CTI-adjacent challenges
- MISP Training VM - Hands-on MISP.
- Mordor / Security-Datasets for TTP practice
- DetectionLab + Atomic Red Team for TTP emulation
- Pyramid of Pain practical exercises (TryHackMe)
- Threat Intel CTFs (HackTheBox seasonal, CyberDefenders CTF)
- MISP - Malware Information Sharing Platform - De-facto open-source TIP.
- OpenCTI - Modern open-source TIP (STIX 2.1 native).
- ThreatConnect - Commercial TIP.
- Anomali ThreatStream
- ThreatQuotient
- EclecticIQ
- VirusTotal + VT Intelligence (paid)
- URLScan.io
- AnyRun - Interactive sandbox.
- Hybrid Analysis
- Triage by Hatching (Recorded Future)
- abuse.ch projects: MalwareBazaar, URLHaus, ThreatFox, FeodoTracker, SSLBLacklist
- Shodan / Censys / Fofa / ZoomEye
- GreyNoise - Internet background-noise / mass-scan classification.
- DomainTools / Iris Investigate
- RiskIQ PassiveTotal (now Microsoft Defender TI)
- Validin / DNSDB by Farsight - Passive DNS.
- Spamhaus / Team Cymru
- MITRE ATT&CK Navigator
- Diamond Model references
- F3EAD cycle
- Caldera by MITRE - Adversary emulation.
- Atomic Red Team by Red Canary
- VECTR by SRA - Purple-team campaign tracking.
- STIX 2.1 spec
- TAXII 2.1 spec
- YARA - Pattern-matching language.
- Sigma - Detection rule format.
- CACAO - Playbook standard.
- GCTI - GIAC Cyber Threat Intelligence (SANS FOR578) - The industry benchmark.
- CTIA - Certified Threat Intelligence Analyst (EC-Council)
- CREST Certified Threat Intelligence Manager (CCTIM) and Analyst (CCTIA)
- Mandiant Certified Threat Intelligence Analyst
- Treadstone 71 Certified Cyber Intelligence Analyst
- arcX CTI certifications
- MITRE ATT&CK and D3FEND
- The DFIR Report
- Mandiant Threat Research
- CrowdStrike Global Threat Report (annual)
- Microsoft Threat Intelligence blog
- Cisco Talos Intelligence
- Unit 42 (Palo Alto)
- Recorded Future blog + Insikt reports
- ESET Research / We Live Security
- Kaspersky Securelist / SecureList APT reports
- Sekoia.io blog
- Google TAG (Threat Analysis Group)
- Verizon DBIR (annual)
- ENISA Threat Landscape (annual)
- Katie Nickels' blog and "I Am the Cavalry" posts
- Florian Roth (Nextron) - cyb3rops
- Joe Slowik / DomainTools / Dragos - attribution essays
- Awesome Threat Intelligence list (GitHub)
- APT groups & operations (Google Sheets by FireEye/Mandiant)
- CISA Known Exploited Vulnerabilities (KEV) catalog