intrusion analysis Archives - Certification Box https://www.certificationbox.com/tag/intrusion-analysis/ Prepared Well With Certification Box Wed, 02 Sep 2026 05:15:16 +0000 en-US hourly 1 https://wordpress.org/?v=7.1 https://www.certificationbox.com/wp-content/uploads/2026/04/cropped-CertificationBox-Mini-Logo-32x32.png intrusion analysis Archives - Certification Box https://www.certificationbox.com/tag/intrusion-analysis/ 32 32 The GCTI Exam Treats Malware as a Source, Not a Skill https://www.certificationbox.com/2026/09/02/gcti-cyber-threat-intelligence-exam-objectives/ Wed, 02 Sep 2026 00:00:00 +0000 https://www.certificationbox.com/?p=30701 Naming an objective Malware as a Collection Source reclassifies a whole discipline into an intelligence input. Nine unweighted objectives, and why coverage beats a mark budget on this paper.

The post The GCTI Exam Treats Malware as a Source, Not a Skill appeared first on Certification Box.

]]>

The seventh objective on the GCTI blueprint is called Malware as a Collection Source. Not malware analysis, not reverse engineering, not incident response. A source. That one piece of naming tells you more about what the GIAC Cyber Threat Intelligence exam is than any definition could, because it quietly reclassifies a whole discipline into something intelligence work consumes rather than something it does.

Read the rest of the nine objectives with that lens and the paper stops looking like a security exam and starts looking like an analysis exam that happens to run on security data. GCTI puts 82 questions in front of you over three hours, costs $999 USD, and asks for 71 percent. None of its nine objectives carries a published weighting, which changes how you should study for it. This guide goes through all nine, what each genuinely tests, and who the fee is actually aimed at.

Why Does GCTI Treat Malware as a Collection Source?

Because on the GCTI exam, malware is evidence rather than an adversary. The objective asks you to demonstrate an understanding of malware analysis tools and techniques used to derive intelligence, which is a different question from how to remove a sample or write a signature for it. The sample is a thing you interrogate for infrastructure, tooling and behaviour you can attribute.

That distinction changes what a question looks like. A defensive exam asks what a piece of malware does to a host. GCTI asks what the sample reveals about who built it and how they operate: the domains it reaches, the certificates it presents, the code reuse it shares with earlier samples, the operational habits it exposes. The answer feeds a campaign, not a ticket.

It also explains why this credential sits oddly for people arriving from a purely defensive background. Analysts who are excellent at containment sometimes find GCTI frustrating, because the exam keeps asking what the finding means rather than what to do about it. That is the whole discipline, and the objective names make it explicit throughout.

What Are the Nine GCTI Exam Objectives?

GCTI publishes nine objectives and no weightings for any of them. They run from intelligence fundamentals and analysis technique through collection, pivoting, the three intrusion-analysis models, campaigns and attribution, malware as a source, practical application, and the sharing of finished intelligence with technical and executive audiences.

Objective What it asks you to demonstrate
Intelligence Fundamentals Core definitions and concepts, plus working knowledge of the technologies that supply analysts with data: network indicators, log repositories and forensics tools
Analysis of Intelligence Analytical technique, and the obstacles to accurate analysis such as fallacies and bias, including how to recognise and avoid them
Collecting and Storing Data Sets Collection and storage from threat feeds, domains, TLS certificates and internal sources
Pivoting Expanding intelligence through pivot analysis, link analysis tools and domain analysis
Kill Chain, Diamond Model, and Courses of Action Matrix The three models and how they are used together to analyse an intrusion
Campaigns and Attribution Profiling intrusion characteristics, grouping intelligence into campaigns, and the factors weighed when making an attribution
Malware as a Collection Source Malware analysis tools and techniques used to derive intelligence
Intelligence Application Practical gathering, analysis and use of intelligence, and how well-known attacks inform work today
Sharing Intelligence Storing intelligence from various sources, the processes and tools for sharing it, and writing accurate reports and assessments for executives

The absence of weightings is the most practically important fact in that table. On a weighted blueprint you can decide that a five percent area is worth an evening of flashcards. Here you cannot, because there is no published basis for treating any objective as cheaper than another, and nine objectives across 82 questions averages roughly nine questions each if the distribution is even.

