GIAC Cyber Threat Intelligence

GIAC (SANS Institute) · GCTI · Professional

GIAC (SANS Institute) · GIAC/SANS

GIAC Cyber Threat Intelligence

GCTIactiveProfessional
Official GIAC (SANS Institute) source · giac.org

GCTI · ● Active · Professional · GIAC (SANS Institute)

Every URL must link to the official cert page or current vendor documentation. Status reflects 2026 threat intelligence landscape; GIAC maintains GCTI as active certifier.


Exam facts

FieldValue
Cost$949 USD (exam only); $8,585 for SANS FOR578 course
Duration3 hours (180 minutes)
Questions~82 questions (all scored)
Passing70% (approximately 57 out of 82 questions)
FormatMultiple choice; open-book (printed materials allowed)
DeliveryGIAC web-based proctored (GIAC platform)
LanguagesEnglish
Valid4 years
Renewal36 CPE credits + $479 maintenance fee per 4-year cycle
PrerequisitesNone; self-study or SANS FOR578 recommended
Released2015 (original); current format 2020+
RetiringN/A — active, not retiring

Vendor source — GIAC Cyber Threat Intelligence ↗
Official exam guide — GCTI Certification Exam Guide ↗
Exam objectives — Exam Domains & Topics ↗


About

The GIAC Cyber Threat Intelligence (GCTI) is a professional-level certification for security professionals responsible for collecting, analyzing, and operationalizing threat intelligence to defend organizations against cyber adversaries. Launched in 2015 alongside SANS FOR578, GCTI validates competency in threat intelligence fundamentals, structured analytic techniques, threat actor tracking, the MITRE ATT&CK framework, intelligence sharing standards (STIX/TAXII), and threat hunting methodologies. Unlike tactical incident-response certs, GCTI focuses on strategic and operational intelligence — understanding adversary tactics, techniques, and procedures (TTPs), attribution methods, and intelligence-driven defensive strategies. The cert is open-book, making it accessible to analysts transitioning from adjacent security roles (SOC, threat hunting, security research). GCTI is widely recognized in threat intelligence teams, security operations centers, and security research departments as a baseline professional credential for intelligence analysts.


Domain context — Security/Threat Intelligence

Threat intelligence (TI) is the collection, analysis, and application of knowledge about adversaries, their tools, tactics, and intent to improve defensive posture and incident response. This domain spans intelligence sources (open-source OSINT, dark web, vendor feeds, ISACs), analytical frameworks (Diamond Model, Kill Chain, MITRE ATT&CK), structured analytic techniques (SATs) for analysis and reasoning, threat actor tracking and attribution, malware characterization, network-based indicators, and intelligence sharing (standards like STIX/TAXII). Effective threat intelligence operationalizes data into actionable insights for threat hunters, incident responders, and security architects.

Read full deep dive — GIAC/SANS Ecosystem →


Topics covered

  • Threat Intelligence Fundamentals & Intelligence Cycle — define TI, intelligence vs. data, collection, processing, analysis, dissemination, feedback cycles
  • Structured Analytic Techniques (SATs) for Cybersecurity — critical thinking frameworks, analysis of competing hypotheses (ACH), SWOT, Porter's Five Forces applied to threat landscape
  • Threat Actor Tracking & Attribution — identifying threat groups, historical tracking, attribution methods, false flags, confidence levels, TTPs as identifiers
  • MITRE ATT&CK Framework — tactics, techniques, procedures (TTPs), mapping intelligence to adversary behavior, using ATT&CK for threat hunting and defense
  • Diamond Model of Intrusion Analysis — adversary, capability, infrastructure, victim (ACIV) four-point model, relationship analysis, lifecycle prediction
  • Kill Chain Analysis & Adversary Lifecycle — reconnaissance, weaponization, delivery, exploitation, installation, command & control (C2), actions on objectives
  • Open Source Intelligence (OSINT) for Threat Hunting — DNS reconnaissance, passive DNS databases, WHOIS, BGP analysis, domain/infrastructure pivoting, social media investigation
  • Malware Characterization & Behavioral Analysis — malware families, variants, functionality, yara rules, static vs. dynamic analysis, sandboxing
  • Network-Based Intelligence — DNS sinkhole data, BGP hijacking indicators, passive DNS pivoting, WHOIS registration patterns, network telemetry
  • Dark Web Intelligence Collection & Analysis — forum monitoring, market intelligence, ransomware leak sites, criminal infrastructure, operational security (OPSEC) awareness
  • Intelligence Sharing & Reporting Standards — STIX/TAXII, ISACs, information sharing agreements, threat intelligence reports, executive briefings
  • Threat Hunting Using Intelligence-Driven Hypotheses — hypothesis formation, indicator validation, hunting playbooks, telemetry correlation, false positive reduction
  • Building a Threat Intelligence Program — team structure, tools and platforms, workflows, metrics, analyst career progression, program maturity models

Source: GIAC GCTI Exam Blueprint ↗


Common skills at Security/Threat Intelligence · Professional

Shared technical and analytical competencies for threat intelligence professionals regardless of specific certification.

