Threat Intelligence Expert (Live Certification Program)

Become a job ready Cyber Threat Intelligence analyst. The Techonquer Certified Threat Intelligence Expert program is a complete 12 week path from threat intelligence foundations to operational tradecraft. Every week builds toward one of six real deliverables, from a threat actor profile report to a full intelligence platform build, covering OSINT, infrastructure tracking, malware intelligence, threat hunting, dark web monitoring and automation, all mapped to the MITRE ATT&CK framework, so you finish job ready with proof to show for it.

#ThreatIntelligence #OSINT #MalwareIntel #ThreatHunting #MITREATTCK
What You Will Learn
  • Threat Intelligence Lifecycle & Analysis
  • OSINT, Infrastructure & Attribution Tracking
  • Malware Intelligence & Threat Hunting
  • Dark Web, Credential & Ransomware Intel
  • MITRE ATT&CK & Cyber Kill Chain
  • Intelligence Platforms: MISP & OpenCTI
Requirements
  • Basic understanding of networking concepts such as IP addresses, DNS and ports
  • Familiarity with how the internet and web infrastructure work
  • Comfort using a computer at a technical level, no coding experience required
Rs 15,000
Rs 8,000
Limited-time discount offer
Enroll Now
Instructor:Harsh Sharma
Start Date:22 September
Days:Mon, Tue, Wed
Level:Basic to Advanced
Duration:12 Weeks (3 Months)
Installments:Rs 4,000 + Rs 4,000
Back to Courses
Eligibility

Who Can Join This Course

This program is built for anyone who wants to move into threat intelligence, whether you are starting from a security foundation or coming in fresh. No prior intelligence experience is required, only a genuine interest in how threats are tracked and understood.

Students and Freshers

Anyone from a computer science, IT or cybersecurity background who wants to enter threat intelligence as a first career path.

SOC Analysts

Analysts already working in a Security Operations Center who want to move from alert triage into intelligence driven work.

IT and Network Professionals

Working professionals from IT, networking or system administration backgrounds who want to shift into cybersecurity.

Security Enthusiasts

Self-taught learners with basic networking and security knowledge who want a structured, job-focused path forward.

Recommended Before You Start
  • Basic understanding of networking concepts such as IP addresses, DNS and ports
  • Familiarity with how the internet and web infrastructure work
  • Comfort using a computer at a technical level, no coding experience required
  • Curiosity about how attackers operate and how that behaviour is tracked
Syllabus

12 Weeks. 55+ Topics.

A complete path from threat intelligence foundations to operational tradecraft. Every week builds toward one of six real deliverables, from a threat actor profile report to a full intelligence platform build, so you finish job ready.

03
Months
12
Weeks
55+
Topics
06
Deliverables
Program Phases
01

Foundations

Weeks 01 to 04. Understand the discipline, then collect and analyse intelligence.

02

Advanced

Weeks 05 to 08. Track infrastructure, study malware and hunt for threats.

03

Tradecraft

Weeks 09 to 11. Dark web, leaked credentials, ransomware and platform building.

04

Capstone

Week 12. Automate the workflow and run a full intelligence operation.

Curriculum

Week by Week Breakdown

Twelve modules, one per week, each closing with a hands-on practical lab that builds toward the program's six final deliverables.

M01 · Foundations

Introduction to Threat Intelligence

Week 01 of 12

This is where the discipline itself gets defined. Before you can collect or analyse anything, you need a working vocabulary: what separates raw data from information, and information from intelligence that is actually decision ready. The module walks through the four types of threat intelligence, strategic, operational, tactical and technical, and closes with the intelligence lifecycle, plus a grounding tour of the current threat landscape.

  • What is threat intelligence
  • Data vs information vs intelligence
  • Types of TI: strategic, operational, tactical, technical
  • Intelligence lifecycle
  • Threat landscape overview
Practical LabReading threat reports

Read a public threat report the way an analyst does, and pull out its type, confidence level and audience.

