Cyber Threat Intelligence
Code: TBD · Credits: 4 · Hours: — · Type: COURSE
Course-based track. CTI is the practice of collecting, analysing, and acting on information about adversaries so defenders can stay ahead instead of just behind. This subject covers the lifecycle, the analytic frameworks, and the sharing ecosystems that turn raw data into operational decisions.
Key topics
- CTI lifecycle: direction, collection, processing, analysis, dissemination, feedback.
- Frameworks: MITRE ATT&CK, Diamond Model, Cyber Kill Chain, Pyramid of Pain.
- Strategic / operational / tactical / technical intelligence — audiences and outputs.
- Sources: open-source (OSINT), commercial feeds, sharing communities (ISACs, FS-ISAC), dark-web monitoring.
- Sharing protocols: STIX, TAXII, MISP.
- Adversary tracking: threat actor profiles, campaign analysis.
- Nepal-specific intelligence needs: financial sector, government, NPIX, civil society.
Learning outcomes
By the end of this subject, a student should be able to:
- Run a small CTI shop's full lifecycle from a single new alert.
- Map an observed intrusion to ATT&CK techniques and infer the actor's likely motivation.
- Use STIX/TAXII to share intelligence with peer organisations.
- Distinguish high-confidence attribution from speculation in finished intel products.
Further reading
- Joint Publication 2-0 / FM 2-22.3 (intelligence-cycle primers).
- The Threat Intelligence Handbook — Recorded Future.
- MITRE ATT&CK Enterprise + ICS matrices.
- Intelligence-Driven Incident Response — Roberts & Brown.
Chapter notes
Detailed chapter-by-chapter notes for this subject are still being written. The topic outline above mirrors the published syllabus. If you'd like to help draft a chapter, see the contributing guide.
· min read