Professional credentials for the
cyber intelligence workforce.
CTIB certification pathways validate real-world capability across security analysis, threat intelligence, SOC operations, and digital forensics — built around vendor-neutral frameworks, public blueprints, and exam integrity.
Choose the credential aligned
to your career stage.
Each CTIB credential is mapped to specific job functions, measurable competencies, and real-world security tasks expected by employers, agencies, and enterprise security teams.
Certified Cyber Defense Associate
Designed for early-career analysts entering SOC, monitoring, and incident triage roles. Focuses on fundamentals of threat identification, log review, alert handling, and basic investigation workflow.
Certified Threat Intelligence Professional
Validates the full intelligence lifecycle: collection planning, source evaluation, adversary tracking, MITRE ATT&CK mapping, IOC handling, and structured intelligence reporting.
Certified Security Operations Professional
For professionals handling advanced SOC operations, detection engineering, alert correlation, incident response coordination, escalation playbooks, and analyst-led investigation workflows.
Certified Cyber Forensics Expert
A practical credential for investigators and forensic specialists covering acquisition, chain of custody, artefact analysis, malware triage, reporting, and expert-level investigation documentation.
Built for trust,
not shortcuts.
CTIB exams are designed to protect credential value through transparent blueprints, controlled delivery, live proctoring, and practical assessment where role requirements demand it.
Live proctored delivery
Candidate identity checks, controlled browser environment, camera verification, and active session monitoring.
Verifiable digital credentials
Credential records can be validated through the CTIB registry for employer and institutional verification.
Continuous blueprint review
Objectives are reviewed periodically to reflect changes in adversary behaviour, SOC operations, intelligence tradecraft, and forensic practice.
Intelligence lifecycle & collection planning
Requirements, PIRs, collection sources, reliability, confidence, and analytical discipline.
Threat actor profiling & TTP mapping
MITRE ATT&CK, kill chain logic, campaign tracking, infrastructure analysis, and behavioural indicators.
IOC handling & intelligence sharing
Indicator lifecycle, STIX/TAXII basics, enrichment, validation, and operational distribution.
Reporting & executive communication
Tactical, operational, and strategic reporting for SOC, CISO, and leadership audiences.
Scenario-based decision making
Applied intelligence judgement using real-world incident context and partial information.
From registration to
verified credential.
A simple candidate flow designed for clarity, governance, and auditability.
Select track
Choose the certification aligned with your role and experience level.
Review blueprint
Study exam objectives, domains, format, and candidate policies.
Schedule exam
Book your online proctored exam through the CTIB exam portal.
Complete assessment
Take the exam under proctored conditions with identity verification.
Verify credential
Receive a digital certificate and registry-verifiable credential ID.
Ready to build a recognised cyber intelligence credential?
Start with the candidate handbook, compare tracks, or speak with CTIB about enterprise and academic certification pathways.