Cyber Threat Intelligence (CTI) Analyst
Cyber Threat Intelligence (CTI) Analyst とは何ですか?
Cyber Threat Intelligence (CTI) AnalystA specialist who collects, structures, and disseminates intelligence about threat actors, campaigns, and TTPs — at strategic, operational, and tactical tiers — to inform defenders, IR teams, and executive decision-makers.
A Cyber Threat Intelligence (CTI) analyst produces and curates the actionable intelligence layer that sits between raw threat data and security decisions. The role splits along three classical tiers. Strategic CTI summarizes adversary motivations, geopolitical context, and long-term trends for executives and board audiences. Operational CTI characterizes specific named threat actors and campaigns (TTPs, infrastructure, victimology, targeting) for SOCs, hunt teams, and IR. Tactical CTI is the day-to-day stream of IOCs, YARA/Sigma rules, ATT&CK mappings, and feed entries that detection engineering consumes. Workflow combines OSINT, paid feeds (Mandiant, CrowdStrike Falcon Intelligence, Recorded Future, Intel 471), criminal-forum monitoring, sample collection (MalwareBazaar, VirusTotal Intelligence), and internal SOC telemetry, structured using frameworks such as MITRE ATT&CK, STIX/TAXII, Diamond Model, the Pyramid of Pain, and TLP. Outputs are written reports, intelligence briefings, IOC feeds, ATT&CK navigator layers, and pre-incident hunt packages. CTI analysts often hold GIAC GCTI, SANS FOR-578, eLearnSecurity eCTHP, or Mandiant-style certifications.
● 例
- 01
A CTI analyst publishes a quarterly report on Scattered Spider's evolving social-engineering TTPs, mapping observed activity to MITRE ATT&CK Enterprise.
- 02
Tactical CTI feeds the SOC a YARA rule and a list of C2 domains within hours of a new XWorm variant being observed in the wild.
● よくある質問
Cyber Threat Intelligence (CTI) Analyst とは何ですか?
A specialist who collects, structures, and disseminates intelligence about threat actors, campaigns, and TTPs — at strategic, operational, and tactical tiers — to inform defenders, IR teams, and executive decision-makers. サイバーセキュリティの 役割とキャリア カテゴリに属します。
Cyber Threat Intelligence (CTI) Analyst とはどういう意味ですか?
A specialist who collects, structures, and disseminates intelligence about threat actors, campaigns, and TTPs — at strategic, operational, and tactical tiers — to inform defenders, IR teams, and executive decision-makers.
Cyber Threat Intelligence (CTI) Analyst はどのように機能しますか?
A Cyber Threat Intelligence (CTI) analyst produces and curates the actionable intelligence layer that sits between raw threat data and security decisions. The role splits along three classical tiers. Strategic CTI summarizes adversary motivations, geopolitical context, and long-term trends for executives and board audiences. Operational CTI characterizes specific named threat actors and campaigns (TTPs, infrastructure, victimology, targeting) for SOCs, hunt teams, and IR. Tactical CTI is the day-to-day stream of IOCs, YARA/Sigma rules, ATT&CK mappings, and feed entries that detection engineering consumes. Workflow combines OSINT, paid feeds (Mandiant, CrowdStrike Falcon Intelligence, Recorded Future, Intel 471), criminal-forum monitoring, sample collection (MalwareBazaar, VirusTotal Intelligence), and internal SOC telemetry, structured using frameworks such as MITRE ATT&CK, STIX/TAXII, Diamond Model, the Pyramid of Pain, and TLP. Outputs are written reports, intelligence briefings, IOC feeds, ATT&CK navigator layers, and pre-incident hunt packages. CTI analysts often hold GIAC GCTI, SANS FOR-578, eLearnSecurity eCTHP, or Mandiant-style certifications.
Cyber Threat Intelligence (CTI) Analyst からどのように防御しますか?
Cyber Threat Intelligence (CTI) Analyst に対する防御は通常、上記の定義で述べたとおり、技術的統制と運用上の実践を組み合わせます。
Cyber Threat Intelligence (CTI) Analyst の別名は何ですか?
一般的な別名: Threat intelligence analyst, CTI researcher。
● 関連用語
- defense-ops№ 292
サイバー脅威インテリジェンス(CTI)
攻撃者・その動機・手口に関する証拠に基づく知見を体系化し、防御判断や統制の優先順位付けに活用する取り組み。
- defense-ops№ 1268
脅威インテリジェンス
脅威と攻撃者に関する、指標・TTP・背景を含むエビデンスベースの知識。セキュリティの意思決定と検知を導くために用いられる。
- compliance№ 762
MITRE ATT&CK
MITRE が維持する、実際の攻撃で観測された攻撃者の戦術・技術に関するグローバルな公開ナレッジベース。
- defense-ops№ 1223
STIX
STIX は OASIS が策定したオープン標準で、サイバー脅威インテリジェンスを構造化された機械可読な形式で表現・交換するための言語です。
- defense-ops№ 1252
TAXII Protocol
TAXII は HTTPS 上で動作する OASIS のアプリケーション層プロトコルで、組織間でサイバー脅威インテリジェンス(主に STIX)を公開・発見・取得するために使われます。
- roles№ 1266
脅威ハンター
既存の検知をすり抜けた攻撃者の活動を、企業のテレメトリから仮説駆動・脅威情報・振る舞い分析を用いて能動的に探し出すシニア防御担当者。