Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Cyber Threat Intelligence

The GIAC Cyber Threat Intelligence (GCTI) certification validates a practitioner's strategic, operational, and tactical cyber threat intelligence knowledge and skills. GCTI holders are qualified to gather, analyze, and apply intelligence from vital sources, profile and analyze intrusions and malware, pivot and perform domain analysis, and create and share accurate and effective reports. This certification is for incident responders, threat hunters, SOC personnel, and analysts who need to deliver actionable intelligence that connects threat data across all layers of an organization.

Exam formatCyberLive: Hands-on testing in a proctored environment
Duration180 minutes
DeliveryGIAC (via ProctorU for remote, Pearson VUE for onsite)
Passing score71%
Free questions386

Content last reviewed 30 July 2026 · Up to date

The certification

What GIAC Cyber Threat Intelligence proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

6domains
9objectives
62concepts
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The GIAC Cyber Threat Intelligence (GCTI) certification validates a practitioner's strategic, operational, and tactical cyber threat intelligence knowledge and skills. It proves your ability to deliver actionable intelligence that connects threat data across strategic, operational, and tactical layers, enabling organizations to understand and respond to cyber threats effectively.

GCTI certification holders are qualified to gather, analyze, and apply intelligence from vital sources, to profile and analyze intrusions and malware, to pivot and perform domain analysis, to use technologies such as network indicators, log repositories, and forensics tools, and to create and share accurate and effective reports. The certification covers key areas including intelligence fundamentals, the kill chain and diamond model, OSINT, campaigns and attribution, and malware as a collection source.

Who it’s for

The GCTI certification is designed for professionals who are responsible for producing and using cyber threat intelligence to protect their organizations. This includes incident response team members, threat hunters, Security Operations Center (SOC) personnel, information security practitioners, experienced digital forensic analysts, and federal agents and law enforcement officials. If your role involves analyzing intrusions, attributing attacks, or communicating intelligence to decision-makers, GCTI validates the hands-on skills you need to perform at a high level.

Recommended experience

Practical work experience in cybersecurity, particularly in incident response, threat hunting, or security operations, is recommended to ensure mastery of the skills necessary for certification. College-level courses or self-paced study through other programs or materials may also meet the needs for mastery. Experience in incident response or security operations; Familiarity with network indicators, log repositories, and forensics tools; Understanding of intrusion analysis and malware analysis concepts; Ability to create and share intelligence reports

The syllabus

What you’ll learn

Every domain and objective GIAC (SANS) measures, with the weight they carry on the exam.

The official GIAC (SANS) exam outline · checked 30 July 2026 · See the source

Intelligence Fundamentals
  • Intelligence Fundamentals
1 objectives · 46 free questions · 10 pages
Intelligence Collection and Storage
  • Collecting and Storing Data Sets
  • Malware as a Collection Source
2 objectives · 89 free questions · 18 pages
Intelligence Analysis and Application
  • Analysis of Intelligence
  • Intelligence Application
2 objectives · 91 free questions · 19 pages
Operational Frameworks and Models
  • Kill Chain, Diamond Model, and Courses of Action Matrix
1 objectives · 36 free questions · 8 pages
Advanced Analysis Techniques
  • Pivoting
  • Campaigns and Attribution
2 objectives · 76 free questions · 16 pages
Intelligence Sharing
  • Sharing Intelligence
1 objectives · 48 free questions · 10 pages
On the day

The exam itself

Everything GIAC (SANS) publishes about sitting it, and nothing we inferred.

Prerequisites

No mandatory prerequisites — this certification has no required predecessor exam or credential.

CertificationGIAC Cyber Threat Intelligence
Exam formatCyberLive: Hands-on testing in a proctored environment
Duration180 minutes
Questions82 questions
Passing score71%
DeliveryGIAC (via ProctorU for remote, Pearson VUE for onsite)
LanguagesEnglish
After you pass

Where this credential goes next

The path GIAC (SANS) lays out, how the credential is kept, and where to book.

Step-by-step path to GIAC Cyber Threat Intelligence

GIAC Cyber Threat Intelligence badgeCredential earnedGIAC Cyber Threat Intelligence Certification
Renewal and maintenance

GIAC certifications must be renewed every four years. Renew by earning 36 Continuing Professional Education (CPE) credits or by retaking the exam. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. GIAC (SANS) maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by GIAC (SANS)

Exam registration

Register for the exam through GIAC (via ProctorU for remote, Pearson VUE for onsite), GIAC (SANS)’s authorized testing partner.

Schedule your exam

Visit the official GIAC (SANS) certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the GCTI exam relate to other GIAC certifications?

GCTI is a Practitioner-level certification. It can be combined with other GIAC certifications to build a portfolio, such as the GIAC Security Professional (GSP) or GIAC Security Expert (GSE).

Is the GCTI exam hands-on?

Yes, the GCTI exam uses the CyberLive format, which includes hands-on testing in realistic lab environments with virtual machines and real security tools.

What is the retake policy for the GCTI exam?

GIAC's retake policy allows candidates to retake an exam after a waiting period. Specific waiting periods and attempt limits are detailed in the GIAC retake policy on the official website.

How soon will I receive my GCTI exam results?

GIAC typically provides score reports immediately after the exam for web-based proctored exams. Detailed score breakdowns are available in your GIAC account.

What job roles does the GCTI certification map to?

GCTI is designed for incident response team members, threat hunters, SOC personnel, information security practitioners, digital forensic analysts, and federal agents or law enforcement officials.

Can I recertify GCTI by passing a different GIAC exam?

Yes, retaking the GCTI exam is one way to renew. Earning a higher-level GIAC certification may also renew lower-level certifications, but you should check the GIAC renewal policy for specifics.

Are there testing accommodations for candidates with disabilities?

GIAC provides accommodations for candidates with disabilities in accordance with applicable laws. Requests should be submitted to GIAC in advance of the exam attempt.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 386 questions, free, no account needed.