GCTI · ● Active · Professional · GIAC (SANS Institute)
Every URL must link to the official cert page or current vendor documentation. Status reflects 2026 threat intelligence landscape; GIAC maintains GCTI as active certifier.
Exam facts
| Field | Value |
|---|---|
| Cost | $949 USD (exam only); $8,585 for SANS FOR578 course |
| Duration | 3 hours (180 minutes) |
| Questions | ~82 questions (all scored) |
| Passing | 70% (approximately 57 out of 82 questions) |
| Format | Multiple choice; open-book (printed materials allowed) |
| Delivery | GIAC web-based proctored (GIAC platform) |
| Languages | English |
| Valid | 4 years |
| Renewal | 36 CPE credits + $479 maintenance fee per 4-year cycle |
| Prerequisites | None; self-study or SANS FOR578 recommended |
| Released | 2015 (original); current format 2020+ |
| Retiring | N/A — active, not retiring |
Vendor source — GIAC Cyber Threat Intelligence ↗
Official exam guide — GCTI Certification Exam Guide ↗
Exam objectives — Exam Domains & Topics ↗
About
The GIAC Cyber Threat Intelligence (GCTI) is a professional-level certification for security professionals responsible for collecting, analyzing, and operationalizing threat intelligence to defend organizations against cyber adversaries. Launched in 2015 alongside SANS FOR578, GCTI validates competency in threat intelligence fundamentals, structured analytic techniques, threat actor tracking, the MITRE ATT&CK framework, intelligence sharing standards (STIX/TAXII), and threat hunting methodologies. Unlike tactical incident-response certs, GCTI focuses on strategic and operational intelligence — understanding adversary tactics, techniques, and procedures (TTPs), attribution methods, and intelligence-driven defensive strategies. The cert is open-book, making it accessible to analysts transitioning from adjacent security roles (SOC, threat hunting, security research). GCTI is widely recognized in threat intelligence teams, security operations centers, and security research departments as a baseline professional credential for intelligence analysts.
Domain context — Security/Threat Intelligence
Threat intelligence (TI) is the collection, analysis, and application of knowledge about adversaries, their tools, tactics, and intent to improve defensive posture and incident response. This domain spans intelligence sources (open-source OSINT, dark web, vendor feeds, ISACs), analytical frameworks (Diamond Model, Kill Chain, MITRE ATT&CK), structured analytic techniques (SATs) for analysis and reasoning, threat actor tracking and attribution, malware characterization, network-based indicators, and intelligence sharing (standards like STIX/TAXII). Effective threat intelligence operationalizes data into actionable insights for threat hunters, incident responders, and security architects.
Read full deep dive — GIAC/SANS Ecosystem →
Topics covered
- Threat Intelligence Fundamentals & Intelligence Cycle — define TI, intelligence vs. data, collection, processing, analysis, dissemination, feedback cycles
- Structured Analytic Techniques (SATs) for Cybersecurity — critical thinking frameworks, analysis of competing hypotheses (ACH), SWOT, Porter's Five Forces applied to threat landscape
- Threat Actor Tracking & Attribution — identifying threat groups, historical tracking, attribution methods, false flags, confidence levels, TTPs as identifiers
- MITRE ATT&CK Framework — tactics, techniques, procedures (TTPs), mapping intelligence to adversary behavior, using ATT&CK for threat hunting and defense
- Diamond Model of Intrusion Analysis — adversary, capability, infrastructure, victim (ACIV) four-point model, relationship analysis, lifecycle prediction
- Kill Chain Analysis & Adversary Lifecycle — reconnaissance, weaponization, delivery, exploitation, installation, command & control (C2), actions on objectives
- Open Source Intelligence (OSINT) for Threat Hunting — DNS reconnaissance, passive DNS databases, WHOIS, BGP analysis, domain/infrastructure pivoting, social media investigation
- Malware Characterization & Behavioral Analysis — malware families, variants, functionality, yara rules, static vs. dynamic analysis, sandboxing
- Network-Based Intelligence — DNS sinkhole data, BGP hijacking indicators, passive DNS pivoting, WHOIS registration patterns, network telemetry
- Dark Web Intelligence Collection & Analysis — forum monitoring, market intelligence, ransomware leak sites, criminal infrastructure, operational security (OPSEC) awareness
- Intelligence Sharing & Reporting Standards — STIX/TAXII, ISACs, information sharing agreements, threat intelligence reports, executive briefings
- Threat Hunting Using Intelligence-Driven Hypotheses — hypothesis formation, indicator validation, hunting playbooks, telemetry correlation, false positive reduction
- Building a Threat Intelligence Program — team structure, tools and platforms, workflows, metrics, analyst career progression, program maturity models
Source: GIAC GCTI Exam Blueprint ↗
Common skills at Security/Threat Intelligence · Professional
Shared technical and analytical competencies for threat intelligence professionals regardless of specific certification.
