Cyber Threat Intelligence Reading Lists
Today is the first day of SANS Cyber Threat Intelligence Summit. During one of the talks, there was a helpful conversation on “recommended readings” for CTI professionals. Scott Roberts (author of Intelligence-Driven Incident Response & Manager of CTI at Splunk) and Katie Nichols (Director of Intelligence at Red Canary & contributing author to the MITRE ATT&CK framework) have written up some really good recommendations. A few books appeared on both of their lists:
Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains by Hutchins, Cloppert & Amin — 
The Diamond Model of Intrusion Analysis by Sergio Caltagirone, Andrew Pendergast, and Chris Betz
Psychology of Intelligence Analysis by Richards Heuer
Incident Response & Computer Forensics, Third Edition
Practical Malware Analysis
Thwarting Enemies at Home and Abroad
Structured Analytic Techniques For Intelligence Analysis
Threat Intelligence: Collecting, Analysing, Evaluating
Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains by Hutchins, Cloppert & Amin — 
The Diamond Model of Intrusion Analysis by Caltagirone, Pendergast, & Betz — 
Psychology of Intelligence Analysis by Heuer 
Industrial Control Threat Intelligence by Sergio Caltagirone
Psychology of Intelligence Analysis by Richards Heuer
Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains by Eric Hutchins, Michael Cloppert, and Rohan Amin
The Diamond Model of Intrusion Analysis by Sergio Caltagirone, Andrew Pendergast, and Chris Betz
MITRE ATT&CK™: Design and Philosophy by Blake Strom, et al
A Brief History of Attribution Mistakes by Sarah Jones
CTI SquadGoals — Setting Requirements by Scott J. Roberts
Threat Intelligence Naming Conventions: Threat Actors, & Other Ways of Tracking Threats by Robert M. Lee
Does a BEAR Leak in the Woods? by Toni Gidwani
Cyber Intelligence Tradecraft Report — The State of Cyber Intelligence Practices in the United States by Jared Ettinger