About Workshop
Structure
Day 1: Foundations of CTI & Global Threat Landscape
Objective: Establish a deep understanding of CTI concepts, types, and their role in modern hybrid warfare.-
- Introduction to Cyber Threat Intelligence (CTI) - Global role and importance in 2025 security environments - Key pillars: Proactive defense, real-time situational awareness
-
- Types of Intelligence - Strategic, Operational, Tactical, Technical — with research-based applications
-
- Threat Intelligence Lifecycle - From direction to dissemination - Integration into cyber defense ecosystems
-
- Threat Actors & Motivations - Nation-states, cybercriminals, hacktivists, insiders - Case Study: Russia–Ukraine cyber campaigns targeting infrastructure
-
- Common Attack Vectors - Phishing, ransomware, APTs, supply-chain attacks - AI-powered phishing and adversarial machine learning attacks
-
- Open-Source Intelligence (OSINT) Essentials - Tools: WHOIS, Shodan, Maltego, Google Dorks - OSINT in conflict zones and disinformation detection
- Lab Activity: Investigating a simulated threat actor via OSINT to build a preliminary intelligence profile.
Day 2: Threat Data Collection, Processing & Ethical Dimensions
Objective: Master CTI data acquisition, normalization, and ethical/legal considerations.-
- Threat Intelligence Sources - Open-source feeds, dark web forums, commercial intelligence networks - Closed intelligence-sharing partnerships (ISACs, CERTs) - Case Study: Data leaks & dark web intelligence in real-world defense operations
-
- Collection Methodologies - Passive vs. active data collection - AI-assisted automated collection pipelines (LLM-integrated scraping & classification)
-
- Processing & Normalization - Formats: STIX/TAXII, JSON, CSV - Tools: MISP, ThreatConnect, Recorded Future
-
- Ethical & Legal Considerations - Cross-border data privacy, attribution laws, human rights in CTI
- Lab Activity: Use MISP to ingest and enrich Indicators of Compromise (IOCs) from multiple feeds.
Day 3: Advanced Threat Analysis, Attribution & Global Conflict Trends
Objective: Strengthen analytical capabilities to detect, attribute, and contextualize threats in a geopolitical framework.-
- Threat Analysis Techniques - Pattern recognition, anomaly detection, behavioral analytics - AI/ML in TTPs detection and campaign correlation
-
- Tactics, Techniques, Procedures (TTPs) - MITRE ATT&CK mapping - Recognition of nation-state playbooks
-
- Malware Analysis for CTI - Static and dynamic analysis workflows - Sandboxing with Hybrid Analysis, ANY.RUN - Case Study: SolarWinds & APT29 operational footprint
-
- Threat Attribution - Linking evidence to adversaries under uncertainty - Blended threats: State-backed cybercrime
-
- Actionable Intelligence Reporting - Structuring reports for defense agencies and international partners
- Lab Activity: Analyze a malware sample from a historical cyberwar scenario and produce a detailed threat report.
Day 4: Operational Integration, AI-Enhanced CTI & Capstone Digital Warfare Simulation
Objective: Apply CTI knowledge in real-time defense simulations, integrating AI and automation.-
- Threat Intelligence Sharing - Global collaboration via STIX/TAXII, OpenIOC - Joint response strategies during active cyber conflicts
-
- Integration into Security Operations - SIEM & SOAR integration (Splunk, IBM QRadar, Cortex XSOAR) - XDR’s role in multi-environment threat detection
-
- Emerging Trends in CTI - AI-driven CTI analysis and autonomous threat hunting - AI commandos & national cyber defense units - Protecting AI models from poisoning attacks
-
- Real-Time Case Study: - How AI-driven CTI neutralized ransomware targeting global finance in 2025
-
- Capstone Simulation: - Scenario: Multi-nation cyber assault on energy & communication grids - Tasks: Collect intelligence (OSINT, dark web, closed feeds), Map TTPs to MITRE ATT&CK, Attribute attack to actors, Produce strategic & operational response plan - Outcome: A fully documented CTI response dossier
- Lab Activity: Configure SIEM to auto-ingest live feeds and generate AI-assisted alert triage.
Why This Program is Researcher-Centric
-
- Integrates real case studies from ongoing conflicts (Ukraine, Middle East, East Asia cyber tensions)
-
- Uses latest AI, ML, and automation research for threat modeling
-
- Focuses on academic and policy impact alongside operational defense
- Blends hands-on labs with scholarly insight for maximum applicability in both academia and security operations
Important Dates
Registration Ends
Workshop Dates
What You Will Gain
-
Global Relevance: Incorporates intelligence trends, emerging adversary tactics, and active threat campaigns from around the world.
-
Research-Focused: Designed with an academic-industry approach, offering scholarly insight alongside operational best practices.
-
AI-Enhanced Learning: Demonstrates how large language models, automation, and autonomous threat hunting are transforming CTI.
-
Hands-On Labs: Practical exercises with OSINT tools, malware sandboxes, SIEM/SOAR integration, and threat feed ingestion.
-
Policy and Ethics: Covers legal, ethical, and cross-border data considerations for international CTI operations.

Deliverables
-
Global Relevance: Incorporates intelligence trends, emerging adversary tactics, and active threat campaigns from around the world.
-
Research-Focused: Designed with an academic-industry approach, offering scholarly insight alongside operational best practices.
-
AI-Enhanced Learning: Demonstrates how large language models, automation, and autonomous threat hunting are transforming CTI.
-
Hands-On Labs: Practical exercises with OSINT tools, malware sandboxes, SIEM/SOAR integration, and threat feed ingestion.
-
Policy and Ethics: Covers legal, ethical, and cross-border data considerations for international CTI operations.
