Skip to main content

Threat Intelligence

Enterprise Architecture

Key information

Next application deadline: TBC
Next course starts: TBC
Format: Fully online, asynchronous and synchronous
Course duration: 12 weeks
Language: English
EQF Level: 7
Delivered by: UPB
Awarding Institution: German University of Digital Science

Certification: 5 ECTS (~125 hours of study workload, including course activities and self-directed learning)
Fees: €350

Microcredential Information

This module aims to introduce the fundamentals of Cyber Threat Intelligence (CTI). The lectures will present the CTI lifecycle, highlight strategic integration and discuss emerging trends in this field. Students will learn how to identify threat intelligence data streams, apply the extracted information for vulnerability assessment and threat mitigation, and disseminate newly acquired knowledge into public databases.

Key Details

This module aims to introduce the fundamentals of Cyber Threat Intelligence (CTI).

The lectures will present the CTI lifecycle, highlight strategic integration and discuss emerging trends in this field. The students will learn how to identify threat intelligence data streams, apply the extracted information for vulnerability assessment and threat mitigation, and disseminate newly acquired knowledge into public databases.

Time commitment

(Estimated) Total workload: 125h
Contact hours:

  • lesson=10h
  • lab=20h
  • assignments=20h
  • Private study including examination preparation: 75h

Assessment

  • 60%: Digitally proctored Exam
  • 40%: Continuous Evaluation (e.g., weekly assignments, presentations, quizzes, practical exercises)
Register your interest

Subjects covered

Week 1: Introduction to Cyber Threat Intelligence (CTI)

  • Lecture: Overview of CTI and its role in a modern security strategy. Present open-source / commercial threat intelligence feeds.
  • Lab: Deploy aggregators for threat intelligence data streams. Probe for emerging threats based on geolocation and other factors.
  • Difficulty: Introductory

Week 2: CTI lifecycle and cybersecurity frameworks

  • Lecture: Present the phases of CTI and best practices to be applied at each stage. Discuss how CTI fits into frameworks such as MITRE ATT&CK and its integration with other areas in cybersecurity.
  • Lab: Become familiar with popular formats / schemas used in specifying Indicators of Compromise (IOC).
  • Difficulty: Introductory

Week 3: Strategic planning

  • Lecture: Describe how to align CTI with the security goals and policies of an organization. Explain how to present security-related findings to non-technical stakeholders.
  • Lab: Automate information extraction from public databases and use OSS to generate reports.
  • Difficulty: Introductory

Week 4: Vulnerability management

  • Lecture: Correlate threat intelligence with vulnerability detection to prioritize patching and mitigation. Present CVE databases.
  • Lab: Perform static, targeted malware detection based on publicly available signatures. Extend verification to an entire system.
  • Difficulty: Introductory

Week 5: Advanced threat actor profiling

  • Lecture: Explain the notion of Threat Actors and how to build Adversary Profiles using historical data and behavioural patterns.
  • Lab: Generate rotating network captures for arbitrary time frames. Investigate user activity and automatically extract identifying features. Discuss honeypots.
  • Difficulty: Intermediate

Week 6: Incident Response

  • Lecture:Present how CTI is used to guide Incident Response efforts. Discuss Intrusion Detection and Prevention Systems (IDP / IPS).
  • Lab: Configure an IDS / IPS to generate events or actively block traffic. Discuss its integration with the Linux network stack & the Netfilter Framework while considering the performance impact.
  • Difficulty: Advanced

Week 7: The role of auditing in CTI

  • Lecture: Discuss the importance of data collection during the CTI lifecycle, as well as its analysis and dissemination. Present new approaches in this field, such as Data Provenance.
  • Lab: Introduction to the Linux audit system and its configuration for detecting anomalous behaviour.
  • Difficulty: Intermediate

Week 8: Automation using Elastic Stack

  • Lecture: Introduction to Elastic Stack.
  • Focus: Configure the Logstash pipeline to collect and parse log entries from different sources. Pass the processed log data to an Elasticsearch cluster and visualise it via Kibana.
  • Difficulty: Advanced

Week 9: Emerging trends and the future of CTI

  • Lecture: Present challenges facing CTI today. Discuss methods of applying Machine Learning techniques for the purpose of achieving predictive threat intelligence.
  • Lab: Introduction to containers and microservice environments. Present technical challenges created by namespaces and how to overcome them. Discuss methods of applying these solutions to Virtual Machine images.
  • Difficulty: Advanced

Week 10: Review

  • Lecture: (optional) Guest speaker. Exam prep.
  • Lab: Review of previous activities.
  • Difficulty: N\A

Week 11-12: Consolidation and Future Directions

Register your interest

Learning objectives

Learning Outcomes:

On successful completion of this module, the learner will be able to:

• LO1: Recognize different types of cyber threats and apply analytical techniques to assess their potential impact.

• LO2: Gather threat data from open-source and proprietary sources, as well as structure it according to their needs.

• LO3: Incorporate threat intelligence into (automated) incident response processes, improving the detection, investigation, and mitigation of attacks.

• LO4: Use specialized platforms and tools to analyze threat data and share relevant information.

• LO5: Utilize the acquired intelligence to guide proactive threat hunting efforts with the goal of identifying potential compromises and indicators of attack.

Register your interest

Module leaders

Radu Mantu

FAQs

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

newsletterStay ahead in cybersecurity

Subscribe to our newsletter for exclusive insights and breakthroughs from Digital4Security directly to your inbox

Applications open
Hybrid Master's
Application deadline:
Friday, 11th September 2026, 22:00 CET
Course starts:
Monday, 28th September 2026
Course duration:
2 years | Hybrid (online + in-person intensives)
Course delivery:
Hybrid program
Certification:
ARACIS (Romania)-accredited masters's degree (120 ECTS)
Language:
English
Apply now
Applications closed
Microcredentials
Application deadline:
Friday, 25th September, 12:00 CEST
Course starts:
From October 2026 (application opens Monday, 27th July)
Course duration:
6-12 weeks depending on chosen course
Course delivery:
Online
Certification:
Official recognition of your completed learning outcomes and awarded ECTS
Language:
English
Register your Interest
Apply now Toggle