Day in the Life of a Senior Threat Intelligence Analyst

What does a day in the life of a cyber threat intelligence analyst look like? 

I often thought this when starting, along with what a SOC analyst actually does and exactly how busy CISOs are. I have been a senior cyber threat intelligence analyst (CTI analyst) for quite some time now and can divulge the secrets! 

Whether you are new to cyber security or just curious about what other cyber security professionals get up to, this article will answer your questions. It details what my typical workday looks like, the daily tasks I perform, and how this enhances the cyber security of my organization.

I have split my day into two chunks. The morning, where I get my daily tasks completed, and the afternoon, where any follow-ups from the morning happen, and the focus shifts to program or personal development. Let’s start from the beginning.


Morning

I typically start my day at 6:00 AM. I get up, make myself a nice cup of black coffee (instant), hydrate, and stare at the sun for 10 minutes. I’m told this is supposed to help you wake up, but I have no idea at this point, and I’m just trying to make the most of the British summer. Finally, I feed the dog and begin my day. 

From 6:30 to 9:00 AM, I work on any side projects or side hustles I have ongoing. I need to complete these tasks by the end of the day or make significant progress, so I prefer to tackle them first. Then the workday begins with my daily tasks, which can be split into threat intelligence, vulnerability intelligence, and threat hunting.

Threat Intelligence Tasks

To start our day, the team will analyze threat intelligence from a range of open sources and our Threat Intelligence Platform (TIP) to identify any new threats relevant to our organization. If we find a new threat, we validate any indicators related to it (to ensure the indicator won’t trigger false positives when we hunt for it) and then add it to our CTI database. 

The team focuses daily on ingesting operational and tactical intelligence that we can make actionable and hunt for. Strategic intelligence is collected and added to a backlog that is reviewed monthly to inform the direction of our CTI program.

For more information on how a CTI team uses intelligence, read Threat Intelligence vs Threat Hunting: What is the Perfect Pipeline?

Vulnerability Intelligence Tasks

Aside from threat intelligence, the team also analyzes vulnerability intelligence from various sources to check if any new vulnerabilities may impact our organization. 

Exploiting public-facing vulnerabilities is a common initial access method for threat actors. Hence, your organization must have a vulnerability management program to ensure that systems are up-to-date and patched. 

Our CTI team identifies new vulnerabilities, then determines if these are relevant to our organization and meet a minimum impact threshold, where immediate patching or mitigation is required. These vulnerabilities are then reported to our vulnerability management team, who are responsible for implementing the patches or mitigation measures.

Threat Hunting Tasks

CTI teams are usually responsible for threat intelligence and threat hunting. This means they use the threat intelligence they gather to track down potential threats in their environment based on Indicators of Compromise (IOCs), malicious/suspicious behavior, and the tactics, techniques, and procedures (TTPs) used by threat actors. 

IOC-based Hunting

To identify the IOCs, we utilize our CTI database. This contains a list of domains, URLs, hashes, and IP addresses related to threat actors likely to target our organization. Each indicator includes a description, the threat campaign it is related to, the date it was added, and a link for more information. 

This additional context is used when we perform our weekly analysis of threats targeting our organization to better understand which campaigns we need to focus on (e.g., writing more detection rules or creating hunting queries).

We utilize automation to extract only the indicator values and insert them into our threat hunting queries or detection rules (depending on the technology) to determine if any IOCs are present in our environment. If they are, we investigate further.

Behaviour-based Hunting

Hunting for behavior is left up to our SIEM and EDR solutions. The detection engineering team has crafted detection rules that flag anomalous behavior, such as suspicious logon times/locations/accounts or uncommon file transfer activities. If one of these rules triggers, then we are responsible for investigating. 

TTP-based Hunting

To hunt for TTPs, the team maintains a database of Sigma rules relevant to adversaries likely to target our organization. Each rule has a description, the time it was added, and an accompanying translation into the query languages of the SIEM, EDR, and other security solutions we use. These queries are automatically or manually extracted from this database and run depending on the security solution. 

Sigma is an open standard for describing cyber security detection rules and provides a structured and standardized format for expressing detection logic. This logic can be shared between security analysts and translated into various query/rule languages used by different security products. Read How to Arm Yourself with Threat Intelligence for more information.

These queries help us detect suspicious or malicious activity that we can investigate further. To track these hunts, we maintain a database of queries we have run for each month, along with the query results and any evidence obtained during our investigations.

This database contains data such as the query’s name, the date it was run, the results found, the actions taken, and the lessons learned. The hunting database is then reviewed monthly to highlight threats that need to be focused on, queries that require refactoring to reduce false positives or runtime, and any other areas for improvement.

Daily Meeting

Once the daily tasks are complete, we have a team meeting to discuss any findings, actions to take, or any projects the team is working on to develop the program. This is typically a brief catch-up, unless something significant happens, such as a Log4j or MOVEit vulnerability, which sends everyone into panic mode. Thankfully, panic mode is saved for rare occasions, and the meeting is usually short. 


