If anyone is interested in developing their skills in #CyberThreatIntelligence (CTI), a quick thought based on my experience that might be helpful.
Here are some tips for developing this skill:
Understand fundamentals: attacker motives, threat types, TTPs, #MITRE #ATT&CK, #CyberKillChain
Follow #OSINT sources: OTX, #MalwareBazaar, #VirusTotal, Any.Run, CISA alerts
Practice #IOC analysis: IPs, hashes, domains, URLs, file behaviours
Develop analytical writing: clearly explain What, Who, Why, How, Impact
Study basic malware behaviour: persistence, C2 patterns, lateral movement, evasion
Learn #CTItools: #MISP, OpenCTI, TheHive, Cortex, STIX/TAXII
Connect CTI with SOC operations: detection tuning, alert enrichment, prioritisation
Track threat actors & APT groups to think like an attacker
Stay consistent: analyse, read, or write a little every day
view more