Hogeschool West-Vlaanderen
Howest Brugge
Spoorwegstraat 4 - 8200 Brugge
Tel: 050 682666
studentadmin@howest.be - Website: www.howest.be
Threat Intelligence21496/2013/2627/1/24
Study guide

Threat Intelligence

21496/2013/2627/1/24
Academic year 2026-27
Is found in:
  • Bachelor of Cybersecurity, programme stage 5
This is a single course unit.
Study load: 3 credits
Total study time: 75,00 hours
Re-sit exam: is possible.
It is not possible to enrol in this course unit under
  • exam contract (to obtain a credit).
  • exam contract (to obtain a degree).
Teaching staff: Desloover Niels, Manzo Sandro
Language course: No
Languages: English

Omschrijving Volgtijdelijkheid (VT) (EN)

Omschrijving Doelstellingen (EN)

LR01

01.3.3 Evaluates measures that reduce the impact or likelihood of identified threats or risks in a realistic simulated context

LR02

02.2.1 Interprets relevant sources of threat intelligence
02.2.2 Translates information about an incident into threat intelligence TTPs (Tactics, Techniques, Procedures) and threat actors, conforming to threat intelligence framework
02.2.3 Translates threat intelligence information into detection rules
02.2.4 Identifies and shares new threat intelligence information
02.3.1 Collects and analyzes threat intelligence from relevant sources in a simulated context
02.3.2 Structures threat intelligence information into a relevant data set in a simulated context

LR03

03.1.2 Identifies OSINT resources and techniques for reconnaissance
03.2.1 Estimates the importance of reported vulnerabilities to a simulated organization and context

LR06

06.2.2 Assesses cybersecurity requirements

LR08

08.3.2 Sets up cybersecurity communication plan and identifies training resources

LR09

09.2.1 Applies cybercrime concepts
09.3.1 Conducts an impact assessment of a project or threat and which takes into account the relevant regulations

LR11

11.1.1 Identifies and interprets the sources and organizations for cybersecurity knowledge
11.2.2 Handles cybersecurity sources and applies the principles of correct source citation when reporting
11.3.1 Translates non-cyber events into possible cyber consequences
11.3.2 Critically assesses the relevance of cybersecurity sources
11.3.3 Actively follows (inter)national developments within cybersecurity

Omschrijving Inhoud (EN)

- CTI Frameworks:
- CTI Lifecycle
- Diamond Model
- Cyber Kill Chain
- MITRE ATT&CK Framework
- CTI Pitfalls:
- Biases & Fallacies
- Analysis of Competing Hypotheses

Omschrijving Studiematerialen (lijst) (EN)

Lecturer's courseMandatory
PresentationMandatory
TutorialsMandatory
WebsitesMandatory

Omschrijving Eindcompetenties (lijst) (EN)

PBACS001: Analyses critical business processes, data and infrastructure and makes a substantial contribution to cybersecurity by design and data protection by design through the identification, evaluation and mitigation of risks and threats, establishing an information security policy, including strategic objectives, procedures, guidelines and policies.
CodeDescription
PBACS001Analyses critical business processes, data and infrastructure and makes a substantial contribution to cybersecurity by design and data protection by design through the identification, evaluation and mitigation of risks and threats, establishing an information security policy, including strategic objectives, procedures, guidelines and policies.
PBACS002: Collects, analyses, structures and shares actionable threat intelligence information that includes the behaviour, motives and capability of cybercriminals, including phishing and ransomware.
CodeDescription
PBACS002Collects, analyses, structures and shares actionable threat intelligence information that includes the behaviour, motives and capability of cybercriminals, including phishing and ransomware.
PBACS003: Across the full range of software, firmware and hardware technologies, evaluates and improves the cybersecurity of (sub)systems by detecting, analysing and dealing with existing attack vectors and vulnerabilities, this by deploying existing defensive and offensive security software, including developing proprietary scripts, penetration testing, digital footprint reduction and participating in red teaming exercises.
CodeDescription
PBACS003Across the full range of software, firmware and hardware technologies, evaluates and improves the cybersecurity of (sub)systems by detecting, analysing and dealing with existing attack vectors and vulnerabilities, this by deploying existing defensive and offensive security software, including developing proprietary scripts, penetration testing, digital footprint reduction and participating in red teaming exercises.
PBACS006: Strengthens cyber security awareness, supports necessary change processes, and provides organisation-specific advice on data and business process security architecture and maintenance.
CodeDescription
PBACS006Strengthens cyber security awareness, supports necessary change processes, and provides organisation-specific advice on data and business process security architecture and maintenance.
PBACS008: Communicates, reports and consults,at least in Dutch and English, on cyber security incidents and action plans with various stakeholders in a professional manner adapted to the target audience.
CodeDescription
PBACS008Communicates, reports and consults,at least in Dutch and English, on cyber security incidents and action plans with various stakeholders in a professional manner adapted to the target audience.
PBACS009: Acts with ethical responsibility in the areas of cybersecurity, intelligence, data protection, cyber crime, forensic investigation and cyber warfare taking into account the legal and deontological framework and the impact on individuals, organizations and society.
CodeDescription
PBACS009Acts with ethical responsibility in the areas of cybersecurity, intelligence, data protection, cyber crime, forensic investigation and cyber warfare taking into account the legal and deontological framework and the impact on individuals, organizations and society.
PBACS011: Directs its own professional development based on monitoring and consultation of relevant sources and practice-oriented research into (inter)national developments in cyber security and the domains that influence it with a view to lifelong learning.
CodeDescription
PBACS011Directs its own professional development based on monitoring and consultation of relevant sources and practice-oriented research into (inter)national developments in cyber security and the domains that influence it with a view to lifelong learning.

Omschrijving Onderwijsvorm (EN)

  • Lecture

Omschrijving Evaluatie (lijst) (EN)

Evaluation(s) for first exam chance
MomentForm%Remark
exam period 1 (1st sem) (regular exam schedule)exam: written100,00
Evaluation(s) for re-sit exam
MomentForm%Remark
exam period 3 (august/september) (regular exam schedule)exam: written100,00