You see the headlines: “Ransomware gang cripples hospital.” You see the what. But you’re obsessed with the who, the why, and the how. If those are the questions that keep you up at night, you’re in the right place.
But let’s be honest: the path to becoming a Cyber Threat Intelligence (CTI) analyst isn’t a straight line. It’s not a clear-cut major in college. It feels like you need to know everything—from malware reversing and data science to geopolitical analysis.
Do you need to speak Russian? Do you need a top-secret clearance? Is it a deeply technical role, or is it a writing and briefing role? (Spoiler: it’s “yes”).
The sheer volume of “must-have” skills is overwhelming, and the most common question I hear is, “Where do I even start?”
If you’re feeling lost, this is for you. We’re demystifying the chaos. This isn’t just a random list of links; it’s a structured CTI analyst roadmap. We’re going to break this journey down into three core pillars you need to build your career as a CTI analyst:
- Core Security Skills: The “hands-on-keyboard” technical bedrock.
- Analytical Skills: The “secret sauce” of thinking like an intelligence pro.
- Soft Skills: The “force multiplier” that makes your work matter.
Let’s jump in!
Core Security Skills
Before you can track the adversary, you have to understand the battlefield. This is the “table stakes” of CTI.
- You can’t analyze a phishing email if you don’t understand email headers.
- You can’t spot a threat actor’s TTPs if you don’t know what a normal process looks like on a Windows machine.
This is your technical foundation. These are the non-negotiable, hands-on skills you need to get in the door and be credible.

Let’s take a look at the core security skills you will need to be successful as a CTI analyst.
Investigation
At its heart, CTI is an investigative discipline. You’ll receive one IP address and be expected to manage a comprehensive campaign. Without a process, you’re just guessing, chasing ghosts down rabbit holes. You’ll fixate on a benign IP address because it’s in a “bad” country or waste hours on a false positive.
To thoroughly learn the investigation process, the Investigation Theory course from Applied Network Defense is perfect!
It literally teaches you how to think. Instead of just Googling an IP, you’ll learn to ask structured questions: “What’s the source of this IP? Is it a VPS, a residential address, or a TOR exit node? What other domains have historically resolved to it? Who owns the ASN? What does the ASN’s peering look like?”
To see these skills in action, your number one read should be The DFIR Report. It’s the gold standard for real-world intrusion analysis.
They don’t just give you IOCs; they show you the entire attack, end-to-end, with investigator commentary. You’ll see how the threat actor transitioned from a single phishing link to a domain-wide ransomware attack, all laid out on a timeline. This is how you learn what real attacks look like!
To go the extra mile, take a look at Digital Forensics and Incident Response (DFIR) specific training. For this, I recommend taking a look at Blue Cape Security!
To help you apply these investigation skills in the real world, you need foundational SOC skills.
SOC Skills
Many of the best CTI analysts come from the Security Operations Center (SOC). Why? Because they’ve spent thousands of hours on the front lines. They have a sixth sense—a “spidey sense”—for what “normal” looks like on a network, so “abnormal” sticks out instantly.
It’s the analyst who says, “Wait… powershell.exe is normal, but not when a Word doc from an \AppData\ folder spawns it. That’s wrong.” You need this knowledge!
Get hands-on with SIEM queries, EDR alerts, and firewall logs. Learn to hunt for a process name that has never run before or a user logging in from two different continents simultaneously.
Platforms like TryHackMe and Hack The Box have fantastic blue team paths for analyzing PCAPs, sifting through memory dumps, and parsing logs. But a new favorite is Let’s Defend.
It’s a “SOC-in-a-box” that feeds you real-world alerts to investigate in a simulated environment. It provides a virtual SIEM, EDR, and email gateway, forcing you to correlate alerts from multiple sources, just like a real job. It’s as close as you can get to day one on the job without being on the job.
Next up, the MITRE ATT&CK framework!
MITRE ATT&CK
You will live and breathe the MITRE ATT&CK framework. It’s not just a buzzword; it’s our industry’s common language. It’s the periodic table of adversary techniques.
Instead of saying, “The attacker ran a weird script to dump passwords,” you can say, “The adversary executed T1003.001, OS Credential Dumping: LSASS Memory.” This is precise, actionable, and universally understood by every other CTI, incident response, and detection engineering team worldwide.
