Companion-course connectionThreat Intelligence Requirements
Threat intelligence requirements translate stakeholder decisions and uncertainties into specific questions that collection and analysis can answer.
Open article →Companion-course connectionDiamond Model of Intrusion Analysis
The Diamond Model examines relationships among adversary, capability, infrastructure, and victim while adding context such as time, direction, and confidence.
Open article →Companion-course connectionMalware Intelligence
Malware intelligence converts static features, runtime behavior, configuration, infrastructure, and family relationships into information defenders can use.
Open article →Companion-course connectionPassive DNS Analysis
Passive DNS analysis uses historical domain-to-address observations to examine infrastructure changes, relationships, reuse, and timing without directly querying adversary systems.
Open article →Companion-course connectionExecutive Incident Briefings
Executive incident briefings summarize current impact, confidence, decisions, risks, resource needs, and next milestones without overwhelming leaders with raw technical detail.
Open article →Companion-course connectionIntelligence Handling Caveats
Intelligence handling caveats communicate restrictions, sensitivities, source protections, legal limits, and conditions that apply in addition to general sharing labels.
Open article →Companion-course connectionAI Audit Evidence Integrity
AI audit evidence integrity is the ability to show that logs, model artifacts, data extracts, test results, approvals, and screenshots are authentic, complete, attributable, and unchanged.
Open article →Companion-course connectionData Dictionaries and Metadata
Data dictionaries and metadata describe fields, formats, meanings, allowed values, ownership, sensitivity, and relationships so data can be interpreted consistently.
Open article →Companion-course connectionDetection Tuning Feedback Loops
Detection tuning feedback loops use analyst dispositions, missed detections, environmental change, testing, and workload evidence to improve analytic precision without erasing useful coverage.
Open article →Companion-course connectionDetection Use-Case Acceptance Criteria
Detection use-case acceptance criteria define the threat behavior, data, logic, context, expected alert, performance, ownership, response path, and evidence required before a detection is treated as operational.
Open article →Companion-course connectionExecutive Security Reporting
Executive security reporting gives decision makers a concise view of material exposure, control performance, incidents, obligations, trends, and choices requiring action.
Open article →Companion-course connectionIntelligence-Led Threat Hunting
Intelligence-led threat hunting converts validated adversary knowledge into hypotheses, data requirements, analytic methods, and searches for activity that existing detections may miss.
Open article →