Threat Intelligence Expert (Live Certification Program)
Become a job ready Cyber Threat Intelligence analyst. The Techonquer Certified Threat Intelligence Expert program is a complete 12 week path from threat intelligence foundations to operational tradecraft. Every week builds toward one of six real deliverables, from a threat actor profile report to a full intelligence platform build, covering OSINT, infrastructure tracking, malware intelligence, threat hunting, dark web monitoring and automation, all mapped to the MITRE ATT&CK framework, so you finish job ready with proof to show for it.
- Threat Intelligence Lifecycle & Analysis
- OSINT, Infrastructure & Attribution Tracking
- Malware Intelligence & Threat Hunting
- Dark Web, Credential & Ransomware Intel
- MITRE ATT&CK & Cyber Kill Chain
- Intelligence Platforms: MISP & OpenCTI
- Basic understanding of networking concepts such as IP addresses, DNS and ports
- Familiarity with how the internet and web infrastructure work
- Comfort using a computer at a technical level, no coding experience required
Who Can Join This Course
This program is built for anyone who wants to move into threat intelligence, whether you are starting from a security foundation or coming in fresh. No prior intelligence experience is required, only a genuine interest in how threats are tracked and understood.
Students and Freshers
Anyone from a computer science, IT or cybersecurity background who wants to enter threat intelligence as a first career path.
SOC Analysts
Analysts already working in a Security Operations Center who want to move from alert triage into intelligence driven work.
IT and Network Professionals
Working professionals from IT, networking or system administration backgrounds who want to shift into cybersecurity.
Security Enthusiasts
Self-taught learners with basic networking and security knowledge who want a structured, job-focused path forward.
- Basic understanding of networking concepts such as IP addresses, DNS and ports
- Familiarity with how the internet and web infrastructure work
- Comfort using a computer at a technical level, no coding experience required
- Curiosity about how attackers operate and how that behaviour is tracked
12 Weeks. 55+ Topics.
A complete path from threat intelligence foundations to operational tradecraft. Every week builds toward one of six real deliverables, from a threat actor profile report to a full intelligence platform build, so you finish job ready.
Foundations
Weeks 01 to 04. Understand the discipline, then collect and analyse intelligence.
Advanced
Weeks 05 to 08. Track infrastructure, study malware and hunt for threats.
Tradecraft
Weeks 09 to 11. Dark web, leaked credentials, ransomware and platform building.
Capstone
Week 12. Automate the workflow and run a full intelligence operation.
Week by Week Breakdown
Twelve modules, one per week, each closing with a hands-on practical lab that builds toward the program's six final deliverables.
Introduction to Threat Intelligence
This is where the discipline itself gets defined. Before you can collect or analyse anything, you need a working vocabulary: what separates raw data from information, and information from intelligence that is actually decision ready. The module walks through the four types of threat intelligence, strategic, operational, tactical and technical, and closes with the intelligence lifecycle, plus a grounding tour of the current threat landscape.
- What is threat intelligence
- Data vs information vs intelligence
- Types of TI: strategic, operational, tactical, technical
- Intelligence lifecycle
- Threat landscape overview
Read a public threat report the way an analyst does, and pull out its type, confidence level and audience.
Threat Actors and APTs
Intelligence is ultimately about people and groups, not just indicators. You will learn how threat actors are classified, from opportunistic criminals to state sponsored Advanced Persistent Threat groups, and how their behaviour gets documented in a structured, repeatable way using MITRE ATT&CK and the Cyber Kill Chain.
- Threat actor types
- APT groups overview
- MITRE ATT&CK framework
- Cyber Kill Chain
- TTPs: tactics, techniques, procedures
Take a real APT profile and plot its known behaviour onto the ATT&CK matrix, tactic by tactic.
Intelligence Collection and Feeds
No analysis is better than the collection that feeds it. You will work through the major collection disciplines, OSINT, TECHINT, HUMINT and SOCMINT, and learn commercial and open intelligence feeds alongside discovery tooling so you can start building a repeatable collection pipeline.
- OSINT
- TECHINT
- HUMINT
- SOCMINT
- Dark web intelligence
- Intelligence feeds
- Shodan, Censys, theHarvester, SpiderFoot
Combine two or more collection sources into one pipeline you can reuse in later modules.