MITRE provides fantastic MITRE ATT&CK Defender (MAD) training. This isn’t just about memorizing the matrix. It teaches you the philosophy of using ATT&CK for defensive gap analysis, mapping intelligence reports, and utilizing the ATT&CK Navigator tool to visualize and compare threat actor TTPs.
After learning all these core skills, you might wonder… Do I need to know how to program?
Programming
Let’s tackle the elephant in the room. Do you need to be a developer? No. Should you be able to write a 10-line script to save yourself 10 hours of manual work? Absolutely.
Your job is data wrangling. If you get a list of 10,000 domains from a sinkhole. You are not going to check them by hand. You will write a Python script to query the VirusTotal API, parse the JSON response, and output a clean CSV file containing only the malicious entries.
This isn’t about building the next great security tool; it’s about building your next great time-saver. That script just saved you an entire day of mind-numbing copy-pasting—a day you can now spend on actual analysis.
Other examples? Automating MISP event creation, parsing a 50-page PDF threat report to extract all IOCs, or building a simple scraper to monitor a dark web forum. You can even create your own Python threat hunting tools!
Start with any free Python course, and then move on to a project-based platform like boot.dev to learn how to build real-world applications.
Analytical Skills
You’ve got the technical chops. You can read a log, understand ATT&CK, and write a script. Fantastic. Now we get to the intelligence part of Cyber Threat Intelligence.
This is pillar two, the “secret sauce.” This is the leap from being a SOC analyst to a true intelligence analyst. This is how you take all that technical data, find the “so what?” and turn it into something a CISO can use to make a multi-million-dollar decision.

This pillar encompasses fundamental knowledge of intelligence and CTI-specific skills that you will need to master.
Intelligence Tradecraft
CTI is an intelligence discipline that borrows its core principles from the 100-year-old world of government intelligence. We stand on the shoulders of giants. You must learn the formal intelligence cycle.
It ensures you’re answering the right questions (Planning) and not just reporting on whatever is “loudest” (Collection). A CISO might ask, “Are we at risk from that new ransomware group?”
- Planning: That question becomes your requirement.
- Collection: You gather data from open-source reports, your threat feeds, and internal logs.
- Analysis: You analyze the data and find that they target your industry, but your specific controls are strong.
- Dissemination: You write a report: “We assess a low risk of compromise due to our controls, but a high risk of targeting. Recommend patching X vulnerability as a priority.”
This process transforms a vague question into a clear, actionable business answer. For this, the foundational textbook is The Intelligence Bible by Oliver Wright. It covers everything you need to know about the general field of intelligence to get started as a CTI analyst.
Once you have mastered the fundamental knowledge, you can then learn how to do real-world intelligence work with analytical techniques.
Structured Analytical Techniques
Here’s a secret: the human brain is lazy. It’s full of cognitive biases and loves to jump to conclusions. In our field, this is dangerous.
Incorrect attribution can send your incident response team on a wild goose chase, or worse, cause your company to misallocate millions in security spending based on a hunch. You’ll fall for confirmation bias—you see one TTP that overlaps with a big-name APT report, and you instantly attribute the attack, ignoring the 10 other pieces of evidence that point to a common cybercrime group.
To fight this, we use Structured Analytical Techniques (SATs).
The foundational text here is Structured Analytical Techniques for Intelligence Analysis by Heuer and Pherson. Buy it. Read it. Keep it on your desk. When you’re stuck, you’ll flip it open and find a tool.
A classic is Analysis of Competing Hypotheses (ACH)—it’s a simple method where you list all possible explanations (not just your favorite one) and systematically try to disprove each one. What’s left is your most likely and defensible answer. It’s the scientific method for spies.
Once you know how to perform intelligence analysis, you need to understand the process of transitioning from requirements to a finished product.
Generating Strategic Intelligence
It’s easy to write a tactical report: “Threat actor X used malware Y. Block this hash.” This helps today. It’s much harder to write a strategic report: “Based on their TTP shifts over 6 months and their new focus on cloud APIs, we assess threat actor X will target our AWS environment in Q3.”
It’s the difference between playing checkers and playing chess.