M02 · Foundations

Threat Actors and APTs

Week 02 of 12

Intelligence is ultimately about people and groups, not just indicators. You will learn how threat actors are classified, from opportunistic criminals to state sponsored Advanced Persistent Threat groups, and how their behaviour gets documented in a structured, repeatable way using MITRE ATT&CK and the Cyber Kill Chain.

  • Threat actor types
  • APT groups overview
  • MITRE ATT&CK framework
  • Cyber Kill Chain
  • TTPs: tactics, techniques, procedures
Practical LabMapping an APT to ATT&CK

Take a real APT profile and plot its known behaviour onto the ATT&CK matrix, tactic by tactic.

M03 · Foundations

Intelligence Collection and Feeds

Week 03 of 12

No analysis is better than the collection that feeds it. You will work through the major collection disciplines, OSINT, TECHINT, HUMINT and SOCMINT, and learn commercial and open intelligence feeds alongside discovery tooling so you can start building a repeatable collection pipeline.

  • OSINT
  • TECHINT
  • HUMINT
  • SOCMINT
  • Dark web intelligence
  • Intelligence feeds
  • Shodan, Censys, theHarvester, SpiderFoot
Practical LabBuilding a collection pipeline

Combine two or more collection sources into one pipeline you can reuse in later modules.

M04 · Foundations

Analysis and Reporting

Week 04 of 12

This module turns everything collected so far into something a decision maker can actually use: structured analytic techniques including Analysis of Competing Hypotheses, link and timeline analysis, confidence levels, professional report writing, and the technical side of extracting IOCs and writing your first YARA and Sigma rules.

  • Structured analytic techniques
  • Analysis of Competing Hypotheses (ACH)
  • Link analysis
  • Timeline analysis
  • Intelligence confidence levels
  • Intelligence report writing
  • IOC extraction
  • YARA basics
  • Sigma rules
Practical LabFull intelligence cycle simulation

Run one dataset through collection, analysis and reporting end to end, and write a short brief.

M05 · Advanced

Infrastructure Tracking

Week 05 of 12

Attackers reuse infrastructure far more than they would like you to think, and this module teaches you to exploit that habit: domain intelligence and passive DNS history, SSL/TLS certificate tracking, and IP correlation across campaigns rather than treating a single indicator as the whole finding.

  • Domain intelligence
  • Passive DNS
  • SSL/TLS certificate tracking
  • IP correlation
  • Infrastructure fingerprinting
Practical LabComplete infrastructure mapping

Start from a single domain and build out a full infrastructure map using DNS and certificate history.

M06 · Advanced

Attribution and Infrastructure Analysis

Week 06 of 12

Building on last week's infrastructure work, this module moves toward the harder question of who is actually behind an operation, including geolocation signals and language analysis. Attribution is treated as probabilistic, with emphasis on a defensible chain of correlated evidence rather than jumping straight to a name.

  • Attribution techniques
  • Geolocation and language analysis
  • Infrastructure correlation and mapping
Practical LabComplete infrastructure mapping

Extend last week's map with attribution signals and document your confidence in each connection.

M07 · Advanced

Malware Intelligence

Week 07 of 12

Malware is one of the richest sources of threat intelligence available, if you know how to read it: malware types and families, static vs dynamic analysis in a sandbox, how malware communicates with its command and control infrastructure, and how to connect samples back to a broader campaign.

  • Malware types and families
  • Static vs dynamic analysis
  • Sandbox analysis
  • Behavioral analysis
  • C2 communication patterns
  • Network traffic analysis
Practical LabMalware campaign tracking

Take a sample from initial triage through to identifying which broader campaign it belongs to.

M08 · Advanced

Threat Hunting and Detection

Week 08 of 12

This is where intelligence stops being descriptive and starts being used to actively find things: three approaches to hunting, hypothesis driven, IOC based and TTP based, followed by hands-on detection engineering that turns findings into durable Sigma and YARA rules.