- Threat landscape mapping & adversary profiling (groups, motivations, capabilities)
- Structured analysis & reasoning under uncertainty (ACH, multiple hypotheses)
- Indicator extraction & enrichment (IP, domain, hash, yara rules)
- Pivot and correlation across multiple data sources (DNS, passive DNS, WHOIS, passive recon)
- Threat actor attribution confidence assessment (definite, likely, possible)
- MITRE ATT&CK mapping & tactical contextualization
- Intelligence sharing (standards-compliant reporting, dissemination, feedback integration)
- Threat hunting hypothesis formation & validation
- Risk contextualization for non-technical stakeholders
Recommended courses at Security/Threat Intelligence · Professional
| Provider | Title | Cost | URL |
|---|---|---|---|
| SANS Institute | FOR578: Cyber Threat Intelligence | $8,585 | ↗ |
| SANS Institute (Self-Paced) | FOR578 OnDemand | $1,600–$2,000 | ↗ |
| Coursera (SANS) | Cyber Threat Intelligence Course | $199–$399 | ↗ |
| Cybrary | Cyber Threat Intelligence Fundamentals | Free–$99 | ↗ |
| INE (Infosec Institute) | Threat Intelligence Professional | $499–$999 | ↗ |
Course-selection rule: FOR578 is the canonical gold-standard course; OnDemand offers flexibility. Coursera and Cybrary serve self-paced learners with lower budgets. Choose based on learning style and availability.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| GIAC Official | GCTI Practice Test (included in FOR578 course) | Included | ↗ |
| GIAC Official | Standalone Practice Exam Bundle | $399 | ↗ |
| Whizlabs | GCTI Practice Test | $49–$99 | ↗ |
| MeasureUp | GIAC Cyber Threat Intelligence Practice Test | $129–$199 | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| GCTI GIAC Cyber Threat Intelligence Study Guide | Jason B. Clinton | Sybex | 2021 | 978-1119819172 | ↗ |
| SANS FOR578 Course Materials (Official) | SANS Instructors | SANS Institute | 2024–2026 | N/A | ↗ |
| Threat Intelligence Essentials | Nadhem Al-Nemrat, Angus Marshall | Packt Publishing | 2020 | 978-1838556457 | ↗ |
Book rule: The Clinton study guide is the dedicated GCTI exam resource. SANS course materials (FOR578) are the authoritative reference; OnDemand includes them digitally. Al-Nemrat's essentials book provides foundational threat intelligence methodology.
Typical job titles at Security/Threat Intelligence · Professional
Threat Intelligence Analyst · Cyber Threat Intelligence (CTI) Analyst · Security Researcher · Threat Hunter · SOC Analyst (Tier 3) · Security Operations Manager
(Job titles drawn from current job-board postings (Glassdoor, LinkedIn, Indeed) that list GCTI as required or strongly preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $110,000 – $165,000 annually | Glassdoor ↗ · PayScale ↗ · ZipRecruiter ↗ |
| ZAR | R1,980,000 – R2,970,000 annually (estimated at 1 USD = 18 ZAR, May 2026) | Derived from USD ranges; region-specific data unavailable — use ICT professional rates (Pnet, CareerJunction) |
| GBP | £65,000 – £98,000 annually | IT Jobs Watch ↗ (threat intelligence roles) |
| EUR | €75,000 – €112,000 annually (DE/FR/NL average) | IT Job Trends ↗ |
| AUD | A$140,000 – A$202,000 annually | SEEK ↗ (security analyst roles) |
Salary rule: USD data reflects threat intelligence analyst roles from PayScale and ZipRecruiter (Feb–May 2026). ZAR converted from USD at prevailing exchange rate; no region-specific ZA threat intelligence salary data available. GBP and EUR derived from IR/TI role postings; certs in demand typically place at upper ranges. Salaries vary by location, employer type (enterprise, consulting, government, MSP), threat landscape complexity, and years of experience.
Skills validated
Concrete technologies, protocols, and tools this exam actually tests.
- MITRE ATT&CK Framework — tactic/technique enumeration, navigator tool, TTP mapping
- Threat intelligence standards — STIX/TAXII, OpenIOC, structured threat reporting
- OSINT tools — Shodan, censys.io, VirusTotal, urlhaus, passive DNS (PassiveTotal, SecurityTrails, Censys)
- Network reconnaissance — DNS enumeration, WHOIS, BGP analysis, passive recon techniques
- Dark web intelligence — Tor, market monitoring, forum analysis, ransomware leak site monitoring
- Analytical frameworks — Diamond Model, Kill Chain, Critical Path Analysis, SWOT, ACH
- Threat actor tracking — historical TTPs, alias identification, confidence assessment
- Malware analysis awareness — family identification, functional behavior, yara rules, sandboxing (basic)
- Incident intelligence integration — IOCs (indicators of compromise), threat hunting playbooks
- Intelligence platforms — threat intelligence platforms (TIPs), dashboards, alerting (basic awareness)
Related certifications
- Stacks with: GIAC Certified Incident Handler (GCIH) ↗ — operationalize intelligence in incident response
- Stacks with: GIAC Certified Forensic Analyst (GCFA) ↗ — deep forensic analysis post-incident
- Prerequisite for: GIAC Certified Enterprise Defender (GCED) ↗ — defense-in-depth certification
- Equivalent (different vendor): CompTIA CySA+ ↗ — CompTIA's security analyst credential
- Vendor overview: GIAC/SANS Vendor Overview ↗
Sources
- GIAC Cyber Threat Intelligence (GCTI): https://www.giac.org/certifications/cyber-threat-intelligence-gcti
- SANS FOR578 Course: https://www.sans.org/cyber-security-courses/cyber-threat-intelligence
- GIAC Pricing: https://www.giac.org/pricing
- PayScale Threat Intelligence Analyst: https://www.payscale.com/research/US/Job=Threat_Intelligence_Analyst/Salary
- ZipRecruiter CTI Analyst: https://www.ziprecruiter.com/Salaries/Threat-Intelligence-Analyst-Salary
- Cybersecurity Ventures CTI Report: https://www.cybersecurityventures.com
Last verified: 2026-05-02
Parent ecosystem: GIAC/SANS Vendor Overview
Parent domain: Security/Threat Intelligence Domain
Vendor overview: GIAC/SANS Overview