Transform raw threat data into intelligence that strengthens security operations. Apply collection, profiling, forensics, threat hunting, incident response, and automation techniques.
Key Features
- Full-lifecycle coverage connects intelligence planning, collection, analysis, and feedback
- Operational examples unite threat profiling, forensics, incident response, and threat hunting
- Platform and automation guidance supports feed enrichment, integration, and scalable workflows
Book Description
Effective cyber threat intelligence starts with a disciplined understanding of what intelligence is, where it comes from, and how it supports decisions. Readers follow the intelligence lifecycle from planning through feedback and compare sources including OSINT, HUMINT, SIGINT, and material from the deep and dark web.
The central chapters turn collection into analysis. Threat actor profiling, behavioral mapping, feed integrity, poisoning, and enrichment are connected with network-centric forensics, host-based analysis, and Windows telemetry. The MITRE ATT&CK framework and practical workflows help readers convert technical evidence into clear, actionable intelligence rather than isolated indicators.
The final stage integrates intelligence with security operations. Incident response, proactive threat hunting, automation, and threat intelligence platforms are explored through practical examples and case-based guidance, with attention to feed quality and operational adoption. By the end of this journey, readers can organize collection, assess adversary behavior, interpret forensic evidence, and apply intelligence across modern defensive workflows.
What you will learn
- Explain the cyber intelligence lifecycle
- Collect intelligence from OSINT, HUMINT, and SIGINT
- Profile threat actors and map their behavior
- Analyze network and host forensic evidence
- Integrate intelligence into incident response
- Automate threat intelligence workflows
Who this book is for
Best suited to security analysts, cyber threat intelligence teams, and security operations center professionals. It supports readers who need to strengthen intelligence collection, forensic analysis, incident response, threat hunting, automation, and operational integration.