- A tactical report tells you what piece was moved.
- A strategic report tells you why they’re sacrificing that pawn, what their 3-move-ahead plan is, and how you should adjust your entire board to counter it.
The strategic report is what the business really cares about. This report enables a CISO to present to the board, stating, “We need to invest $500k in our cloud security next quarter, not next year, and here’s exactly why.”
To learn this, read Critical Thinking for Strategic Analysis by Pherson and Pherson. An excellent textbook that provides guiding questions to help you transition from an intelligence requirement to a finished intelligence product.
That’s enough talk about intelligence, let’s get into the CTI-specific learning resources!
CTI Specifics
Let’s get laser-focused on CTI itself.
For paid courses, ArcX is a practical, modern, and highly respected platform that offers affordable CTI training for various levels. The other big one is the SANS 578 Cyber Threat Intelligence course, which gets you the GCTI certification. It’s expensive, but it’s the most recognized cert in the industry and proves you have a solid foundation.
For books, Visual Threat Intelligence by Thomas Roccia is highly recommended. It helps you learn the basics of CTI through beautiful graphics, infographics, and diagrams that bring to life the subject matter. The other must-read is Intelligence-Driven Incident Response by Brown and Roberts. It bridges the gap between the CTI team and the incident response team, demonstrating that intelligence is more than just a report you email out; it’s an active, living part of the response, helping hunters identify the next compromised host before it becomes an alert.
There are also tons of free ebooks and PDF reports available online that I recommend exploring. To get you started, here are some of my favorites:
- Group-IB’s Operationalizing CTI e-book
- The UK Government’s Cyber Threat Intelligence: A Guide for Decision Makers and Analysts
- Definitive Guide to CTI by iSIGHT Partners
Next up, how to wrangle all the data and information you will be collecting as a CTI analyst.
Data Analysis
CTI is increasingly a big data problem. You don’t need a Ph.D. in stats, but you need to know if a pattern is real or just random chance.
Naked Statistics by Charles Wheelan is a fantastic, engaging book that teaches you to ask, “Is this spike in activity actually significant, or is it just the regular end-of-month backup script?” It “strips the dread from the data” and helps demystify the often daunting field of data analysis.
For tools, this goes back to Python. You must learn the Pandas library. It’s Excel on steroids, run from code.
You’ll receive a CSV file containing 5 million firewall logs. In two lines of Pandas, you can group by the source IP, count the number of connections, filter for specific ports, and sort by “most-frequent,” instantly finding your noisiest scanners or a potential C2 channel. This is the power that turns a mountain of data into a molehill of leads you can turn into actionable intelligence.
Mastering the fundamentals of data analysis is a key step on this CTI analyst roadmap, but honing your open-source intelligence (OSINT) skillset is even more critical.
OSINT
As an analyst, you’ll be hunting for clues on the open, deep, and dark web. You’ll be “pivoting” and following a breadcrumb trail to fulfill your priority intelligence requirements.
You start with a domain name from a phishing email. You use OSINT to find the registrar. You check the registration email, which leads you to 10 other malicious domains. You check the IPs for those domains, which leads you to a shared web host. You check other sites on that host… that’s pivoting.
The undisputed heavyweight champion in the Open-Source Intelligence (OSINT) world is Michael Bazzell. His book, OSINT Techniques, is the bible. It’s not a book you read; it’s a 900-page reference manual of tools and methods. It’s not just a list of websites; it’s a methodology that shows you how to find information you thought was impossible to find, from tracking social media accounts to digging up old, cached versions of websites to find clues.
Get this book, read it, and start practicing the OSINT techniques it describes today!
Soft Skills
This is the pillar everyone skips, and it’s the one that will determine if you’re a good analyst or a great one.
This is the “so what?” of your career. It’s the force multiplier. Your genius-level analysis is worthless if it stays in your head. If your report is unreadable, your briefing is confusing, or your boss doesn’t get why it matters, you’ve failed.

These soft skills matter in cyber security, and they are what amplify your technical expertise.
Communication
You’ll be briefing everyone from a junior SOC analyst to your CISO. You must tailor your message. The SOC analyst needs precision and speed. The CISO requires context and a clear understanding of the business impact.