What Is the GCTI Exam Format?

GCTI is one proctored exam of 82 questions over three hours, needing a minimum of 71 percent to pass, at $999 USD. That works out at roughly two minutes and ten seconds per question, and 59 correct answers out of 82. The recommended training is the SANS FOR578 course, and the exam is web-based with two proctoring routes.

Specification Detail
Exam code GCTI
Full credential name GIAC Cyber Threat Intelligence
Questions 82
Duration 180 minutes
Passing score 71 percent
Price $999 USD
Proctoring Remote through ProctorU, or onsite at Pearson VUE
Recommended training FOR578: Cyber Threat Intelligence

Where the 71 percent figure comes from

GIAC set the GCTI cut score using a psychometric standard-setting study, and it applies to every candidate receiving the exam version released on or after 26 December 2017. GIAC also states that it periodically reviews and may update certification specifications, and it directs candidates to confirm the format and passing score attached to their own attempt in their GIAC account before sitting.

That is worth doing rather than assuming, because a specification review can move a figure between the day you buy the attempt and the day you sit it. The current specification is published on the official GCTI certification page, which states the question count, the three hour limit and the cut score together.

Practising against the real question style matters more than the arithmetic, though. Working through a set of GCTI sample questions is the quickest way to find out whether your analysis reflexes translate into exam answers, and whether two minutes is comfortable or tight for the way you read a scenario.

What Does Pivoting Actually Mean in Threat Intelligence?

Pivoting is taking one confirmed indicator and using it to find others that the adversary did not intend you to connect. GCTI names pivot analysis, link analysis tools and domain analysis specifically, and expects you to demonstrate the ability to expand a collection rather than simply describe the concept. It is the objective that most rewards having actually done the work.

A concrete version helps. You start with a single domain from a phishing message. You look at who registered it and when, what address it resolved to, what else resolved to that address in the same window, what TLS certificate it presented, and where else that certificate appears. Each answer is a new starting point, and the discipline is knowing which ones are meaningful and which are shared hosting noise.

The judgement being tested is when to stop

Every pivot widens the set, and a wide enough set eventually includes everything. Pivoting from an address on a large hosting provider produces thousands of unrelated domains, and treating that output as a campaign is the classic beginner error. The examinable skill is recognising which shared attribute is genuinely characteristic of the adversary and which is an artefact of the internet.

This objective also connects directly to the collection one before it. TLS certificates and domain records are named in Collecting and Storing Data Sets as sources, and named again here as pivot points, which is a strong hint that the exam treats them as a single workflow rather than two topics.

How Are the Kill Chain and Diamond Model Examined Together?

GCTI groups the Kill Chain, the Diamond Model and the Courses of Action Matrix into a single objective and asks how they are used together to analyse intrusions. That grouping is the exam telling you not to learn them as three separate diagrams. They answer different questions about the same intrusion, and the examinable skill is moving between them.

GCTI intrusion analysis models compared showing the Kill Chain for sequence, the Diamond Model for event features and the Courses of Action Matrix for response

Put simply: the Kill Chain describes the sequence an intrusion moves through. The Diamond Model describes the four features of any single event, being the adversary, the capability, the infrastructure and the victim, and the relationships between them. The Courses of Action Matrix is what you do about it, crossing the phases against your available defensive actions.

Used together, they compose. Each Diamond event sits at a phase of the Kill Chain, and the matrix then asks what action you can take at that phase. That composition is where the questions live, and it is why memorising the seven phases in order earns almost nothing on its own. Lockheed Martin, which originated the model, publishes its own description of the Cyber Kill Chain phases, and reading the source is a better use of an hour than a summary of it.

