CREST - Registered Threat Intelligence Analyst (CRTIA)

Duration

Duration:

Just 2 Days

Method

Method:

Classroom / Online / Hybrid

Next date

Next date:

10/2/2025 (Monday)

Overview

The accelerated Crest: Crest Registered Threat Intelligence Analyst (CRTIA) certification is aimed at individuals who are part of a team delivering threat intelligence services.  The CRTIA qualification provides assurance that an individual has reached the appropriate standard as a threat intelligence team member to deliver safe, legal and ethical services.

The (CRTIA) tests candidates’ knowledge and expertise in collecting and analysing information in support of threat intelligence objectives.

This certification will assess the candidate’s understanding of the key phases of intelligence generation, cyber specific information sources and common approaches to collection and analysis. The aim is to demonstrate a high level of competence in the collection, analysis and dissemination of intelligence to a consistently high standard and in accordance with legal and ethical guidelines.

The CRTIA qualification provides assurance that an individual has reached the appropriate standard as a threat intelligence team member to deliver safe, legal and ethical services.

At the end of this course, you’ll sit the Crest exam, and achieve your Crest Registered Threat Intelligence Analyst (CRTIA) certification. Through Firebrand’s Lecture | Lab | Review methodology, you’ll get certified at twice the speed of the traditional training and get access to courseware, learn from certified instructors, and train in a distraction-free environment.

 

 

 

Audience

This course is ideal for:

  • Individuals who are part of a team delivering threat intelligence services.

Four reasons why you should sit your course with Firebrand Training

  1. You'll be trained and certified faster. Learn more on this 2-day accelerated course. You'll get at least 12 hours a day of quality learning time in a distraction-free environment
  2. Your course is all-inclusive. One simple price covers all course materials, exams, accommodation and meals – so you can focus on learning
  3. Pass first time or train again for free. Your expert instructor will deliver our unique accelerated learning methods, allowing you to learn faster and be in the best possible position to pass first time. In the unlikely event that you don't, it's covered by your Certification Guarantee
  4. Study with an award-winning training provider. We've won the Learning and Performance Institute's "Training Company of the Year" three times. Firebrand is your fastest way to learn, with 134.561 students saving more than one million hours since 2001

Curriculum

Module 1: Key Concepts

The key concepts underlying intelligence-led cyber threat assessments.

  • Business imperative
    • Background and reasons for intelligence-led security testing
    • Understanding of the range of scenarios in which threat intelligence can be used within an organisation.
  • Terminology
    • Knowledge of common terms relating to threat intelligence, business risk and information security.
  • Threat actors & attribution
    • Knowledge of common attackers (e.g. hacktivists, criminals, nation states) and their motivation and intent. The benefits of associating activity with real people, places or organisations.
  • Attack methodology
    • Knowledge regarding phases of the cyber ‘kill chain’ methodology.
    • Knowledge of common tactics, techniques and procedures (TTPs).
    • Understanding of, and familiarity with the Mitre ATT&CK framework
    • Sequences of tool application, behavioural identification/observed behaviour.
  • Analysis methodology
    • Understanding of typical methodologies used to analyse collected intelligence and their application. Knowledge of methods for analysis of threat, e.g. the diamond model.
    • Analysis of competing hypotheses (ACH), Intelligence Preparation of the Environment / Battlefield (IPB / IPE).
    • Familiarity with concepts and terminology concerning forecasting and predictive methodologies.
  • Process and intelligence lifecycle:
    • Ability to plan and execute an intelligence-led engagement start to finish, including providing direction to junior staff and managing the client.
    • Understanding of the intelligence lifecycle (and variations of if including F3EAD) and how it relates to conducting a client engagement.
  • Principles of Intelligence
    • Understanding of the principles of intelligence and their application in Cyber Threat Intelligence context.

 

Module 2: Direction and Review

Conducting engagements that encompass the entire intelligence lifecycle, from gathering customer requirements to reviewing outcomes.

  • Requirements analysis (scoping)
    • Analysing a intelligence customer’s position to understand requirements.
    • Scoping projects to achieve key outcomes relevant to the client’s organisation.
    • Accurate timescale scoping and resource planning.
    • Establishing rules of engagement, limitations and constraints.
  • Intelligence planning
    • Prioritising intelligence requirements (e.g. MoSCoW).
    • Basic mapping of how a customer will consume and apply threat intelligence.
  • Project review
    • Conducting a review after an intelligence-led engagement, assessing the successes and failures in conjunction with the customer.

