The Job Posting Wants Three Years of Experience for an Entry-Level Role, and You Have None
This is the wall most people hit trying to get into CTI. The "junior analyst" listing asks for prior intelligence experience, three named tools, a framework or two, and often a certification that costs more than a used car. You read it, you don't tick the boxes, you close the tab. The gap between "interested in threat intelligence" and "employable in threat intelligence" feels like it has no bridge.
It does, but almost nobody describes the bridge honestly. The career advice in this space splits into two useless piles. One pile tells you to buy an $8,000 course and you'll be fine. The other hands you a list of forty free resources with no order, no priorities, and no sense of what a hiring manager actually looks at. Neither tells you the real thing: CTI is a skill you demonstrate, not a credential you purchase, and the fastest way in is to produce work that looks like the work the job requires before anyone hires you to do it.
What follows is the roadmap I'd give someone starting from zero today. It assumes no security background, no budget for a $9,000 bootcamp, and a willingness to do actual work rather than collect certificates. It's opinionated on purpose, because an honest roadmap has to be.
Track Threat Intelligence like this every Monday.
Every Monday, the 5 threats SOC teams can't afford to miss — with analyst commentary.
What a CTI Analyst Actually Does (and How It Differs from a SOC Role)
Before you spend a single hour studying, understand what you're training for, because a lot of people confuse CTI with adjacent roles and end up preparing for the wrong job.
A SOC analyst responds to what's happening on their own network right now. Alerts fire, they triage, they investigate, they escalate or close. The time horizon is immediate and the scope is internal. A CTI analyst works one level up and one step ahead: understanding adversaries as actors, their tools, their techniques, their intentions, and translating that understanding into something defenders can act on before an attack lands. The SOC asks "what is this alert." CTI asks "who does this, how do they operate, what will they do next, and what does our organization need to know about it."
In practice, the CTI job is a cycle. You collect raw information from technical sources, open sources, human sources, and dark web monitoring. You analyze it: correlating indicators, mapping behavior to frameworks like MITRE ATT&CK, assessing confidence, separating what you know from what you infer. Then you produce intelligence: reports, briefings, detection content, attribution assessments, written for an audience that ranges from SOC analysts who need IOCs to executives who need risk framing. The writing matters more than newcomers expect. An analyst who can run down a threat actor but can't communicate the finding clearly is half an analyst.
This is why the roadmap isn't just "learn tools." The craft is collection, analysis, and communication, and each needs deliberate practice.
The Skill Stack You Actually Need
Job postings list tools, but tools are the surface. Underneath, the skills that make you hireable fall into a stack, and you build it roughly bottom to top.

Foundational security literacy comes first. You cannot analyze threats you don't understand structurally. That means knowing how networks work, what the common protocols do, how authentication and identity function, how Windows and Linux actually operate, and what the major attack categories look like. If you're coming from zero, this is the unglamorous groundwork, and skipping it is the single most common reason people stall later. You don't need to be a network engineer, but "what is DNS and how is it abused" should be a question you can answer cold.
OSINT is the first CTI-specific skill, and it's deeper than people assume. Open-source intelligence is not Google dorking. It's infrastructure mapping, pivoting across indicators (a domain to its registration to its hosting to its certificate to the other domains that share it), social media and persona analysis, and knowing which data sources to trust for what. A good OSINT analyst can start with a single IOC and build out a picture of an operation. This is learnable and it's where a lot of real CTI work actually lives.
Threat hunting and malware analysis fundamentals sit above that. You don't need to reverse-engineer packed malware on day one, but you need to understand infection chains, read a sandbox report critically, recognize common TTPs, and know enough static and dynamic analysis to triage a sample and extract what matters. Threat hunting teaches you to form a hypothesis about adversary behavior and go looking for it in data rather than waiting for an alert, which is the mindset CTI runs on.
Framework fluency and analytic tradecraft tie the stack together. MITRE ATT&CK is the common language; you need to think in it, not just reference it. Beyond that sits the actual intelligence discipline: the intelligence lifecycle, structured analytic techniques, confidence assessment, and attribution logic. This is the part generic cybersecurity training skips entirely, and it's what separates a threat researcher from an intelligence analyst. The analyst who writes "we assess with moderate confidence that X, based on Y and Z, while noting the alternative hypothesis of W" is doing the job. The one who writes "it was definitely APT28" because the malware matched is not.
The Honest Truth About CTI Certifications
Certifications are where most of the money and most of the confusion live, so here's the straight version with current prices from the providers' own pages.
The SANS FOR578 course paired with the GIAC GCTI exam is the recognized gold standard, and it's priced accordingly. As of late September 2026, FOR578 was listed around $8,780 in the US, with a standalone GCTI exam attempt at $999. It's genuinely excellent training and the GCTI is more rigorous than most, with hands-on tooling tasks rather than pure multiple choice. It's also an advanced credential built for people with years of operational experience, and the price makes it something you take when an employer is paying, not something you self-fund on the way in.
The EC-Council CTIA sits a tier down in both price and depth. It bundles with training from roughly $1,069 on EC-Council's own store, covers the full intelligence lifecycle more broadly but less deeply, and includes scripting and threat hunting in the syllabus. It's positioned as a mid-career specialization cert, better suited to someone with a couple of years of security experience bridging into intel than to a true beginner. CREST's threat intelligence track (CPTIA at the practitioner level, CRTIA above it) is respected particularly in UK and European markets, with CRTIA expecting around two years of CTI experience. Mandiant's MCTIA exam is cheap by comparison at $250 per attempt and carries real brand weight given the source.
