CATALOGUECOURSESGIAC Cyber Threat Intelligence (GCTI)
    Converged Security Certification
    [ converged ]

    "The GIAC Cyber Threat Intelligence, or GCTI, certification is a highly respected credential focused on strategic adversary profiling, campaign attribution, and intelligence cycle management. It trains security professionals to utilize structured analytical techniques and frameworks, such as MITRE ATT&CK and the Diamond Model, to anticipate and mitigate advanced persistent threats. By mastering open-source intelligence collection and tactical telemetry analysis, credential holders are uniquely positioned to transform raw data into actionable defense strategies."

    The GIAC Cyber Threat Intelligence (GCTI) certification is a premier professional-level credential designed for security practitioners who specialize in the collection, analysis, and dissemination of actionable threat intelligence. This rigorous program equips professionals with the analytical methodologies required to profile sophisticated threat actors, attribute malicious campaigns, and map adversary behaviors to standardized frameworks such as MITRE ATT&CK, the Cyber Kill Chain, and the Diamond Model of Intrusion Analysis. By mastering structured analytical techniques, OSINT data collection, and intelligence cycle management, candidates learn to transition from reactive incident response to proactive, intelligence-driven defense. The curriculum is tailored for CTI analysts, security operations center (SOC) personnel, and incident responders seeking to elevate their strategic, operational, and tactical intelligence capabilities.

    [01] Verify Your Readiness

    Deploy into hands-on sandbox simulations mapped directly to GIAC Cyber Threat Intelligence (GCTI) objectives. Verify your readiness under real-world conditions:

    Verification Available

    VECTOR-LOCK: Trading Floor Compromise

    ID: SECM-8402Deploy
    Verification Available

    Operation Helix-Chain: Ransomware Triage

    ID: SECM-4205Deploy
    Verification Available

    Active Threat Hunt: SPECTER-STORM

    ID: SECM-4633Deploy

    [ EDITORIAL_INDEPENDENCE_NOTICE ]

    SecNav is not a commercial partner for this course. We do not receive compensation, referral commissions, or affiliate fees from SANS/GIAC for indexing this credential. We map this path purely for its educational merit and alignment with career progression.

    PROVIDER_INTEL

    [02] Skills Validated by This Certification

    The GIAC Cyber Threat Intelligence (GCTI) curriculum tests and measures critical capabilities across these essential converged cyber-physical security operations skills. Explore the dedicated skills nodes below:

    [03] Career Pathways & Target Roles

    Securing a verified status in GIAC Cyber Threat Intelligence (GCTI) is a high-value accelerator for major converged risk management career paths. Learn more about the primary roles mapping to this pathway:

    No linked career roles in telemetry

    [04] Frequently Asked Questions about GIAC Cyber Threat Intelligence (GCTI)

    Yes, absolutely! You can verify your real-world readiness by launching the following active-threat sandbox simulations on our platform: VECTOR-LOCK: Trading Floor Compromise, Operation Helix-Chain: Ransomware Triage, Active Threat Hunt: SPECTER-STORM. Completing these sandboxes grants cryptographically signed proof and reward XP.
    The GCTI certification heavily emphasizes the use of structured analytical techniques and established intrusion analysis models, including the Cyber Kill Chain, the Diamond Model of Intrusion Analysis, and the MITRE ATT&CK framework, to systematically track and attribute adversary behaviors.
    By training analysts in Intelligence Cycle Management, the GCTI ensures that security teams can properly plan, collect, and analyze threat data. This allows organizations to anticipate adversary campaigns, create targeted Detection-as-Code rules, and implement defensive measures before a breach occurs.
    The ideal candidates are current Cyber Threat Intelligence (CTI) analysts, SOC analysts, incident responders, and digital forensics professionals who wish to enhance their ability to analyze malware campaigns, conduct OSINT investigations, and provide strategic threat briefings to executive leadership.

    [05] Authoritative Sources & Certification References

    Certifying Body & Official Resources

    NIST Special Publication ReferenceNIST SP 800-150: Guide to Cyber Threat Information Sharing
    Official Link
    Industry Best Practices ReferenceMITRE ATT&CK Framework
    Official Link