Cyber Knowledge · Domain 01 of 11 · Practitioner field guide

Cyber Threat Intelligence (CTI)

A progressive field guide: everything from "what counts as intelligence" through the frameworks professionals actually use, the tradecraft that keeps analysis honest, and how CTI output becomes a working detection. Ten modules, in the order most people should learn them.

Version 1.0 Published Source review: Status: maintained practitioner guide Maintained by Andrey Pautov Editorial policy and corrections

Reviewed 27 July 2026

Definitions were checked against current primary standards where available. Product examples link to hands-on 1200km research and are clearly separate from the standards themselves.

Module 1 — Foundations: What CTI Is

7 terms

Start here. These are the definitions used throughout the rest of this field guide.

Module 2 — The Intelligence Cycle & Intelligence Types

6 terms

The production process behind every CTI product, and the four altitudes intelligence gets consumed at.

Module 3 — Core Frameworks & Models

9 terms

The shared vocabulary that lets analysts, engineers, and vendors describe the same adversary behavior consistently.

Module 4 — Collection & Sources

8 terms

Where CTI actually comes from, roughly ordered from broadest to most organization-specific.

Module 5 — Analysis Techniques & Tradecraft

9 terms

The discipline that separates intelligence analysis from guessing — and the part most self-taught analysts skip.

Module 6 — The Threat Actor Landscape

6 terms

Who you're actually tracking, and why the same group can have five different names.

Module 7 — Intelligence Products & Sharing

6 terms

What CTI actually hands to the rest of the organization, and where teams pool intelligence with each other.

Module 8 — Operationalizing CTI (CTI → Detection)

6 terms

Where CTI stops being a report and starts being a rule that fires. See also the Detection & SOC library section.

Module 9 — Tools of the Trade

9 tools

What an analyst actually opens day to day. AdversaryGraph, this site's own platform, connects most of these workflows into one CTI-to-detection tool — see the product page.

Module 10 — Career Path & Continuing Education

4 topics

Where "zero" ends and "hero" begins — how to keep going after this page.

Continue Your CTI Path

This field guide is the map. For worked examples, read the CTI & Threat Intelligence guides in the Library, browse selected CTI research, or work hands-on inside AdversaryGraph, which implements this entire workflow — enrichment, ATT&CK mapping, actor tracking, and detection handoff — as a self-hosted platform.

Connected original research

AI in Cyberattacks: statistical CTI study

Use the source explorer and normalized tags to compare how 103 core publications describe adversary AI use, campaign context, providers, sectors, and ATT&CK coverage.