Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by GIAC
Exam Format
Registration
Validity
GCTI Exam Topics and Domains
GCTI is organized into 9 weighted domains. Expect to work with MISP, PassiveTotal, SIEM, ThreatConnect, and more.
Intelligence Fundamentals
Cyber Threat Intelligence Definitions and Concepts
- Demonstrate understanding of fundamental cyber threat intelligence definitions and concepts
- Distinguish between strategic, operational, and tactical intelligence levels
Technologies for Intelligence Analysis
Demonstrate basic working knowledge of technologies that provide intelligence analysts with data
Collecting and Storing Data Sets
Threat Feed Collection
Demonstrate understanding of collecting data from threat feeds, domains, TLS certificates, and internal sources
Data Storage and Management
Demonstrate understanding of storing data from collection sources
Analysis of Intelligence
Analysis Techniques
Demonstrate understanding of techniques employed in analyzing information
Overcoming Analysis Obstacles
- Demonstrate understanding of obstacles to accurate analysis, such as fallacies and bias
- Know how to recognize and avoid analytical pitfalls
Kill Chain, Diamond Model, and Courses of Action Matrix
Cyber Kill Chain
- Demonstrate understanding of the Cyber Kill Chain framework
- Apply kill chain to analyze intrusions
Diamond Model of Intrusion Analysis
- Demonstrate understanding of the Diamond Model
- Use Diamond Model for intrusion analysis
Courses of Action Matrix
- Demonstrate understanding of the Courses of Action Matrix
- Use frameworks together to analyze intrusions
Intelligence Application
Practical Intelligence Application
Demonstrate understanding of the practical application of gathering, analyzing, and using intelligence
Learning from Historical Attacks
Demonstrate understanding of how well-known cyber attacks inform cyber intelligence professionals
Malware as a Collection Source
Malware Analysis Tools
Demonstrate understanding of malware analysis tools
Deriving Intelligence from Malware
Demonstrate understanding of techniques to derive intelligence from malware
Pivoting
Pivot Analysis Techniques
Demonstrate understanding of pivoting to expand intelligence
Link Analysis and Domain Analysis
Demonstrate ability to use link analysis tools and perform domain analysis to expand intelligence collections
Campaigns and Attribution
Campaign Identification and Profiling
Demonstrate understanding of identifying and profiling intrusion characteristics and external intelligence into campaigns
Attribution Analysis
Demonstrate understanding of the importance of attribution and factors considered when making an attribution
Sharing Intelligence
Intelligence Sharing Methods
- Demonstrate understanding of methods and practices of storing intelligence from various sources
- Understand processes, tools, and techniques used in sharing intelligence
Intelligence Reporting
Demonstrate understanding of effectively sharing tactical intelligence with executives through accurate and effective reports and assessments
How do I earn this certification?
Passing GCTI earns the GIAC Cyber Threat Intelligence certification. It sits in the Cyber Threat Intelligence / DFIR track.
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
The most effective way to prepare for GCTI is by using the PlanetCert Simulator to practice questions and review detailed explanations.
What's changed on this exam?
- MISP (Malware Information Sharing Platform) Latest
- STIX/TAXII 2.x
- YARA Latest
- MITRE ATT&CK Latest
Who should take this exam?
This exam is typically taken by Incident response team members and Threat hunters.
- Experience in information security
- Basic understanding of networking and security concepts
- Familiarity with incident response processes
- FOR578: Cyber Threat Intelligence course (highly recommended)