A focused course, tailored for you
The Cyber Threat Analyst Merchant-Risk Intel Playbook
Turn skimmer, ATO and storefront-fraud telemetry into merchant-facing intel the fraud, trust and detection teams act on this week.
Your skimmer report sits in a ticket three teams half-read. The merchant never saw it. The same family is already on tomorrow's scrape.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
Cyber threat analysts inside a global commerce platform sit on a unique signal mix: real-time storefront JavaScript scrapes, checkout-page integrity monitoring, abuse-API anomaly feeds, credential-stuffing telemetry from the login layer, payment-fraud chargeback patterns, dark-web listings of stolen card stock, and OSINT on threat actors targeting hosted merchants. The collection is rich. The problem is the translation layer. Fraud ops want a per-merchant risk score with a recommended action. Trust and safety want a takedown-ready packet for the storefront, the typosquat domain, and the C2 IP. Platform engineering wants a detection-engineering ticket with a YARA or Sigma rule that ships into the WAF or the storefront integrity service. The merchant wants a plain-language email naming the script, the deadline, and the one button they press. Without an explicit playbook, every CTI finding ends up as a Slack thread, a partially completed Jira ticket, and a follow-up that fades. This course is the playbook for converting raw merchant-risk telemetry into the four artefacts that get action this week.
What you walk away with
- Ship a weekly merchant-risk brief that fraud, trust and safety, and platform engineering read end to end and act on.
- Convert a single Magecart-style scrape finding into a takedown packet, a fraud advisory, a detection rule, and a merchant email in one cycle.
- Score merchants on storefront-integrity risk using a defensible model that survives review by trust and safety leadership.
- Hand detection engineering a ready-to-deploy YARA, Sigma or WAF rule the same day the intel lands.
- Run a credential-stuffing or ATO incident as the intel owner, not the bystander, with a clear hand-off to fraud ops.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- 12 written modules in the Art of Service learning environment, each ending in the concrete artefact for the role.
- Downloadable templates: the weekly merchant-risk brief, the fraud-ops advisory, the trust and safety takedown packet, the detection-engineering ticket, the merchant notification.
- Worked examples for each artefact based on a Magecart-style finding, a credential-stuffing wave, and a dark-web listing scenario.
- Reference profiles for the major actor clusters targeting hosted commerce.
- Hand-built implementation playbook tuned to your merchant mix and current detection stack, provisioned alongside course access.
What you will have in hand by Day 1, Week 1, Month 1
Within 24 hours: learning environment account provisioned, all 12 modules accessible, templates and worked examples downloadable.
Within 24 hours: hand-built implementation playbook delivered alongside course access, tuned to your merchant mix and current detection stack.
Week 1: weekly merchant-risk brief structure adopted, first issue shipped.
Week 2: fraud-ops advisory and trust and safety takedown packet templates in production use.
Week 4: detection-engineering ticket pattern integrated with the detection team's intake.
Week 6: measurement dashboard live, first quarterly action-rate review scheduled.
Before and after
Intel findings live in Slack threads and half-completed Jira tickets. Fraud ops, trust and safety, and platform engineering each read a different slice. Merchants find out from chargeback patterns, not from you. The CTA seat is described as valuable but cannot point to last quarter's action rate.
Every finding lands as four artefacts: the brief, the advisory, the takedown packet, the detection ticket. The merchant gets the notification before the chargeback. The action rate, the time-to-action, and the protected-merchant count are reported every quarter. The CTA seat is the intel owner, not the bystander.
What happens if you do not address this
The skimmer the merchant first learns about from their chargeback report becomes the trust event nobody recovers. The credential-stuffing wave that ATO'd three high-value merchants in one week becomes the executive question with no clean answer. The intel seat that cannot point to converted action becomes the line item on the next budget review.
Who it is for
You are a cyber threat analyst inside a global hosted-commerce platform. You sit between fraud operations, trust and safety, platform security engineering, and the merchant-facing relationship managers. You run open-source collection, dark-web monitoring, and storefront integrity analysis. You read scrape diffs, abuse-API alerts, login telemetry, and chargeback patterns. You write intel reports that need to be readable by fraud analysts, trust and safety operators, detection engineers, and the merchants themselves, often in the same week.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Roughly 14 to 18 hours across the 12 modules, plus the time you spend wiring the artefacts into your existing workflow. Most learners ship the weekly brief in week one and the takedown packet pattern by week three.
Why $199 is the right number
Generic CTI training (SANS FOR578 and similar) teaches actor tracking and finished intel writing in a single-tenant enterprise context. This course is built for the CTA seat inside a multi-tenant hosted-commerce platform, where the intel customer is fraud ops, trust and safety, detection engineering, and the merchants themselves, and where the artefact set is specifically the merchant-risk brief, the fraud advisory, the takedown packet, the detection ticket, and the merchant notification.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.