The models are also where GCTI connects to the wider vocabulary an analyst is expected to share with colleagues. Adversary behaviours mapped through the MITRE ATT&CK framework slot naturally into the capability and infrastructure vertices of a Diamond event, and analysts who already think in techniques will find the transition short.

What Does Campaigns and Attribution Expect You to Judge?

This objective asks you to identify and profile intrusion characteristics, group external intelligence into campaigns, and understand the importance of attribution and the factors considered when making one. The word doing the work is factors. GCTI is not testing whether you can name threat groups; it is testing whether you can reason about confidence.

Grouping comes first. A campaign is a set of intrusions that share enough characteristics to be treated as one effort by one actor, and the analytical question is which characteristics are strong enough to justify that. Reused infrastructure is weaker evidence than reused custom code. Shared commodity tooling is weaker still, because everyone uses the same commodity tooling.

Attribution is a confidence statement, not a name

The exam’s framing treats attribution as an assessment with a stated confidence level and stated reasoning, which is why the objective sits so close to Analysis of Intelligence and its material on fallacies and bias. Confirmation bias is the specific failure mode: once an analyst has a candidate actor in mind, every subsequent indicator starts to look like support for it.

Expect questions that give you a set of overlapping indicators and ask what can legitimately be concluded, rather than questions that ask who did it. The correct answer is often more cautious than it first appears, and candidates who have written real assessments tend to find these the easiest questions on the paper.

Why Is Sharing Intelligence an Examinable Skill?

Because intelligence that nobody acts on has no value, and GCTI says so directly. The objective covers storing intelligence from various sources, the processes, tools and techniques used to share it, and specifically effectively sharing tactical intelligence with executives by writing accurate and effective reports and using capabilities such as assessments.

The executive clause is the unusual part. Most technical certifications stop at the technical audience. GCTI explicitly examines the translation step, which means understanding that an executive reader needs the assessment and its confidence up front, not the pivot chain that produced it, and that the recommendation has to be something the organisation can actually do.

The storage and process half is more conventional but no less examinable: how intelligence from different sources is normalised and retained so it stays usable, and the mechanics of sharing it onwards. Analysts who have worked inside an information-sharing community will recognise most of this, and those who have not should treat it as a genuine study area rather than assuming it is common sense.

It is also the objective that most clearly separates GCTI from the detection-focused GIAC credentials. A candidate who enjoyed the analysis half of a detection exam such as the one covered in this GCIA intrusion analyst guide will find GCTI asks them to carry the same findings several steps further, into a written product with a named audience.

How Do You Prepare When No Objective Carries a Weighting?

You prepare by coverage rather than by budget. Without published weightings there is no defensible way to decide that one of the nine objectives deserves less time, so the sequence below works outward from the concepts everything else depends on, and it is deliberately ordered because each stage supplies the vocabulary the next one assumes.

Four stage GCTI study order running from fundamentals and bias, through the three models, collection and pivoting, to judgement and sharing
  1. Begin with Intelligence Fundamentals and Analysis of Intelligence together, because the definitions and the material on fallacies and bias underpin every judgement the other seven objectives ask you to make.
  2. Learn the three models next as one connected system, mapping a real published intrusion onto the Kill Chain, the Diamond Model and the Courses of Action Matrix in a single exercise rather than three.
  3. Work collection and pivoting as a practical pair, taking one domain and expanding it through registration data, resolution history and TLS certificates until you can feel where the noise starts.
  4. Finish with campaigns, attribution, malware as a source and sharing, which are the four objectives that ask you to produce a judgement and communicate it rather than to gather anything new.

Layer the official course over that if your employer is funding it. FOR578 is the training GIAC names against this exam, and the SANS FOR578 course outline maps closely to the nine objectives, which is unsurprising given the relationship between the two organisations.

