Skip to content

Skills you need to be a threat intelligence analyst

9 skills a hiring manager would actually test for, each with the level this role expects and what it is used for. Not a syllabus — the shape of the job.

Build my path to this role

Upskili checks what you can already do, then sequences only what is missing. No account needed.

What the role requires

Ordered by how much the job depends on it. The bar is the proficiency expected of a competent threat intelligence analyst — not mastery, and not a passing acquaintance.

  • Threat Intelligence Platforms (MISP, ThreatConnect, Anomali)

    Essential

    Centralizes, correlates, and operationalizes threat data from multiple sources.

    Strong
  • Python

    Essential

    Automates data enrichment, API queries, and custom threat feed parsing.

    Strong
  • STIX/TAXII

    Essential

    Structures and shares threat intelligence in a standardized, machine-readable format.

    Deep
  • MITRE ATT&CK Framework

    Important

    Maps adversary behaviors to techniques for detection and gap analysis.

    Deep
  • SQL

    Important

    Queries internal security databases to hunt for indicators and patterns.

    Strong
  • Malware Analysis (static/dynamic)

    Important

    Extracts indicators and understands capabilities from suspicious files.

    Working
  • Network Traffic Analysis (Wireshark, Zeek)

    Useful

    Identifies command-and-control traffic and data exfiltration patterns.

    Strong
  • Open Source Intelligence (OSINT) Techniques

    Useful

    Gathers and validates threat information from public and dark web sources.

    Strong
  • Report Writing and Briefing

    Useful

    Communicates findings and risk to both technical and executive audiences.

    Strong

An order worth learning it in

A list of ten skills is the same unhelpful answer a catalogue gives, just sorted. This is where to actually start.

1

Start here

Essential to the role, and reachable from a standing start. Everything below rests on these.

  • Python
  • SQL
  • Malware Analysis (static/dynamic)
2

Then this

The rest of what the role is assessed on. Harder, and it builds on the foundation above.

  • Threat Intelligence Platforms (MISP, ThreatConnect, Anomali)
  • STIX/TAXII
  • MITRE ATT&CK Framework
3

What sets you apart

Not what gets you hired, but what separates doing the job from being trusted with it.

  • Network Traffic Analysis (Wireshark, Zeek)
  • Open Source Intelligence (OSINT) Techniques
  • Report Writing and Briefing

You almost certainly have some of this already.

That is the point of starting from the role rather than a course. Upskili checks what you can do, then builds a path across only the gap.

See my path to threat intelligence analyst