
Cyber Espionage and Counterintelligence Course
Master the tradecraft of cyber espionage and counterintelligence from threat actor profiling to active defense operations. This course equips security professionals and intelligence analysts with the frameworks, techniques, and analytical rigor needed to detect, attribute, and counter state-sponsored intrusions. From adversary TTPs to enterprise CI program management, every module is built for real-world application.
What you will learn:
Identify and classify nation-state threat actors by capability, motivation, and historical behavior.
Apply structured analytic techniques to produce defensible, high-confidence attribution assessments.
Design layered detection architectures tuned to the low-and-slow patterns of espionage actors.
Build and manage threat intelligence pipelines from collection requirements through finished products.
Construct deception environments and adversary engagement protocols within legal and ethical boundaries.
Integrate counterintelligence program governance, metrics, and executive communication into a unified strategy.
How you study in practice Cyber Espionage and Counterintelligence Course
How you practise Cyber Espionage and Counterintelligence Course
For companies looking to train their team
With Dedika for Business, the course includes exercises and examples tailored to your own business and the way your company needs.
Course Content
8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsFoundations of Cyber Espionage
Foundations of Cyber Espionage
Lesson 1 • Defining Cyber Espionage
Clarifies what cyber espionage is, how it differs from cybercrime and hacktivism, and why the distinction matters. Anchors all subsequent threat analysis in precise terminology.
Lesson 2 • Historical Evolution of Cyber Espionage
Traces espionage from Cold War signals intelligence to modern advanced persistent threats. Provides historical patterns students use to anticipate future threat evolution.
Lesson 3 • Threat Actor Taxonomy
Categorizes nation-state groups, criminal proxies, and insider threats by capability and motivation. Students apply this taxonomy to attribute and prioritize threats throughout the course.
Lesson 4 • Geopolitical Drivers of Cyber Espionage
Examines how economic competition, military rivalry, and political conflict motivate espionage campaigns. Students connect geopolitical context to adversary targeting decisions.
Lesson 5 • Intelligence Cycle Fundamentals
Introduces the planning, collection, processing, and dissemination cycle as it applies to cyber operations. Frames how adversaries and defenders both use structured intelligence processes.
Chapter 2HideHide detailsSee detailsAdversary Tactics, Techniques, and Procedures
Adversary Tactics, Techniques, and Procedures
Lesson 1 • Structured Adversary Behavior Frameworks
Introduces kill-chain and behavior-matrix frameworks for organizing observed adversary actions. Provides the analytical scaffolding used in all subsequent threat analysis sections.
Lesson 2 • Reconnaissance and Target Selection
Covers passive and active reconnaissance methods adversaries use before initial access. Students learn to identify reconnaissance indicators in network and open-source data.
Lesson 3 • Initial Access and Exploitation Techniques
Examines spear-phishing, watering-hole attacks, and zero-day exploitation as primary entry vectors. Connects each technique to the adversary goals established in Chapter 1.
Lesson 4 • Persistence and Lateral Movement
Details how adversaries maintain long-term access and expand within target networks. Students trace movement patterns to understand dwell-time and data staging behavior.
Lesson 5 • Data Exfiltration Methods
Analyzes covert channels, encrypted tunnels, and staged exfiltration used to remove sensitive data. Students identify exfiltration signatures that inform detection strategies in later chapters.
Chapter 3HideHide detailsSee detailsCyber Counterintelligence Principles
Cyber Counterintelligence Principles
Lesson 1 • Counterintelligence Mission and Scope
Defines counterintelligence objectives, organizational roles, and the relationship to broader security programs. Positions CI as a proactive discipline rather than a reactive security function.
Lesson 2 • Insider Threat Detection Programs
Examines behavioral indicators, access anomalies, and program structures for detecting malicious insiders. Students design detection criteria aligned with organizational risk profiles.
Lesson 3 • Counterintelligence Collection Strategies
Covers technical and human collection methods used to detect adversary presence and intent. Bridges offensive TTP knowledge from Chapter 2 into defensive collection planning.
Lesson 4 • Counterintelligence Analysis Methods
Introduces structured analytic techniques for evaluating adversary intent, capability, and opportunity. Students apply these methods to produce actionable CI assessments.
Lesson 5 • Threat Modeling for Counterintelligence
Applies structured threat modeling to identify high-value assets and likely adversary approaches. Students produce threat models that drive prioritization decisions throughout the course.
Chapter 4HideHide detailsSee detailsThreat Intelligence Collection and Analysis
Threat Intelligence Collection and Analysis
Lesson 1 • Structured Analytic Techniques
Applies structured methods to reduce cognitive bias and improve analytical rigor in threat assessments. Students practice techniques that produce defensible, peer-reviewable conclusions.
Lesson 2 • Open-Source Intelligence for Cyber Threats
Covers systematic OSINT collection from technical repositories, dark web forums, and public feeds. Students apply collection discipline to avoid information overload and bias.
Lesson 3 • Intelligence Requirements and Planning
Establishes how to define priority intelligence requirements and translate them into collection tasks. Ensures all subsequent collection activity is purposeful and measurable.
Lesson 4 • Technical Indicator Collection and Management
Addresses collection, normalization, and lifecycle management of indicators of compromise. Students build indicator pipelines that feed detection systems covered in Chapter 5.
