Adversary Tradecraft Decoded: CTI from Zero to Hero is an immersive training program designed to bridge the gap between foundational cybersecurity knowledge and the practical, operational use of Cyber Threat Intelligence (CTI). This course provides a structured path for participants to transform raw adversary tradecraft into actionable intelligence products that support detection, response, and strategic defense.
Starting from first principles, attendees will explore the intelligence lifecycle, types of CTI, and the role of cognitive biases in analysis. The course then advances into the practical decoding of adversary Tactics, Techniques, and Procedures (TTPs), mapping them against frameworks such as MITRE ATT&CK to create consistent and reliable intelligence outputs. Participants will learn to apply open standards (STIX, TAXII, OpenIOC), enrichment methods, and structured analytic techniques to normalize and contextualize threat data.
The centerpiece of the training is a cloud-based lab environment that recreates realistic attack scenarios in a safe and controlled setting. Participants will investigate a simulated phishing and privilege escalation incident, reconstruct the cyber kill chain using the Diamond Model, extract indicators, and identify adversary behaviors. Through guided exercises, they will practice building competing hypotheses (ACH), mitigate the influence of analytical bias, and ultimately produce both technical and executive-level CTI reports.
What makes this program unique is its dynamic and in-depth approach to understanding how intelligence is truly built, not just as a theoretical exercise, but as the foundation for making future decisions about whether and how to share it. Learners are pushed to challenge their own hypotheses and identify the biases inherent in the analytic process. While they work through a known case, the procedures and steps they follow can be directly applied to generating new, useful intelligence beyond the classroom.
This hands-on, end-to-end process ensures that learners not only grasp the theory of CTI but also experience how to operationalize it in passive defense and threat hunting contexts. By simulating the work of real-world analysts, participants will leave with the ability to generate intelligence products that directly support security operations, reduce uncertainty in incident response, and inform decision-making at tactical, operational, and strategic levels.
Presented at Black Hat USA 2026