A five-day intensive certification that prepares cyber threat intelligence professionals to operate across defense, intelligence, coalition, and enterprise environments, integrating doctrine, structured frameworks, hands-on tooling, and legal guardrails into a single applied curriculum.
Developed by the CSFI Cyber Threat Intelligence Division. Instructor-led, pairing lecture and demonstration with hands-on labs and team exercises across forty instructional hours.
The Certified Cyber Threat Intelligence Analyst and Strategist (CCTI-A&S) is a five-day intensive certification developed by the Cyber Security Forum Initiative. It prepares CTI professionals to operate effectively across defense, intelligence community, coalition, and enterprise environments by integrating foundational doctrine, structured analytical frameworks, hands-on tooling proficiency, and legal and policy guardrails into a single applied curriculum.
Nine units unfold across five days. Foundational frameworks come first, followed by requirements management, behavioral analysis, role and stakeholder mapping, technical analysis, and a concluding policy and synthesis capstone. Every day pairs structured lecture and instructor-led demonstration with hands-on labs and team exercises with brief-outs.
Government, military, and qualified private sector
Upon successful completion, participants leave with six capabilities that translate directly into finished intelligence and confident decisions.
Apply the Diamond Model and the Cyber Kill Chain to frame intrusion events and adversary activity into disciplined, defensible analytic judgments.
Manage requirements across IR, GIR, PIR, and RFI levels, capturing them from stakeholders and using them to drive the full intelligence cycle.
Conduct analysis with Maltego, the MITRE ATT&CK Navigator, JSON tooling, and OSINT methods against real adversary artifacts and telemetry.
Map adversary behavior and analytic outputs to the ODNI Cyber Threat Framework, building timelines and layered, confidence-rated judgments.
Analyze disinformation and influence campaigns using the DISARM Red and Blue taxonomies, from lookalike domains to forged content and amplification.
Navigate authorities, intelligence oversight, classification, and controlled dissemination so intelligence is shared lawfully and responsibly.
Foundational frameworks are introduced first, followed by requirements management, behavioral analysis, role and stakeholder mapping, technical analysis, and concluding policy and synthesis.
| Day | Units | Focus Area |
|---|---|---|
| Day 1 | Unit 1 | Foundations of Cyber Threat Intelligence; the Diamond Model; applied analysis labs. |
| Day 2 | Unit 2 | The Cyber Kill Chain; phase-by-phase analyst use; reconnaissance and command-and-control labs. |
| Day 3 | Units 3 & 4 | Intelligence Requirements (IR, GIR, PIR, RFI); Pyramid of Pain, MITRE ATT&CK, and D3FEND. |
| Day 4 | Units 5, 9 & 6 | CTI roles and stakeholders; DISARM framework; ODNI Cyber Threat Framework with the KONNI case. |
| Day 5 | Units 7, 8 & Capstone | JSON for CTI; legal and policy guardrails; course synthesis and the certification capstone. |
Each day builds on the prior day's frameworks and skills, moving from analytical foundations to a full capstone synthesis. Expand any day to see its focus and labs.
Participants learn the purpose of intelligence, the intelligence cycle, and the Diamond Model, then convert raw artifacts into framed intelligence judgments through four hands-on labs.
A full day phase-by-phase walkthrough of the seven kill chain phases, anchored in observable evidence and detection opportunities and closing with an ICS scenario.
The morning shifts to the demand side of intelligence and capturing requirements from stakeholders; the afternoon delivers behavior-to-technique mapping and detect-focused defensive alignment.
Three lenses on the same problem space: CTI role and stakeholder mapping, influence-operations analysis with DISARM, and a two-part KONNI lab in the ODNI Cyber Threat Framework.
The morning develops JSON literacy for CTI; the afternoon covers legal and policy guardrails and closes with a DoD enclave exercise, full capstone synthesis, and certification preparation.
CCTI-A&S is built around the frameworks and tools that working CTI teams rely on every day, applied to real adversary cases throughout the week.
Framing intrusion events across adversary, capability, infrastructure, and victim.
The seven-phase adversary lifecycle, from reconnaissance to actions on objectives.
Prioritizing indicators by the cost they impose on the adversary.
Behavior-to-technique mapping and analysis in the ATT&CK Navigator.
Aligning detections and countermeasures to observed adversary techniques.
A four-layer model for structured, confidence-rated analytic judgments.
Red and Blue taxonomies for influence and information operations analysis.
Link analysis and open-source collection against real-world artifacts.
Rapid reading and IOC extraction from structured telemetry and reporting.
Authorities, oversight, markings, and controlled dissemination.
The curriculum serves government, military, and qualified private sector practitioners alike. It is designed for those who need to integrate cyber threat intelligence into real decisions, products, and workflows.
Participants should arrive with:
The Certified Cyber Threat Intelligence Analyst and Strategist credential is awarded on successful completion of the five-day program and its capstone. It reflects CSFI's commitment to producing intelligence professionals who can apply rigorous analytic tradecraft, operate confidently within legal and policy guardrails, and translate technical observation into actionable intelligence judgments.
CCTI-A&S is developed and delivered by the CSFI Cyber Threat Intelligence Division, which builds advanced cyber threat intelligence and cyberspace operations curricula for the United States Department of Defense, the Intelligence Community, federal civilian agencies, allied and coalition partners, and qualified private sector practitioners.
Tell us about yourself and your mission. A member of the CSFI team will follow up with scheduling, pricing, and enrollment details for CCTI-A&S.
Notice
CSFI is an independent nonprofit incorporated in Nebraska and based in Omaha. CSFI is not affiliated with, and does not represent, the U.S. Government (including the Intelligence Community) or any foreign government. CSFI will not provide services where prohibited, or where authorization is required under ITAR/DDTC, EAR/BIS, or OFAC, unless obtained. CSFI may screen participants and may, in its sole discretion and as permitted by law, deny, refuse, limit, suspend, or terminate participation, consistent with non-discrimination laws.