- To the SOC analyst: “Here’s the YARA rule and the 5 IPs for this threat. Block it. Hunt for this mutex.”
- To the CISO: “This threat actor is targeting our industry, and their TTPs bypass our current EDR configuration. This represents a 15% increase in financial risk to our Q3 earnings. My recommendation is…”
Same intelligence, totally different product.
Supercommunicators by Charles Duhigg is a new favorite for learning this. It teaches you to identify what kind of conversation you’re in—are you sharing facts, feelings, or just trying to make a decision? Knowing this allows you to connect with your stakeholders and actually answer the question they intended to ask, not just the words they said.
Once you learn how to communicate effectively, you can move on to learning how to manage people and be impactful in your organization.
Management
You need to understand how you fit into the bigger picture. Whether you like it or not, you’re part of a business. The Manager’s Path by Camille Fournier is a tech classic that gives you a map of the corporate structure. Even if you never want to be a manager, it’s critical. It helps you understand what your boss actually cares about.
Hint: they’re probably fighting battles for resources, headcount, and budget.
Your boss isn’t just your boss; they’re your advocate. When your report clearly states, “Our CTI team’s analysis pre-empted an attack that would have cost the company $1.2M in downtime,” you’ve just given your boss the ultimate piece of ammunition to justify your team’s existence (and your next raise).
Don’t just see yourself as another analyst; become a business enabler.
Writing
This is the most important one. You are a professional writer who just happens to be a cyber security expert.
Your primary product is not the analysis; it’s the report of that analysis. Your analysis could be brilliant, but if your CISO has to read a 10-page, jargon-filled mess to find the one-sentence conclusion, you’ve failed. Your product is the CTI report, and it must be good!
The classic book here is On Writing Well by William Zinsser. It’s not about “dumbing it down.” It’s about clarity. It will teach you to write with active verbs, cut useless adverbs, and put your most important information first—a principle we call BLUF, or Bottom Line Up Front. Your CISO, who has 30 seconds between meetings, will appreciate it!
Summary
So, that’s the roadmap. It’s a lot, we know. But you don’t have to learn it all at once. This is a journey, a marathon, not a sprint. Every script you write, every log you analyze, and every report you clarify is a step forward.
- Start with the Core Security Skills: Get your hands on the keyboard. Learn to investigate, gain hands-on experience in a SOC-like environment, understand the ATT&CK framework, and learn just enough Python to be effective and save yourself time.
- Then, build your Analytical Skills: This is the tradecraft. Learn the intelligence cycle, fight your own biases with SATs, and start thinking strategically about the “so what?”
- Throughout the journey, polish your Soft Skills: this is your amplifier. Learn to communicate effectively, understand the business context, and, above all, learn to write with clarity.
This field is one of the most rewarding and challenging careers in the tech industry. The adversaries are relentless, innovative, and fast. However, by being smart, structured, and continually learning, you can land a CTI analyst role and excel in your career!
Frequently Asked Questions
Do I Really Need to Learn to Code to Be a CTI Analyst?
You don’t need to be a software developer, but it’s beneficial to learn scripting. Learning basic Python to automate data collection (like querying APIs) and analysis (using Pandas) will save you hundreds of hours, make you self-sufficient, and immediately separate you from other candidates.
I’m Not in a SOC. Can I Still Break Into CTI?
Absolutely. While the SOC is a common path, many analysts come from IT support, networking, incident response, or even non-technical roles like journalism or political science. The key is to demonstrate your passion and skills. Build a home lab, practice on platforms like Let’s Defend, write your own analysis of a recent threat report, and post it online. That hands-on initiative matters more than a specific job title.
What’s the Most Important Skill for a New CTI Analyst?
Curiosity. Technical skills can be taught. Writing can be learned. But a relentless, driving curiosity—the need to pull on a thread, ask “why?” five times, and not stop until you have a defensible answer—is the single greatest predictor of success in this field.
Which of These CTI Learning Resources Should I Start With Today?
If you’re brand new, start with two things: 1) Get hands-on with a platform like TryHackMe’s Blue Team paths or Let’s Defend to understand the technical data. 2) Start reading The DFIR Report to see what real-world analysis looks like. This combination will give you both the “what” and the “so what?” from day one.