Afternoon

After completing all the daily tasks and reporting any relevant information in the daily meeting, I take the dog for a walk to get some fresh air and take lunch – typically a chicken and spinach wrap, but sometimes I splurge and have last night’s leftovers. Then, return to work to follow up on investigations from the hunts run in the morning, complete any program development tasks, and try to incorporate some personal development if possible.

Follow Up

The afternoon typically starts and is periodically interrupted with follow-up calls, emails, and investigation activities based on the morning’s threat intelligence and threat hunting. This could involve following up with a user who ran a suspicious executable, creating threat hunting queries to address a new threat, or responding to an external request from another security team for assistance in an investigation. 

These tasks tend to be sporadic, so we utilize our hunting database to track them and maintain evidence files that are shared using various Microsoft products. This allows one team member to pick up from where another left off and keep a chain of evidence during investigations.

Program Development

Aside from follow-ups, the afternoon is usually dedicated to activities that help develop our CTI program. These can generally be grouped into three categories:

  • Expansion activities: These build the maturity of the CTI program in new directions and include tasks such as adding new threat hunting queries, implementing new threat hunting methods, or researching new strategies.
  • Optimizations: This involves implementing measures that enhance the efficiency of current processes, such as building automation, refining processes, or streamlining the CTI database and TTP databases to keep them up-to-date and relevant.
  • Refinement activities: These tasks solidify the program and are the catch-up work from the expansion activities. They include building documentation, improving onboarding, or turning hunting queries into detection rules.

The team also works on long-term projects to steadily build out our CTI capabilities and further mature the program. These tend to be confidential. 

Personal Development

At the end of the day, I enjoy working on projects or certifications that help me develop my own set of cyber security and technology skills. This can range from home lab projects focusing on getting to grips with the latest open-source C2 frameworks to studying for certification exams, such as GIAC’s Reverse Engineering Malware.

I love honing my craft and learning new things every day. It is a driving factor in my success, but more importantly, it keeps me engaged with my work and provides me with a great sense of accomplishment at the end of my day. You can find my thoughts on cyber security training in Free vs Paid Cyber Security Training: The Secret to Career Success.


Conclusion

This article has been vague regarding the specific details of the technologies and processes we use due to the sensitivity of my work. However, it should give you a good idea of what my day typically looks like. Hopefully, you now have a better understanding of what a CTI analyst does and, perhaps, what you can bring to your organization.

It is essential to incorporate activities into your day beyond work. Tackle personal projects, get out for a walk on your lunch break, take regular breaks to reset and refocus, and try to finish with some personal development time to learn something new or hone your craft. Even the most interesting jobs can become routine and monotonous over time, so try to structure your day to keep it fresh and interesting.

How to Become a Threat Intelligence Analyst?

To become a threat intelligence analyst (CTI analyst), you typically need a strong foundation in IT and cyber security, often gained from a role such as a SOC analyst. You should focus on developing skills in data analysis, research, and understanding cyber threats, including frameworks like MITRE ATT&CK. Specializing in areas such as malware analysis or open-source intelligence and pursuing relevant certifications can also significantly advance your career path.

What is a Threat Intelligence Consultant?

A threat intelligence consultant is an external expert who provides organizations with specialized knowledge on cyber threats relevant to their industry and operations. They are typically engaged on a project basis to help develop or mature an in-house intelligence program, assess security posture against specific adversaries, or provide strategic guidance. This allows a company to leverage high-level expertise without the cost of a full-time, dedicated senior threat intelligence analyst.

What Makes a Senior Cyber Threat Intelligence Analyst?

A senior cyber threat intelligence analyst (CTI analyst) is distinguished by their ability to move beyond tactical reporting and provide strategic, forward-looking insights to leadership. They are expected to independently manage complex intelligence projects, mentor junior analysts, and translate technical data into business risk. This role requires a deep understanding of the threat landscape and the ability to influence security strategy across the organization.

What to Expect in a Threat Intelligence Analyst Job Description?

A threat intelligence analyst’s job description typically outlines responsibilities such as collecting and analyzing threat data from multiple sources to produce actionable intelligence reports. Expect to see required qualifications such as strong analytical and writing skills, knowledge of cyber security frameworks like MITRE ATT&CK, and experience tracking threat actor TTPs. The core focus of the role is to help the organization understand the threat landscape and make informed, proactive security decisions.

What are Common Threat Intelligence Roles and Responsibilities?

Common threat intelligence roles include the Threat Intelligence Analyst (CTI analyst), who collects and analyzes data, the Threat Hunter, who proactively searches for adversaries, and the more technical Malware Analyst. Their core responsibilities involve processing raw information into finished intelligence products, such as reports on threat actor TTPs or vulnerability warnings. Ultimately, these roles work to provide actionable, forward-looking insights that enable an organization to shift from a reactive to a proactive security posture.