Skip to main content
CYB-0348ExpertCurrent Intake
XCTI

XCTI: Xcademia Cyber Threat Intelligence Practitioner

6-Day Instructor-Led Programme

The XCTI Certification Programme is the practitioner standard for cyber threat intelligence analysts who collect, analyse, and operationalise intelligence across strategic, operational, and tactical layers, producing intelligence products that drive measurable security improvement across SOC operations, incident response, and executive decision-making. Assessed on Day 6 through a supervised intelligence analysis exercise producing a professional threat intelligence report. No MCQs. No closed-book exam.

Duration

6 Days

Price

$4,996

XCTI: Xcademia Cyber Threat Intelligence Practitioner
Duration
6 Days
Complete in 6 days
Learning Style
Mentor-led, practical and scenario-based
Guided walkthroughs, real-world examples, and applied skills for the workplace.

Course Overview

Cyber threat intelligence is the difference between reacting to attacks and anticipating them. The CTI analyst who can only consume threat feeds is not performing intelligence: they are performing data management. Real threat intelligence requires hypothesis formation, structured analytic technique application, source evaluation, confidence grading, and intelligence product development that actually changes defensive decisions. The GCTI from SANS is the most respected CTI certification, but it is a 115 to 118 question MCQ exam. XCTI is built for analysts who want to demonstrate they can produce intelligence, not pass a test.

Across six instructor-led days, participants build CTI capability across the complete intelligence lifecycle: intelligence requirements and planning, OSINT collection methodology, STIX 2.1 and TAXII 2.1 standards, MISP and OpenCTI platform operations, threat actor profiling and campaign analysis, dark web intelligence collection in authorised environments, the Diamond Model and Cyber Kill Chain for intrusion analysis, strategic and geopolitical threat intelligence, intelligence product development for different audiences, and CTI integration into SOC operations and incident response.

On Day 6, participants receive a raw intelligence collection package (OSINT artefacts, malware reports, network indicators, and industry reports) and must produce a complete threat intelligence product: a threat actor profile with campaign attribution, MITRE ATT&CK heat map, IOC list, and an executive summary and technical annex. A senior practitioner assesses analytical rigour, structured technique application, and product quality. XCTI certificate and Practitioner Assessment Report issued together.

Hands-On Learning

OSINT collection exercises using Maltego, Shodan, and Censys, MISP event creation and relationship mapping, OpenCTI threat actor profile building, Diamond Model analysis exercises, dark web monitoring in authorised Tor environments, and a full intelligence product exercise on Day 6.

Mentor-Led Sessions

Mentor-led sessions examining real threat actor campaigns from OSINT perspective, structured analytic technique application (ACH and key assumptions check), confidence grading discipline, and how CTI products are consumed differently by SOC analysts, incident responders, and boards.

Career-Ready Skills

Produce professional cyber threat intelligence products across strategic, operational, and tactical layers, integrating structured analytic techniques, MITRE ATT&CK mapping, and platform-based intelligence management for SOC and IR operations.

Learning Outcomes

Apply the intelligence lifecycle to CTI operations including requirements management, collection planning, and systematic feedback collection

Conduct OSINT collection using passive infrastructure analysis tools and apply structured analytic techniques to produce high-confidence threat assessments

Operate MISP and OpenCTI platforms for threat actor profiling, IOC lifecycle management, and intelligence sharing using STIX 2.1 and TAXII 2.1

Apply the Diamond Model and MITRE ATT&CK to produce threat actor profiles with attribution confidence grading and campaign timeline analysis

Produce professional threat intelligence products for strategic, operational, and tactical audiences including executive briefings and technical threat advisories

Integrate CTI outputs into SOC detection engineering, SIEM enrichment, and SOAR automation to deliver measurable security improvement

Prerequisites

1

Minimum 12 months in a SOC, DFIR, threat hunting, or security analysis role with exposure to threat intelligence concepts

2

Working knowledge of MITRE ATT&CK framework and basic familiarity with at least one SIEM platform

3

Basic understanding of malware types, C2 communications, and common adversary TTPs

Detailed Syllabus

Organized by professional domains with comprehensive coverage

Topics Covered:
  • Intelligence lifecycle phases: planning, collection, processing, analysis, dissemination, and feedback applied to CTI
  • Priority Intelligence Requirements (PIRs): developing and managing stakeholder-driven intelligence requirements
  • Collection management: matching sources to requirements and managing source gaps systematically
  • Intelligence bias recognition: confirmation bias, anchoring, availability, and mirror imaging in CTI analysis
  • Confidence grading frameworks: analytic certainty, source reliability, and information credibility rating systems
Stage 5Final Capstone

XCTI: Xcademia Cyber Threat Intelligence Practitioner — Capstone Project

On Day 6, participants receive a raw intelligence collection package covering a simulated threat actor active against UK financial services: network IOCs, OSINT artefacts, a malware analysis summary, and industry threat reports. They must apply Diamond Model analysis, MITRE ATT&CK mapping, structured analytic techniques, and produce a complete threat intelligence product covering threat actor profile, campaign timeline, ATT&CK heat map, tactical IOC list, and executive summary. The senior practitioner assesses analytical rigour, technique application, confidence grading, and product quality.