Lesson 5 • Intelligence Product Development
Guides students through drafting tactical alerts, operational briefs, and strategic assessments. Products are calibrated to audience needs and decision timelines.
Chapter 5HideHide detailsSee detailsDetection, Monitoring, and Incident Response
Detection, Monitoring, and Incident Response
Lesson 1 • Post-Incident Intelligence Integration
Converts incident findings into updated threat models, detection rules, and intelligence products. Closes the loop between operational response and strategic CI analysis.
Lesson 2 • Detection Architecture for Espionage Threats
Designs layered detection systems tuned to the low-and-slow behavior of espionage actors. Applies indicator and TTP knowledge from Chapters 2 and 4 to sensor placement decisions.
Lesson 3 • Digital Forensics for Counterintelligence
Covers memory forensics, artifact analysis, and timeline reconstruction in espionage investigations. Students extract adversary TTPs from forensic evidence to enrich threat intelligence.
Lesson 4 • Incident Response for Espionage Intrusions
Adapts standard incident response to the unique challenges of long-dwell espionage cases. Students practice containment decisions that preserve forensic evidence and intelligence value.
Lesson 5 • Behavioral Analytics and Anomaly Detection
Applies user and entity behavior analytics to surface insider threats and compromised accounts. Students configure detection logic that minimizes false positives in high-noise environments.
Chapter 6HideHide detailsSee detailsAttribution and Threat Actor Profiling
Attribution and Threat Actor Profiling
Lesson 1 • Behavioral and Tradecraft Attribution
Uses targeting patterns, tool preferences, and operational tempo to distinguish actor groups. Complements technical attribution with behavioral signatures resistant to spoofing.
Lesson 2 • Attribution in Operational Context
Examines how attribution findings inform policy, legal, and operational response decisions. Students practice communicating attribution assessments to non-technical decision-makers.
Lesson 3 • Technical Indicators of Attribution
Examines malware code similarities, infrastructure reuse, and operational security failures as attribution signals. Students weigh technical evidence against adversary deception capabilities.
Lesson 4 • Threat Actor Profile Construction
Guides students through building structured profiles covering capability, intent, and historical activity. Profiles become living documents updated as new intelligence is collected.
Lesson 5 • Attribution Methodology and Standards
Establishes the evidentiary standards, confidence levels, and analytical process for cyber attribution. Prevents overconfidence by grounding attribution in reproducible, documented reasoning.
Chapter 7HideHide detailsSee detailsDeception Operations and Active Defense
Deception Operations and Active Defense
Lesson 1 • Honeypot and Honeynet Design
Covers the architecture, placement, and monitoring of honeypots and honeynets for adversary engagement. Students design deception environments calibrated to attract and observe specific threat actors.
Lesson 2 • Adversary Engagement and Intelligence Collection
Examines controlled adversary engagement to collect TTPs, tools, and infrastructure details. Students balance intelligence gain against operational risk and legal exposure.
Lesson 3 • Measuring Deception Operation Effectiveness
Defines metrics for evaluating whether deception operations achieved their intelligence and defensive goals. Students apply measurement frameworks to refine future deception designs.
Lesson 4 • Deception Theory and Principles
Introduces the cognitive and operational principles underlying effective deception in cyber environments. Provides the theoretical foundation for all deception design activities in this chapter.
Lesson 5 • Breadcrumb and Canary Token Techniques
Teaches placement of false documents, credentials, and tokens to detect and track adversary access. Students design breadcrumb strategies aligned with specific threat actor behaviors.
Chapter 8HideHide detailsSee detailsStrategic Counterintelligence and Program Management
Strategic Counterintelligence and Program Management
Lesson 1 • Crisis Management and Strategic Response
Prepares students to lead organizational response to confirmed state-sponsored espionage campaigns. Integrates attribution, legal, communications, and remediation workstreams into a unified response.
Lesson 2 • Enterprise CI Program Architecture
Designs the governance structure, team composition, and operational model for a mature CI program. Synthesizes technical and analytical capabilities from all prior chapters into a unified framework.
Lesson 3 • Strategic Threat Assessment Production
Guides production of long-range threat assessments that inform executive strategy and resource allocation. Students apply structured analytic techniques from Chapter 4 at the strategic level.
Lesson 4 • CI Program Metrics and Performance Management
Establishes key performance indicators and measurement frameworks for CI program accountability. Students design dashboards that communicate program value to non-technical leadership.
Lesson 5 • CI Policy and Regulatory Alignment
Aligns CI program activities with data protection, privacy, and security compliance obligations. Students identify regulatory constraints that shape collection and retention practices.
Your valid completion certificate
This course is for you:
SOC Analyst: ready to move beyond reactive alerts into intelligence-driven defense.
Intelligence Analyst: transitioning from traditional analysis into cyber-focused threat work.
Security Engineer: wanting to understand adversary behavior behind the tools they deploy.
Military or Government Veteran: applying prior intelligence experience to civilian cybersecurity roles.
Threat Hunter: seeking structured methodology to replace intuition-based investigation habits.
Cybersecurity Student: building a specialization in nation-state threats and counterintelligence programs.
What our students say
Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.

I like the content and the presentation style and video transcription, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top training programs
FAQ
Who is Dedika?
Is the certificate valid in Canada?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















