Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by EC-Council
Exam Format
Registration
Validity
312-85 Exam Topics and Domains
312-85 is organized into 8 weighted domains. Expect to work with MISP, OpenCTI, Splunk, ThreatConnect, and more.
Introduction to Threat Intelligence
Intelligence Fundamentals
- Understand fundamentals of threat intelligence
- Differentiate between types of intelligence
- Apply intelligence concepts to security scenarios
Cyber Threat Intelligence Concepts
- Master cyber threat intelligence concepts
- Apply threat intelligence frameworks
- Evaluate threat intelligence maturity
Threat Intelligence Lifecycle and Frameworks
- Understand the complete threat intelligence lifecycle
- Apply lifecycle stages to real scenarios
Threat Intelligence Platforms (TIPs)
- Understand TIP capabilities and features
- Select appropriate platforms for requirements
Threat Intelligence in the Cloud Environment
- Adapt threat intelligence for cloud environments
- Understand cloud-specific threat vectors
Future Trends and Continuous Learning
- Identify emerging trends in threat intelligence
- Plan for continuous improvement
Cyber Threats and Attack Frameworks
Cyber Threats
- Identify and categorize threat actors
- Understand threat actor motivations and capabilities
Advanced Persistent Threats (APTs)
- Analyze APT characteristics and behaviors
- Track and attribute APT activities
Cyber Kill Chain
- Apply Cyber Kill Chain methodology
- Identify defensive opportunities at each stage
MITRE ATT&CK and Diamond Model
- Apply MITRE ATT&CK framework effectively
- Use Diamond Model for intrusion analysis
Indicators of Compromise (IoCs)
- Create and manage IoCs effectively
- Share IoCs using standard formats
Requirements, Planning, Direction, and Review
Organization's Current Threat Landscape
- Assess organizational threat landscape
- Identify and prioritize threats
Requirements Analysis
- Define intelligence requirements effectively
- Align requirements with business objectives
Planning Threat Intelligence Program
- Design comprehensive threat intelligence programs
- Develop program documentation
Establishing Management Support
- Secure management support
- Communicate value effectively
Building a Threat Intelligence Team
- Structure threat intelligence teams
- Define roles and responsibilities
Threat Intelligence Sharing
- Establish sharing relationships
- Implement sharing protocols
Reviewing Threat Intelligence Program
- Evaluate program effectiveness
- Implement continuous improvement
Data Collection and Processing
Threat Intelligence Data Collection
- Develop collection strategies
- Evaluate source reliability
Threat Intelligence Collection Management
- Manage collection operations
- Optimize resource utilization
Threat Intelligence Feeds and Sources
- Select appropriate intelligence feeds
- Integrate multiple feed sources
Threat Intelligence Data Collection and Acquisition
- Master various collection techniques
- Apply appropriate collection methods
Bulk Data Collection
- Automate data collection
- Build collection pipelines
Data Processing and Exploitation
- Process raw intelligence data
- Ensure data quality
Threat Data Collection and Enrichment in Cloud Environments
- Collect intelligence from cloud environments
- Enrich cloud-based threat data
Data Analysis
Data Analysis Fundamentals
- Apply structured analytic techniques
- Recognize and mitigate biases
Data Analysis Techniques
- Master analytical techniques
- Apply appropriate analysis methods
Threat Analysis
- Conduct comprehensive threat analysis
- Assess threat severity and likelihood
Threat Analysis Process
- Execute threat analysis workflows
- Correlate multiple data sources
Fine-Tuning Threat Analysis
- Optimize analysis processes
- Reduce false positives
Threat Intelligence Evaluation
- Evaluate intelligence quality
- Assign confidence levels
Creating Runbooks and Knowledge Base
- Create effective runbooks
- Build knowledge repositories
Threat Intelligence Tools
- Select appropriate analysis tools
- Leverage tool capabilities effectively
Dissemination and Reporting of Intelligence
Threat Intelligence Reports
- Create effective intelligence reports
- Tailor reports to audiences
Dissemination
- Implement dissemination strategies
- Ensure timely distribution
Participating in Sharing Relationships
- Engage in sharing communities
- Build trust relationships
Sharing Threat Intelligence
- Apply sharing protocols correctly
- Sanitize sensitive information
Delivery Mechanisms
- Implement delivery mechanisms
- Automate intelligence distribution
Threat Intelligence Sharing Platforms
- Deploy sharing platforms
- Configure platform integrations
Intelligence Sharing Acts and Regulations
- Understand legal frameworks
- Ensure compliance in sharing
Threat Intelligence Integration
- Integrate intelligence with security tools
- Automate response actions
Threat Intelligence Sharing and Collaboration using Python Scripting
- Develop Python scripts for sharing
- Automate collaboration workflows
Threat Hunting and Detection
Threat Hunting Concepts
- Understand threat hunting principles
- Develop hunting hypotheses
- Execute hunting operations
Threat Hunting Automation
- Automate hunting processes
- Develop detection rules
- Implement continuous hunting
Threat Intelligence in SOC Operations, Incident Response, and Risk Management
Threat Intelligence in SOC Operations
- Integrate intelligence into SOC operations
- Support SOC analysts effectively
- Measure intelligence impact
Threat Intelligence in Risk Management
- Apply intelligence to risk management
- Support strategic decisions
- Quantify threat risks
Threat Intelligence in Incident Response
- Support incident response with intelligence
- Perform post-incident analysis
- Improve detection based on incidents
How do I earn this certification?
Passing 312-85 earns the Certified Threat Intelligence Analyst certification. It sits in the Threat Intelligence & Blue Team track.
- 312-79 - ECIH - EC-Council Certified Incident Handler Advanced incident response with threat intelligence
- 312-75 - EC-Council Certified Chief Information Security Officer Executive-level security management
- LPT-Master - Licensed Penetration Tester MasterAdvanced penetration testing expertise
- 312-40 - CCSE - Certified Cloud Security EngineerCloud threat intelligence specialization
- 312-96 - CPENT - Certified Penetration Testing ProfessionalOffensive security perspective
- 312-82 - CAST - Certified Application Security Tester Application threat intelligence
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
Use the official PlanetCert Practice Test alongside the study plan below to prepare efficiently for 312-85.
What's changed on this exam?
- ACTIVE
- Last content update: 2024-02-01
- Announcement date: 2024-01-15
- Python for Threat Intelligence Python 3.11+ Increased focus on automation scripting • Release date: 2024-01-01
- STIX 2.1 2.1 Standard format for threat intelligence sharing • Release date: 2021-03-01
- MITRE ATT&CK v14.0 Framework heavily referenced in exam • Release date: 2023-10-31
Who should take this exam?
This exam is typically taken by Threat Intelligence Analysts and SOC Analysts.
- 2-3 years of experience in cybersecurity, IT, or related field
- Understanding of basic networking concepts
- Familiarity with security operations
- Knowledge of threat landscape