 

Module 3: Data Collection

Collection of data relevant to a customer’s intelligence requirements and turning it into a format suitable for analysis.

  • Collection planning
    • Knowledge of building a collection plan that is efficient, agile, robust and appropriate.
  • Data sources and acquisition
    • Understanding of various intelligence sources and their relevance to an engagement e.g. OSINT, HUMINT, SIGINT.
    • Knowledge of legal frameworks relevant to collecting data from technical and human sources.
  • Data reliability
    • Understanding of how to assess the relevance of intelligence sources.
    • Knowledge of factors which affect the credibility of an intelligence source and how to rate specific intelligence sources for reliability.
    • Understanding of the key differences between deception, disinformation and misinformation.
    • Understanding of how methods used in data collection can affect the availability or freshness of data.
  • Registration records
    • Knowledge of the information contained within IP and domain registries (WHOIS).
  • Domain Name Server (DNS)
    • Knowledge of DNS queries and responses, zone transfers and common record types.
    • Awareness of dynamic DNS providers and the concepts of fast-flux DNS
  • Web enumeration and social media
    • Effective use of search engines and other open source intelligence sources to gain information about a target.
    • Knowledge of information that can be retrieved from common social networking sites and how these platforms are used by threat actors.
  • Document metadata
    • Awareness of metadata contained within common document formats, such as author, application versions, machine names, printer and operating system information.
  • Dump site scraping
    • Knowledge of online services commonly used to leak stolen data and how these have been used historically to share sensitive data
  • Operational security
    • Understanding of how to securely conduct collection operations online, implementing robust procedures to protect the safety and anonymity of individuals.
    • Knowledge of how to establish identities for data collection, for example operating alias accounts for monitoring online activity.
  • Bulk data collection
    • Knowledge of how to collect data in bulk, such as from social media, Passive DNS or online feeds of malware.
    • Explain the benefits and challenges arising from collecting such data in bulk.
  • Handling human sources
    • Knowledge of interviewing techniques and tactics involved in cultivation of human sources.
    • Awareness of specific legal and reliability issues relating to human sources.

 

 

Module 4: Data Analysis

Using structured techniques and methods to address customer requirements by analysis of collected data.

  • Contextualisation
    • Understanding of the environment surrounding data and data sources, for example political, economic, social and technological contexts.
  • Analysis methodologies
    • Ability to sort and filter data.
    • Ability to use standard qualitative and quantitative analysis methodologies to process data and generate intelligence product.
    • Awareness of social network analysis and behavioural profiling techniques.
    • Awareness of threat modelling and techniques such as attack trees.
  • Machine based techniques
    • Awareness of structured and unstructured data analysis techniques.
    • Awareness of machine learning techniques, for example supervised and unsupervised learning.
  • Statistics
    • Knowledge of fundamental statistical methods used during data analysis, including averages, standard deviation, statistical distributions and techniques for data correlation, for example: • Time-series analysis • Graphing techniques • Charting techniques • Confidence levels
  • Critique
    • Critical analysis of collected data, ensuring that all potential hypotheses are explored and evaluated.
    • Ability to identify fake or conflicting data, for example misinformation.
    • Understanding of prediction and forecasting and the differences between secrets and mysteries.
    • Awareness of the importance of identifying and removing bias should this occur as an artefact of collection methods or analysis techniques.
  • Consistency
    • Ability to achieve consistency in analysis outputs and intelligence products throughout multiple engagements for a single customer or across industry sectors.

 

 Module 5: Product Dissemination

Methods for disseminating intelligence product to consumers and for sharing intelligence with trusted members of the wider intelligence community.

  • Forms of delivery
    • Understanding of effective delivery mechanisms that meet customer requirements, ranging from simple alerts to tailored reports.
    • Knowledge of why machine-readable data formats are important for efficient intelligence sharing and awareness of common vendor or community sponsored file formats.
  • Technical data sharing
    • Knowledge of what constitutes useful technical defensive intelligence, for example different types of host and network based indicators.
    • Knowledge of common formats for distributing indicators of compromise to collaboration partners and ability to interpret these.
  • Intelligence sharing initiatives
    • Knowledge of intelligence sharing initiatives and their relevance to individual clients.
  • Intelligence handling and classification
    • Knowledge of formal data classification or handling policies.
    • Understanding of why and how to establish secure mechanisms for delivery and sharing of intelligence with clients (for example the use of data encryption and strong authentication).