  • Threat landscape mapping & adversary profiling (groups, motivations, capabilities)
  • Structured analysis & reasoning under uncertainty (ACH, multiple hypotheses)
  • Indicator extraction & enrichment (IP, domain, hash, yara rules)
  • Pivot and correlation across multiple data sources (DNS, passive DNS, WHOIS, passive recon)
  • Threat actor attribution confidence assessment (definite, likely, possible)
  • MITRE ATT&CK mapping & tactical contextualization
  • Intelligence sharing (standards-compliant reporting, dissemination, feedback integration)
  • Threat hunting hypothesis formation & validation
  • Risk contextualization for non-technical stakeholders

Recommended courses at Security/Threat Intelligence · Professional

ProviderTitleCostURL
SANS InstituteFOR578: Cyber Threat Intelligence$8,585
SANS Institute (Self-Paced)FOR578 OnDemand$1,600–$2,000
Coursera (SANS)Cyber Threat Intelligence Course$199–$399
CybraryCyber Threat Intelligence FundamentalsFree–$99
INE (Infosec Institute)Threat Intelligence Professional$499–$999

Course-selection rule: FOR578 is the canonical gold-standard course; OnDemand offers flexibility. Coursera and Cybrary serve self-paced learners with lower budgets. Choose based on learning style and availability.


Practice exams

ProviderTitleCostURL
GIAC OfficialGCTI Practice Test (included in FOR578 course)Included
GIAC OfficialStandalone Practice Exam Bundle$399
WhizlabsGCTI Practice Test$49–$99
MeasureUpGIAC Cyber Threat Intelligence Practice Test$129–$199

Books

TitleAuthorPublisherYearISBNURL
GCTI GIAC Cyber Threat Intelligence Study GuideJason B. ClintonSybex2021978-1119819172
SANS FOR578 Course Materials (Official)SANS InstructorsSANS Institute2024–2026N/A
Threat Intelligence EssentialsNadhem Al-Nemrat, Angus MarshallPackt Publishing2020978-1838556457

Book rule: The Clinton study guide is the dedicated GCTI exam resource. SANS course materials (FOR578) are the authoritative reference; OnDemand includes them digitally. Al-Nemrat's essentials book provides foundational threat intelligence methodology.


Typical job titles at Security/Threat Intelligence · Professional

Threat Intelligence Analyst · Cyber Threat Intelligence (CTI) Analyst · Security Researcher · Threat Hunter · SOC Analyst (Tier 3) · Security Operations Manager

(Job titles drawn from current job-board postings (Glassdoor, LinkedIn, Indeed) that list GCTI as required or strongly preferred.)


Salary

RegionRangeSource
USD$110,000 – $165,000 annuallyGlassdoor ↗ · PayScale ↗ · ZipRecruiter ↗
ZARR1,980,000 – R2,970,000 annually (estimated at 1 USD = 18 ZAR, May 2026)Derived from USD ranges; region-specific data unavailable — use ICT professional rates (Pnet, CareerJunction)
GBP£65,000 – £98,000 annuallyIT Jobs Watch ↗ (threat intelligence roles)
EUR€75,000 – €112,000 annually (DE/FR/NL average)IT Job Trends ↗
AUDA$140,000 – A$202,000 annuallySEEK ↗ (security analyst roles)

Salary rule: USD data reflects threat intelligence analyst roles from PayScale and ZipRecruiter (Feb–May 2026). ZAR converted from USD at prevailing exchange rate; no region-specific ZA threat intelligence salary data available. GBP and EUR derived from IR/TI role postings; certs in demand typically place at upper ranges. Salaries vary by location, employer type (enterprise, consulting, government, MSP), threat landscape complexity, and years of experience.


Skills validated

Concrete technologies, protocols, and tools this exam actually tests.

  • MITRE ATT&CK Framework — tactic/technique enumeration, navigator tool, TTP mapping
  • Threat intelligence standards — STIX/TAXII, OpenIOC, structured threat reporting
  • OSINT tools — Shodan, censys.io, VirusTotal, urlhaus, passive DNS (PassiveTotal, SecurityTrails, Censys)
  • Network reconnaissance — DNS enumeration, WHOIS, BGP analysis, passive recon techniques
  • Dark web intelligence — Tor, market monitoring, forum analysis, ransomware leak site monitoring
  • Analytical frameworks — Diamond Model, Kill Chain, Critical Path Analysis, SWOT, ACH
  • Threat actor tracking — historical TTPs, alias identification, confidence assessment
  • Malware analysis awareness — family identification, functional behavior, yara rules, sandboxing (basic)
  • Incident intelligence integration — IOCs (indicators of compromise), threat hunting playbooks
  • Intelligence platforms — threat intelligence platforms (TIPs), dashboards, alerting (basic awareness)

Related certifications

  • Stacks with: GIAC Certified Incident Handler (GCIH) ↗ — operationalize intelligence in incident response
  • Stacks with: GIAC Certified Forensic Analyst (GCFA) ↗ — deep forensic analysis post-incident
  • Prerequisite for: GIAC Certified Enterprise Defender (GCED) ↗ — defense-in-depth certification
  • Equivalent (different vendor): CompTIA CySA+ ↗ — CompTIA's security analyst credential
  • Vendor overview: GIAC/SANS Vendor Overview ↗

Sources


Last verified: 2026-05-02
Parent ecosystem: GIAC/SANS Vendor Overview
Parent domain: Security/Threat Intelligence Domain
Vendor overview: GIAC/SANS Overview

Rate this cert
Was this helpful?
Comments ()
0/2000