Build an index as you go. GIAC exams reward organised reference material far more than memorisation, and the useful index is one organised by objective rather than by page, so that a question about pivot noise sends you to the right place in seconds rather than the right chapter in a minute. With roughly two minutes per question, that difference decides the paper.

Who Is the $999 Fee Actually Aimed At?

GCTI is priced for employer-funded candidates in dedicated intelligence roles, not for self-funded career changers. At $999 for the attempt it is one of the more expensive specialist security exams, and the value case rests on the reader already working with intelligence data rather than hoping the credential will get them near it.

The roles it fits best are cyber threat intelligence analyst, intrusion analyst, SOC lead, detection engineer moving toward intelligence work, and incident responders who have started producing assessments rather than just findings. In each case the candidate is already doing part of what the exam measures, and the credential formalises it.

Where it fits worst is the entry point. Nothing in the nine objectives is beginner material, and the collection, pivoting and attribution objectives assume you have seen enough real infrastructure to know what normal looks like. A candidate without that exposure can pass by study alone, but the studying required is considerably more than the fee suggests.

If you are still deciding between this and the other GIAC options, the objective list is the honest comparison tool rather than the marketing copy, and a fuller walkthrough of the exam materials sits in this GCTI exam resource guide.

Frequently Asked Questions

How many questions are on the GCTI exam?

Eighty-two questions over three hours, which is roughly two minutes and ten seconds each. GIAC’s own certification page and the money-site syllabus page agree on both figures.

What is the GCTI passing score?

Seventy-one percent, so 59 correct answers out of 82. GIAC set that figure using a psychometric standard-setting study covering exam versions released on or after 26 December 2017.

How much does the GCTI certification cost?

Nine hundred and ninety-nine US dollars for the attempt. GIAC does not publish the price on its certification page, so that figure comes from the money-site syllabus page.

How many objectives does GCTI have?

Nine, and none of them carries a published weighting. That means no objective can be treated as cheap, and preparation has to work by coverage rather than by mark budget.

Is the GCTI exam proctored?

Yes. All GIAC exams are web-based and must be proctored, with two routes available: remote proctoring through ProctorU, or onsite proctoring at a Pearson VUE test centre.

What training does GIAC recommend for GCTI?

FOR578: Cyber Threat Intelligence, the SANS course named against this exam. It is not compulsory, and candidates do sit GCTI without it, but the outline maps closely to the objectives.

Does GCTI cover the Diamond Model?

Yes, alongside the Kill Chain and the Courses of Action Matrix, all three inside a single objective. The exam asks how they are used together to analyse an intrusion, not how each works alone.

Does GCTI require malware reverse engineering?

It requires understanding malware analysis tools and techniques used to derive intelligence. The framing is malware as a collection source, so the emphasis is what a sample reveals rather than deep reversing skill.

Who should take the GCTI certification?

Analysts already working with intelligence data: threat intelligence analysts, intrusion analysts, SOC leads and responders producing assessments. It is not an entry-level credential and the fee reflects that.

How long should you prepare for GCTI?

Long enough to build a reference index organised by objective and to have pivoted on real infrastructure. Candidates already in the role commonly need weeks rather than months; those coming from pure defence need longer.

Conclusion

GCTI is an analysis exam wearing security clothing. Its nine objectives ask you to gather, judge and communicate rather than detect and contain, and the naming of Malware as a Collection Source is the clearest signal of that. Eighty-two questions, three hours, 71 percent, $999, and no published weighting on any objective.

Prepare by coverage rather than by mark budget, learn the three intrusion models as one connected system rather than three diagrams, pivot on real infrastructure until the noise is obvious, and practise writing the assessment as well as reaching it. Then confirm the format and passing score attached to your own attempt in your GIAC account before you sit, because GIAC reserves the right to update specifications between purchase and exam day.

Rating: 5 / 5 (1 votes)

The post The GCTI Exam Treats Malware as a Source, Not a Skill appeared first on Certification Box.

]]>