  • Hypothesis-driven hunting
  • IOC-based hunting
  • TTP-based hunting
  • Anomaly detection
  • Detection engineering
  • Sigma rules deep dive
  • YARA rules deep dive
Practical LabFull hunt simulation

Run a complete hunt from hypothesis to a working detection rule against a simulated environment.

M09 · Tradecraft

Dark Web Intelligence

Week 09 of 12

The tradecraft phase opens with the part of the internet most collection tools never touch: how to access and monitor dark web sources safely and responsibly, and how to build a structured, repeatable process for watching underground forums over time.

  • Dark web intelligence
  • Underground forum monitoring
Practical LabUnderground forum monitoring

Set up a structured, safe process for tracking activity on an underground forum over time.

M10 · Tradecraft

Credential and Ransomware Intelligence

Week 10 of 12

Two of the most operationally urgent intelligence areas get their own dedicated week: how leaked credentials move through breach dumps, combolists and stealer logs, and ransomware intelligence, following the ecosystem of ransomware groups, their leak sites and negotiation behaviour.

  • Leaked credential tracking
  • Ransomware intelligence
Practical LabThreat intelligence investigation

Combine credential exposure and ransomware group tracking into one focused investigation.

M11 · Tradecraft

Intelligence Platform

Week 11 of 12

Everything collected and analysed so far has lived in notes, spreadsheets and one-off reports. This module moves that work into a real intelligence platform: MISP for structured indicator sharing and OpenCTI for connecting intelligence into a knowledge graph, thinking of a platform as the backbone of a team's program.

  • Building an intelligence platform
  • MISP
  • OpenCTI
Practical LabBuilding the intelligence platform

Stand up a working MISP or OpenCTI instance and load in indicators from earlier modules.

M12 · Capstone

Automation and Capstone

Week 12 of 12

The program closes by making everything you have learned repeatable at scale: automate parts of the intelligence workflow with Python, then run a full intelligence operation end to end, collection, analysis, infrastructure tracking, reporting and platform entry, against a realistic scenario.

  • Automation with Python
  • Capstone: full intelligence operation
Practical LabCapstone: full intelligence operation

Run the entire intelligence cycle end to end against a realistic scenario as your final deliverable.

Technical Toolkit

The Technical Ecosystem Covered in the Syllabus

Named technologies and methodologies used across the twelve week program.

Frameworks and Analytic Methods

MITRE ATT&CKCyber Kill ChainStructured analytic techniquesACH

Collection and Discovery

OSINTTECHINTHUMINTSOCMINTShodanCensystheHarvesterSpiderFoot

Detection

YARASigma

Intelligence Platforms

MISPOpenCTI

Infrastructure Analysis

Passive DNSSSL/TLS certificate trackingIP correlationInfrastructure fingerprinting

Advanced Intelligence

Dark web intelligenceUnderground forum monitoringLeaked credential trackingRansomware intelligenceAutomation with Python
About Your Mentor

Harsh Sharma

Security Analyst, Techonquer (TQ) · Associated with Cyber Cell, Ministry of Home Affairs

4+ Yrs
Teaching Exp.
Cyber Cell
Ministry of Home Affairs
Security Analyst
Techonquer

Our Placed Students

Success stories of learners who transformed their careers through Techonquer's trainings

Shiv

Shiv

Security Analyst, EYLinkedIn
Sandhya

Sandhya

Network Engineer, IZEON InnovationLinkedIn
Satish Kumar

Satish Kumar

Graduate Trainee, TCSLinkedIn
Vedant Salaskar

Vedant Salaskar

SOC Analyst, CyberNXLinkedIn
Sarvesh

Sarvesh

Jr Pre-Sales Engineer, Crowe IndiaLinkedIn
Shubham

Shubham

SOC Analyst, CyberAssureLinkedIn
Nilesh

Nilesh

SOC and Technical AnalystLinkedIn
Shiv

Shiv

Security Analyst, EYLinkedIn
Sandhya

Sandhya

Network Engineer, IZEON InnovationLinkedIn
Satish Kumar

Satish Kumar

Graduate Trainee, TCSLinkedIn
Vedant Salaskar

Vedant Salaskar

SOC Analyst, CyberNXLinkedIn
Update: This list is continuously being updated. Many more students have been placed and their profiles will be published soon.