Here's the opinion the cert-selling sites won't give you: for someone starting from zero, none of these should be your first move. A certificate proves you passed an exam. It does not prove you can do the work, and increasingly, hiring managers in this field know the difference. Spend your early effort on demonstrable skill and a portfolio, and reach for a certification when you have the experience to pass the good ones and, ideally, an employer to fund them. The exception is if a specific job you want explicitly gates on a named cert, in which case get that one and only that one.
| Credential | Body | Cost (training + exam) | Best for |
|---|---|---|---|
| GCTI (FOR578) | SANS/GIAC | ~$8,780 + $999 exam | Experienced analysts, employer-funded |
| CTIA v2 | EC-Council | from ~$1,069 | Mid-career, bridging into CTI |
| CPTIA / CRTIA | CREST | Varies by country | UK/EU market, 2+ yrs experience |
| MCTIA | Mandiant | $250/attempt | Brand signal, budget-conscious |
Build the Portfolio Before Anyone Asks for It
This is the part that actually gets people hired, and it's the part most roadmaps bury. CTI is a demonstrable craft. You can do the work in public, for free, before you have a job, and that body of work is worth more than any line on a résumé.
The move is simple to describe and hard to sustain: produce analysis and publish it. Pick a threat actor, a malware family, a campaign, or a technique, research it properly, and write it up the way a working analyst would. Map it to ATT&CK. Pull the IOCs. Assess the tradecraft. State your confidence and your reasoning. Do this repeatedly and you accumulate proof that you can collect, analyze, and communicate, which is the entire job. A hiring manager who sees five solid writeups on your blog has seen more evidence of your ability than a certificate could ever provide.
Pair the writing with hands-on practice so the analysis has teeth. Stand up a home lab. Pull real malware samples from a service like MalwareBazaar and detonate them safely in a sandbox. Run MISP or OpenCTI yourself so you understand how intelligence platforms actually work rather than just naming them in an interview. Practice pivoting on infrastructure with the free tiers of the tools analysts use. The point isn't to master everything; it's to have genuinely touched the workflows so that when you write "I analyzed this sample," it's true.
Then put yourself where the field is. The CTI community is small and reachable. Following and engaging with working analysts, contributing to open discussions, and sharing your own work is how you learn what's current and how you become known. A surprising number of first roles come through visibility and relationships rather than cold applications, precisely because the people hiring would rather bring on someone whose work they've already seen.
Where to Actually Learn and Practice
The resource landscape is cluttered, so here's a prioritized, honest map rather than a dump of forty links. These serve different purposes, and the right order depends on where you're starting.
For foundational security knowledge, the hands-on learning platforms are the efficient path. TryHackMe and Hack The Box teach the underlying security literacy through guided, practical exercises, and both have substantial free content. Work through the fundamentals there before worrying about anything CTI-specific, because the groundwork makes everything above it faster.
For the CTI-specific skill stack, you want material built around real workflows rather than theory you'll never apply. This is a genuine gap in the market: most beginner cybersecurity training is broad and shallow, and most CTI-specific training assumes you're already a practitioner. A few focused platforms have grown up to fill the middle. CTI Academy (ctiacademy.io), for instance, is a practitioner-built platform structured for people starting from zero, with guided learning paths from foundational concepts up through advanced levels, and a set of working simulators (SOC operations, phishing analysis, attack investigation, and an OSINT lab built on synthetic breach data) where you make real calls instead of answering quiz questions about them. Its entry level is free, which makes it a low-risk place to find out whether the actual work appeals to you before committing money anywhere. Whatever platform you choose, the test is the same: does it make you do the work, or does it just describe it? Favor the ones with hands-on labs and real tooling over the ones that are glorified slideshows.
For free, high-quality reading that doubles as a model for your own writing, go straight to the primary sources. The threat research blogs from vendors and teams like Mandiant, Cisco Talos, Unit 42, Recorded Future, and CERT-UA publish the kind of analysis you're learning to produce. Read them not just for the findings but for the structure: how they map behavior, how they hedge attribution, how they present evidence. Reverse-engineering good intelligence writing is one of the cheapest and most effective ways to learn the craft.
For frameworks and reference, MITRE ATT&CK itself is free and should become something you navigate fluently. Pair it with the free tiers of intelligence platforms (OpenCTI and MISP are both open source and self-hostable) so you learn the tooling by running it, not reading about it.
The Order That Actually Works
Put together, the sequence is less complicated than the noise around it suggests, and the ordering matters more than any single resource.

Start with foundational security literacy until "how does this attack work structurally" stops being a mystery. Layer OSINT on top, because it's the most immediately practical CTI skill and the one you can practice endlessly for free. Add malware analysis and threat hunting fundamentals to the depth you need to triage and understand, not to the depth of a dedicated reverse engineer. Build framework fluency and analytic tradecraft throughout, because they're the connective tissue. And from very early, publish your work, because the portfolio compounds and the certifications don't, at least not until much later.
The thing nobody tells you at the start, the thing that would have saved me months, is that the barrier isn't knowledge. The knowledge is mostly free and sitting in the open. The barrier is doing the reps and showing the work, consistently, when no one is making you. The people who break into this field aren't the ones who found the perfect course. They're the ones who picked a threat actor on a Tuesday night, wrote up what they found, hit publish, and then did it again the next week, and the week after, until the body of work spoke for itself and