 

Module 6: Management

General management of operations, projects and quality.

  • Client management & communications
    • Knowledge sharing, daily checkpoints and defining escalation paths for encountered problems.
    • Knowledge and practical use of secure out-of-band communication channels.
    • Regular updates of progress to necessary stakeholders.
  • Project management
    • Ability to manage a team of threat intelligence analysts providing services to customers.
    • Knowledge of the full engagement lifecycle including scoping, authorisation, non-disclosure agreements and review. Ability to make decisions using sound judgement and critical reasoning.
  • Reporting
    • Ability to compile concise reporting with clear explanation of limitations, caveats and assumptions.
    • Ability to concisely communicate technical data and attack techniques in a coherent narrative that addresses the intelligence needs of the consumer.
    • Knowledge of methods for organising and presenting complicated links between related intelligence in a variety of graphical forms.
  • Understanding, explaining and managing risk
    • Knowledge of the additional risks that threat led engagements pose.
    • Communication and explanation of the risks relating to intelligence collection. Effective planning for potential problems during later phases of an engagement.
    • Awareness of relevant risk management standards, for example: • Risk Management ISO 31000 • Information Security ISO 27001 • Business Continuity ISO 22301 • Risk Assessment ISO 27005
  • Third Parties
    • Ability to deal with external third parties in a professional and knowledgeable manner to facilitate threat led engagements.
    • Knowledge of public organisations, Government departments and regulatory bodies relevant to specific clients and their role in overseeing industry sectors.
  • Regulator Mandated TI schemes
    • Basic understanding of the range of regulator mandated, intelligence led, penetration testing schemes, their format and requirements.

 

Module 7: Legal and Ethical

Legal and ethical considerations arising from conducting intelligence-led engagements.

  • Law & Compliance
    • Knowledge of pertinent UK legal issues: • Computer Misuse Act 1990 • Human Rights Act 1998 • Data Protection Act 1998 • Police and Justice Act 2006 • Official Secrets Act 1989 • Telecommunications (Lawful Business Practice) (Interception of Communications) 2000 • Regulation of Investigatory Powers Act 2000 • Bribery Act 2010 • Proceeds of Crime Act 2002 Awareness of relevant laws concerning employment rights, copyright and intellectual property.
    • Awareness of relevant international legislation and the complexities of working with multi-national organisations.
    • Understanding of how and when to interact with law enforcement during an engagement.
    • Knowledge of what written authority is necessary to comply with local laws.
  • Ethics
    • Awareness of the strong ethical requirements needed when providing accurate threat intelligence.
    • Understanding of the CREST Code of Conduct and the responsibilities it places on individuals and companies.

 

 

Module 8: Technical Cyber Security

Fundamental technical concepts, attack methods and countermeasures.

  • IP Protocols
    • IP protocols: IPv4 and IPv6, TCP, UDP and ICMP.
    • VPN Protocols (e.g. PPTP).
    • Awareness that other IP protocols exist.
    • Knowledge of how these protocols are used by adversaries when conducting a attacks ways in which analysis can assist in the assessment of adversary capability, sophistication and lead to attribution to a specific threat actor.
  • Cryptography
    • Fundamental understanding of cryptography, including the differences between encryption and encoding, symmetric and asymmetric encryption, common algorithms.
  • Vulnerabilities
    • Knowledge of common vulnerabilities used in the exploitation of popular desktop, web servers and mobile devices, particularly those for which robust exploit code exists in the public domain.
    • Awareness of zero-day exploits and how these are used by adversaries.
    • Ability to characterise a threat using vulnerability information and suggest mitigations for common vulnerability classes.
  • Intrusion Vectors
    • Knowledge of the different vectors by which threat actors attempt to compromise a network, for example spear phishing, strategic web compromise / watering holes / drive-by downloads.
    • Awareness of common definitions of attack patterns and related vulnerabilities (e.g. CAPEC, OWASP)
    • Awareness of advanced techniques used by some well-funded threat actors which may not be detected by common IDS platforms.
  • Command & Control and Exfiltration Techniques
    • Knowledge of common malware control mechanisms and corresponding detection techniques.
    • Knowledge of the various protocols and techniques that can be used for egressing data from a network, facilitated by malware or standard operating system / network tools.
  • Attack Attribution
    • Knowledge of techniques that can be used to hide the source of an attack, for example use of VPNs, proxy servers or Tor.
    • Understanding of difficulties associated with attribution and how technical analysis of malware and related datasets can be used to provide demonstrable links between an attack and a threat actor.
  • Current threat landscape
    • A working knowledge of some threat actors, their objectives, and associated campaigns.
    • An understanding of how the threat landscape is changing, and factors which are likely to influence future changes