Placement Assistance

Our placement assistance is focused on making you job-ready by building your technical confidence, interview skills, and real world understanding of threat intelligence and SOC hiring requirements.

ATS-Friendly CV Preparation

Build a professional, ATS-optimized resume tailored for Threat Intelligence Analyst, SOC Analyst and Threat Hunter job roles after completing the program.

Monthly Mock Interview Sessions

Every month, practice real technical and HR interviews covering threat intel workflows, OSINT, IOC analysis, MITRE ATT&CK mapping and situational SOC questions.

Interview Confidence Building

Dedicated sessions to improve communication, articulation of hands-on lab experience, and overall interview mindset, preparing you for both technical and behavioral rounds.

Job Opportunity Sharing

Throughout the program, relevant threat intelligence and SOC job openings, internship listings, referrals and hiring updates are actively shared with all enrolled students.

What You Can Become After This Course

By the end of the twelve weeks you will have six real deliverables in hand and a working knowledge of the full intelligence cycle. That combination opens up roles across the defensive and intelligence side of cybersecurity.

Cyber Threat Intelligence Analyst

Track adversaries, build actor profiles and turn raw indicators into reporting that decision makers actually use.

SOC Analyst (L2 / L3)

Move beyond alert triage into intelligence-informed investigation using ATT&CK, IOCs and structured analysis.

Threat Hunter

Proactively search environments for hidden threats using hypothesis-driven and TTP-based hunting techniques.

Malware Intelligence Analyst

Analyse malware samples, trace C2 infrastructure and connect individual samples back to broader campaigns.

OSINT Investigator

Run open source investigations using Shodan, Censys, theHarvester and SpiderFoot for reconnaissance and attribution.

Detection Engineer

Write and maintain YARA and Sigma rules that turn hunt findings into durable, reusable detections.

CTI Platform Engineer

Build and run threat intelligence platforms like MISP and OpenCTI as the shared backbone for a security team.

What the Syllabus Specifies You Will Produce

These six deliverables are listed explicitly in the source syllabus.

01Threat actor profile report
02Infrastructure map
03Malware campaign report
04Detection rules (YARA / Sigma)
05Full intelligence platform
06Capstone operation report
Program format: 3 months, 12 weeks. The 12 week structure organises the course duration while keeping the source syllabus terminology, topics and practical outputs intact.

Frequently Asked Questions

When does the training start and on which days?

Batch dates are announced regularly. The program runs 3 days per week on Monday, Tuesday and Wednesday with live instructor-led sessions across 12 weeks.

Is this live training or recorded?

This is a 100% live training program. All sessions are instructor-led and lifetime recording access is provided for revision.

Which tools and frameworks are covered?

You will get hands-on experience with OSINT and discovery tools like Shodan, Censys, theHarvester and SpiderFoot, detection tooling like YARA and Sigma, and intelligence platforms MISP and OpenCTI, all mapped to the MITRE ATT&CK framework.

What is the fee structure?

The total program fee is Rs 15,000. Under the current discount offer the fee is Rs 8,000, payable as Rs 4,000 at registration and Rs 4,000 after the first month.

Do I need prior threat intelligence experience?

No. The program starts from the fundamentals and moves through infrastructure tracking, malware intelligence, threat hunting and dark web tradecraft, so it is beginner friendly. Basic networking knowledge is helpful but not required.

What certification will I receive?

On successful completion you earn the Techonquer Certified Threat Intelligence Expert credential, validating hands-on capability across the full threat intelligence lifecycle.

Will I get mentor support?

Yes, you will receive 1-to-1 mentor support from Harsh Sharma throughout the training to help you understand concepts and clear doubts.

Are the seats limited?

Yes, this program has limited seats to ensure personalized attention, practical guidance, and effective mentor support for every student.