Skip to content

Latest commit

 

History

History
128 lines (115 loc) · 9.45 KB

File metadata and controls

128 lines (115 loc) · 9.45 KB

Awesome Cyber Threat Intelligence (CTI) Learning Resources

Cyber Threat Intelligence covers strategic, operational, tactical, and technical intelligence. It's the discipline of collecting, analyzing, and disseminating information about adversaries, their TTPs (Tactics, Techniques, and Procedures), infrastructure, and motivations so defenders can act on it. Standard frameworks: MITRE ATT&CK, the Cyber Kill Chain, the Diamond Model, and F3EAD.

ToC

  1. Books
  2. Videos
  3. Free/Paid Courses
  4. Free/Paid Labs
  5. CTI Tools
  6. Certifications
  7. Blogs/Articles

Books

  1. Intelligence-Driven Incident Response, 2nd Ed by Scott J. Roberts, Rebekah Brown (O'Reilly, 2023) - Canonical CTI + IR integration book.
  2. Practical Threat Intelligence and Data-Driven Threat Hunting by Valentina Costa-Gazcon (Packt)
  3. Psychology of Intelligence Analysis by Richards J. Heuer Jr. (CIA, free) - Required reading; covers cognitive biases.
  4. Structured Analytic Techniques for Intelligence Analysis by Heuer, Pherson - Practical analytic method reference.
  5. The Threat Intelligence Handbook by Recorded Future (free)
  6. Visual Threat Intelligence by Thomas Roccia (free)
  7. Operator Handbook: Red Team + OSINT + Blue Team Reference by Joshua Picolet
  8. The Cuckoo's Egg by Clifford Stoll - Classic CTI origin story.
  9. Countdown to Zero Day by Kim Zetter - Stuxnet deep-dive, still highly relevant.

Videos

  1. SANS CTI Summit archives
  2. MITRE ATT&CKcon conference talks
  3. Katie Nickels talks on threat intelligence
  4. Sergio Caltagirone - Diamond Model talks
  5. Mandiant / Google Cloud CTI webinars
  6. Recorded Future videos
  7. The Cyberwire / Hacking Humans podcasts (video versions)

Free/Paid Courses

Free

  1. MITRE ATT&CK for CTI (free on MITRE)
  2. Arcanum Cyber Security Bot - free CTI training
  3. AttackIQ Academy - CTI and detection courses (free)
  4. Google Cybersecurity Certificate - covers CTI basics
  5. TryHackMe - Cyber Defense / Threat Intelligence paths
  6. OpenCTI documentation & tutorials
  7. MISP training materials (free)

Paid

  1. SANS FOR578: Cyber Threat Intelligence (GCTI) - Industry standard course.
  2. SANS FOR589: Cybercrime Intelligence
  3. EC-Council CTIA - Certified Threat Intelligence Analyst
  4. Mandiant Academy courses
  5. Recorded Future University
  6. Treadstone 71 CTI training
  7. ZeroFox CTI education

Free/Paid Labs

  1. TryHackMe - Threat Intelligence Tools, MISP, OpenCTI rooms
  2. CyberDefenders - CTI-adjacent challenges
  3. MISP Training VM - Hands-on MISP.
  4. Mordor / Security-Datasets for TTP practice
  5. DetectionLab + Atomic Red Team for TTP emulation
  6. Pyramid of Pain practical exercises (TryHackMe)
  7. Threat Intel CTFs (HackTheBox seasonal, CyberDefenders CTF)

CTI Tools

TIP (Threat Intelligence Platforms)

  1. MISP - Malware Information Sharing Platform - De-facto open-source TIP.
  2. OpenCTI - Modern open-source TIP (STIX 2.1 native).
  3. ThreatConnect - Commercial TIP.
  4. Anomali ThreatStream
  5. ThreatQuotient
  6. EclecticIQ

OSINT / research

  1. VirusTotal + VT Intelligence (paid)
  2. URLScan.io
  3. AnyRun - Interactive sandbox.
  4. Hybrid Analysis
  5. Triage by Hatching (Recorded Future)
  6. abuse.ch projects: MalwareBazaar, URLHaus, ThreatFox, FeodoTracker, SSLBLacklist
  7. Shodan / Censys / Fofa / ZoomEye
  8. GreyNoise - Internet background-noise / mass-scan classification.
  9. DomainTools / Iris Investigate
  10. RiskIQ PassiveTotal (now Microsoft Defender TI)
  11. Validin / DNSDB by Farsight - Passive DNS.
  12. Spamhaus / Team Cymru

Adversary TTP frameworks / tracking

  1. MITRE ATT&CK Navigator
  2. Diamond Model references
  3. F3EAD cycle
  4. Caldera by MITRE - Adversary emulation.
  5. Atomic Red Team by Red Canary
  6. VECTR by SRA - Purple-team campaign tracking.

Format / standards

  1. STIX 2.1 spec
  2. TAXII 2.1 spec
  3. YARA - Pattern-matching language.
  4. Sigma - Detection rule format.
  5. CACAO - Playbook standard.

Certifications

  1. GCTI - GIAC Cyber Threat Intelligence (SANS FOR578) - The industry benchmark.
  2. CTIA - Certified Threat Intelligence Analyst (EC-Council)
  3. CREST Certified Threat Intelligence Manager (CCTIM) and Analyst (CCTIA)
  4. Mandiant Certified Threat Intelligence Analyst
  5. Treadstone 71 Certified Cyber Intelligence Analyst
  6. arcX CTI certifications

Blogs/Articles

  1. MITRE ATT&CK and D3FEND
  2. The DFIR Report
  3. Mandiant Threat Research
  4. CrowdStrike Global Threat Report (annual)
  5. Microsoft Threat Intelligence blog
  6. Cisco Talos Intelligence
  7. Unit 42 (Palo Alto)
  8. Recorded Future blog + Insikt reports
  9. ESET Research / We Live Security
  10. Kaspersky Securelist / SecureList APT reports
  11. Sekoia.io blog
  12. Google TAG (Threat Analysis Group)
  13. Verizon DBIR (annual)
  14. ENISA Threat Landscape (annual)
  15. Katie Nickels' blog and "I Am the Cavalry" posts
  16. Florian Roth (Nextron) - cyb3rops
  17. Joe Slowik / DomainTools / Dragos - attribution essays
  18. Awesome Threat Intelligence list (GitHub)
  19. APT groups & operations (Google Sheets by FireEye/Mandiant)
  20. CISA Known Exploited Vulnerabilities (KEV) catalog