Analysis and Reporting
This module turns everything collected so far into something a decision maker can actually use: structured analytic techniques including Analysis of Competing Hypotheses, link and timeline analysis, confidence levels, professional report writing, and the technical side of extracting IOCs and writing your first YARA and Sigma rules.
- Structured analytic techniques
- Analysis of Competing Hypotheses (ACH)
- Link analysis
- Timeline analysis
- Intelligence confidence levels
- Intelligence report writing
- IOC extraction
- YARA basics
- Sigma rules
Run one dataset through collection, analysis and reporting end to end, and write a short brief.
Infrastructure Tracking
Attackers reuse infrastructure far more than they would like you to think, and this module teaches you to exploit that habit: domain intelligence and passive DNS history, SSL/TLS certificate tracking, and IP correlation across campaigns rather than treating a single indicator as the whole finding.
- Domain intelligence
- Passive DNS
- SSL/TLS certificate tracking
- IP correlation
- Infrastructure fingerprinting
Start from a single domain and build out a full infrastructure map using DNS and certificate history.
Attribution and Infrastructure Analysis
Building on last week's infrastructure work, this module moves toward the harder question of who is actually behind an operation, including geolocation signals and language analysis. Attribution is treated as probabilistic, with emphasis on a defensible chain of correlated evidence rather than jumping straight to a name.
- Attribution techniques
- Geolocation and language analysis
- Infrastructure correlation and mapping
Extend last week's map with attribution signals and document your confidence in each connection.
Malware Intelligence
Malware is one of the richest sources of threat intelligence available, if you know how to read it: malware types and families, static vs dynamic analysis in a sandbox, how malware communicates with its command and control infrastructure, and how to connect samples back to a broader campaign.
- Malware types and families
- Static vs dynamic analysis
- Sandbox analysis
- Behavioral analysis
- C2 communication patterns
- Network traffic analysis
Take a sample from initial triage through to identifying which broader campaign it belongs to.
Threat Hunting and Detection
This is where intelligence stops being descriptive and starts being used to actively find things: three approaches to hunting, hypothesis driven, IOC based and TTP based, followed by hands-on detection engineering that turns findings into durable Sigma and YARA rules.
- Hypothesis-driven hunting
- IOC-based hunting
- TTP-based hunting
- Anomaly detection
- Detection engineering
- Sigma rules deep dive
- YARA rules deep dive
Run a complete hunt from hypothesis to a working detection rule against a simulated environment.
Dark Web Intelligence
The tradecraft phase opens with the part of the internet most collection tools never touch: how to access and monitor dark web sources safely and responsibly, and how to build a structured, repeatable process for watching underground forums over time.
- Dark web intelligence
- Underground forum monitoring
Set up a structured, safe process for tracking activity on an underground forum over time.
Credential and Ransomware Intelligence
Two of the most operationally urgent intelligence areas get their own dedicated week: how leaked credentials move through breach dumps, combolists and stealer logs, and ransomware intelligence, following the ecosystem of ransomware groups, their leak sites and negotiation behaviour.
- Leaked credential tracking
- Ransomware intelligence
Combine credential exposure and ransomware group tracking into one focused investigation.
Intelligence Platform
Everything collected and analysed so far has lived in notes, spreadsheets and one-off reports. This module moves that work into a real intelligence platform: MISP for structured indicator sharing and OpenCTI for connecting intelligence into a knowledge graph, thinking of a platform as the backbone of a team's program.
- Building an intelligence platform
- MISP
- OpenCTI
Stand up a working MISP or OpenCTI instance and load in indicators from earlier modules.
Automation and Capstone
The program closes by making everything you have learned repeatable at scale: automate parts of the intelligence workflow with Python, then run a full intelligence operation end to end, collection, analysis, infrastructure tracking, reporting and platform entry, against a realistic scenario.
- Automation with Python
- Capstone: full intelligence operation
Run the entire intelligence cycle end to end against a realistic scenario as your final deliverable.
The Technical Ecosystem Covered in the Syllabus
Named technologies and methodologies used across the twelve week program.