Assessed by a senior Xcademia practitioner

Framework Alignment

This course is mapped directly onto the standards your organisation already answers to. No invented frameworks, no proprietary jargon.

  • MITRE ATT&CK v14

    Global

    Threat actor profiling, campaign analysis, and detection gap mapping throughout all technical domains

  • Diamond Model

    Global

    Intrusion analysis framework: adversary, infrastructure, capability, and victim applied throughout

  • Cyber Kill Chain

    Global

    Campaign phase analysis: reconnaissance through impact applied to threat actor profiling throughout

  • STIX 2.1 and TAXII 2.1

    Global

    Structured threat intelligence sharing standards: platform integration and intelligence exchange throughout

  • TLP 2.0

    Global

    Traffic Light Protocol for intelligence sharing governance: applied to all intelligence product distribution

  • MISP Project

    Global

    Open-source threat intelligence platform: full operator-level coverage throughout Days 3 and 4

  • OpenCTI

    Global

    Open-source CTI platform: threat actor and campaign management throughout Days 3 and 4

  • OSINT Framework

    Global

    Open-source intelligence collection methodology: passive collection techniques throughout Day 2

Skills You'll Gain

Master these in-demand skills through hands-on practice

Intelligence lifecycle and requirements managementOSINT collection (Maltego/Shodan/Censys)STIX 2.1 and TAXII 2.1MISP platform operationsOpenCTI threat actor profilingDiamond Model intrusion analysisCyber Kill Chain analysisThreat actor profiling and attributionDark web intelligence collectionStrategic CTI product developmentIOC lifecycle managementCTI integration into SOC and SOAR

Career Progression

A clear view of the roles this programme supports, what typically comes next, and where learners progress over time

Cyber Threat Intelligence AnalystThreat Intelligence LeadSOC L3 Analyst (CTI)Incident Responder (CTI)Strategic Threat AnalystRed Team Intelligence Analyst
Flexible Delivery Options

Ways to Learn

Choose the learning format that works best for you and your team

Book Now

Live Online

Instructor-Led Training

Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.

6 Days
Small cohorts
  • Live instructor interaction (real-time)
  • Trainer-led walkthroughs and real examples
  • Guided resources and session notes provided
  • Structured Q&A and practical discussion

Price per person

$4,996+ VAT

Group enrolments and early planning options available.

Also Available

Custom quotes for teams and organisations

Onsite Training

Quote Required

We come to you. Training delivered at your workplace for teams of 6 or more.

6 Days

Custom pricing based on:

  • • Team size & location
  • • Training dates & duration
  • • Customisation requirements
  • Training at your location
  • Customised content for your team
  • Flexible scheduling

No obligation. Response within 1 business day.

Venue-Based

Quote Required

Classroom training at a professional venue. Ideal for focused, immersive learning.

6 Days

Custom pricing based on:

  • • Team size & location
  • • Training dates & duration
  • • Customisation requirements
  • Professional training venue
  • Face-to-face instruction
  • Networking opportunities

No obligation. Response within 1 business day.

Blended

Quote Required

Combine online and in-person learning for maximum flexibility and impact.

6 Days

Timeline tailored to learner availability

Custom pricing based on:

  • • Team size & location
  • • Training dates & duration
  • • Customisation requirements
  • Mix of online and classroom
  • Self-paced pre-work
  • Intensive practical sessions

No obligation. Response within 1 business day.

All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.

Premium Training Option

Prefer a Faster, Personalised Route into IT?

Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.

Personalised XCTI: Xcademia Cyber Threat Intelligence Practitioner learning plan
Tailored to your pace and goals
Live 1-to-1 sessions
With an experienced mentor
Real-world troubleshooting
Practice, not just exam theory
Flexible scheduling
To fit around work, study, or family

"Many learners choose 1-to-1 when they want understanding, not memorisation."

Exam & Certification Information

Everything you need to know about the certification exams

Awarding Organisation
Xcademia
Credential Awarded
Certificate of completion

Important Information

You will receive an Xcademia certificate of completion based on participation and successful completion of labs and scenario simulations.

Credential

Certificate of Completion

On successful completion of XCTI: Xcademia Cyber Threat Intelligence Practitioner, learners receive an Xcademia Certificate of Completion. This standalone certificate is issued directly by Xcademia and is aligned with globally recognised frameworks and best practices.

Frequently Asked Questions

Everything you need to know about this course

SANS FOR578 costs approximately $9,000 total including training and the GCTI exam (115 to 118 MCQs, 3 hours, closed-book). XCTI is 6 instructor-led days ending in a supervised intelligence analysis exercise on Day 6 where participants receive raw intelligence collection data and must produce a professional threat intelligence product. The Practitioner Assessment Report documents analytical capability and product quality. Less than half the GCTI total cost.

Share:

Ready to Start Your Learning Journey?

Take the next step in your professional development

Digital certificate upon completion
Comprehensive course materials
Expert instructor support
Flexible learning options