Exam Track

At the end of this accelerated course, you’ll sit the following exam at the Firebrand Training centre, covered Certification Guarantee:

Crest Registered Threat Intelligence Analyst (CRTIA) exam

  • Format: A multiple-choice paper, and a selection of long form questions that require detailed written answers.
  • Passing score: Candidates are required to meet or exceed a two-thirds pass mark in the multiple choice paper.

What's Included

Your accelerated course includes:

  • Accommodation *
  • Meals, unlimited snacks, beverages, tea and coffee *
  • On-site exams **
  • Exam vouchers **
  • Practice tests **
  • Certification Guarantee ***
  • Courseware
  • Up-to 12 hours of instructor-led training each day
  • 24-hour lab access
  • Digital courseware **
  • * For residential training only. Accommodation is included from the night before the course starts. This doesn't apply for online courses.
  • ** Some exceptions apply. Please refer to the Exam Track or speak with our experts
  • *** Pass first time or train again free as many times as it takes, unlimited for 1 year. Just pay for accommodation, exams, and incidental costs.

Prerequisites

Before attending this accelerated course, you should have:

  • A minimum of two years’ experience collecting, analysing and documenting threat intelligence.

Are you ready to get certified in record time?

We interview all applicants for the course on their technical background, degrees and certifications held, and general suitability. If you get through this screening process, it means you stand a great chance of passing.

Firebrand Training is an immersive training environment. You must be committed to the course. The above prerequisites are guidelines, but many students with less experience have other background or traits that have enabled their success in accelerated training through Firebrand Training.

If you have any doubts as to whether you meet the pre-requisites please call 09 - 31 587 431 and speak to one of our enrolment consultants, who can help you with a training plan.

Reviews

We've currently trained 134.561 students in 12 years. We asked them all to review our Accelerated Learning. Currently,
94,80% have said Firebrand exceeded their expectations:

"Great to learn with a motivated and fun instructor who genuinely wants you to succeed. The training environment and those you are learning with was motivating and promoted positive engagement and interaction. In summary, an excellent course and teach method."
JC. (18/9/2023 (Monday) to 21/9/2023 (Thursday))

"Firebrand had good communication before the course began, the instructor was knowledgeable and credible, and covered many aspects of both CTI and management, in good detail."
Anonymous. (18/9/2023 (Monday) to 21/9/2023 (Thursday))

"Thanks to our instructor, I really enjoyed the course, materials was explained and taught well. He has a deep knowledge of Cyber Security and I’m looking forward to sitting my exam!"
Toju Nanna, Proact IT. (8/8/2023 (Tuesday) to 11/8/2023 (Friday))

"Instructor was patient, explained well, interactive"
RW. (1/8/2023 (Tuesday) to 4/8/2023 (Friday))

"The instructor was very knowledgeable and able to answer questions proficiently. In regards to practical application of threat intelligence, the instructor provided useful recommendations"
Anonymous (1/8/2023 (Tuesday) to 4/8/2023 (Friday))

Course Dates

Start

Finish

Status

Location

Book now

26/8/2024 (Monday)

27/8/2024 (Tuesday)

Finished - Leave feedback

-

 

 

10/2/2025 (Monday)

11/2/2025 (Tuesday)

Limited availability

Nationwide

 

24/3/2025 (Monday)

25/3/2025 (Tuesday)

Open

Nationwide

 

5/5/2025 (Monday)

6/5/2025 (Tuesday)

Open

Nationwide

 

16/6/2025 (Monday)

17/6/2025 (Tuesday)

Open

Nationwide

 

Latest Reviews from our students