Frameworks and Analytic Methods
MITRE ATT&CKCyber Kill ChainStructured analytic techniquesACHCollection and Discovery
OSINTTECHINTHUMINTSOCMINTShodanCensystheHarvesterSpiderFootDetection
YARASigmaIntelligence Platforms
MISPOpenCTIInfrastructure Analysis
Passive DNSSSL/TLS certificate trackingIP correlationInfrastructure fingerprintingAdvanced Intelligence
Dark web intelligenceUnderground forum monitoringLeaked credential trackingRansomware intelligenceAutomation with PythonHarsh Sharma
Security Analyst, Techonquer (TQ) · Associated with Cyber Cell, Ministry of Home Affairs
Our Placed Students
Success stories of learners who transformed their careers through Techonquer's trainings
Placement Assistance
Our placement assistance is focused on making you job-ready by building your technical confidence, interview skills, and real world understanding of threat intelligence and SOC hiring requirements.
ATS-Friendly CV Preparation
Build a professional, ATS-optimized resume tailored for Threat Intelligence Analyst, SOC Analyst and Threat Hunter job roles after completing the program.
Monthly Mock Interview Sessions
Every month, practice real technical and HR interviews covering threat intel workflows, OSINT, IOC analysis, MITRE ATT&CK mapping and situational SOC questions.
Interview Confidence Building
Dedicated sessions to improve communication, articulation of hands-on lab experience, and overall interview mindset, preparing you for both technical and behavioral rounds.
Job Opportunity Sharing
Throughout the program, relevant threat intelligence and SOC job openings, internship listings, referrals and hiring updates are actively shared with all enrolled students.
What You Can Become After This Course
By the end of the twelve weeks you will have six real deliverables in hand and a working knowledge of the full intelligence cycle. That combination opens up roles across the defensive and intelligence side of cybersecurity.
Cyber Threat Intelligence Analyst
Track adversaries, build actor profiles and turn raw indicators into reporting that decision makers actually use.
SOC Analyst (L2 / L3)
Move beyond alert triage into intelligence-informed investigation using ATT&CK, IOCs and structured analysis.
Threat Hunter
Proactively search environments for hidden threats using hypothesis-driven and TTP-based hunting techniques.
Malware Intelligence Analyst
Analyse malware samples, trace C2 infrastructure and connect individual samples back to broader campaigns.
OSINT Investigator
Run open source investigations using Shodan, Censys, theHarvester and SpiderFoot for reconnaissance and attribution.
Detection Engineer
Write and maintain YARA and Sigma rules that turn hunt findings into durable, reusable detections.
CTI Platform Engineer
Build and run threat intelligence platforms like MISP and OpenCTI as the shared backbone for a security team.
What the Syllabus Specifies You Will Produce
These six deliverables are listed explicitly in the source syllabus.
Frequently Asked Questions
When does the training start and on which days?
Batch dates are announced regularly. The program runs 3 days per week on Monday, Tuesday and Wednesday with live instructor-led sessions across 12 weeks.
Is this live training or recorded?
This is a 100% live training program. All sessions are instructor-led and lifetime recording access is provided for revision.
Which tools and frameworks are covered?
You will get hands-on experience with OSINT and discovery tools like Shodan, Censys, theHarvester and SpiderFoot, detection tooling like YARA and Sigma, and intelligence platforms MISP and OpenCTI, all mapped to the MITRE ATT&CK framework.
What is the fee structure?
The total program fee is Rs 15,000. Under the current discount offer the fee is Rs 8,000, payable as Rs 4,000 at registration and Rs 4,000 after the first month.
Do I need prior threat intelligence experience?
No. The program starts from the fundamentals and moves through infrastructure tracking, malware intelligence, threat hunting and dark web tradecraft, so it is beginner friendly. Basic networking knowledge is helpful but not required.
What certification will I receive?
On successful completion you earn the Techonquer Certified Threat Intelligence Expert credential, validating hands-on capability across the full threat intelligence lifecycle.
Will I get mentor support?
Yes, you will receive 1-to-1 mentor support from Harsh Sharma throughout the training to help you understand concepts and clear doubts.
Are the seats limited?
Yes, this program has limited seats to ensure personalized attention, practical guidance, and effective mentor support for every student.






