About Anomali
Anomali is a cybersecurity technology provider specializing in threat intelligence and security operations. Its technology helps security teams understand threats, operationalize intelligence, and use threat data to support faster and more informed security decisions.
As part of its engagement with cybersecurity leaders and practitioners, Anomali wanted to go beyond the traditional product presentation and create an experience where participants could understand threat intelligence concepts, explore practical use cases, and see how intelligence can be transformed into action.
Challenges
Threat intelligence platforms can provide security teams with large volumes of feeds, indicators, reports, and threat data. However, demonstrating the real operational value of these capabilities through a traditional presentation or product demo can be challenging.
Anomali needed:
Move Beyond the Traditional Product Demo
Rather than simply presenting platform features, Anomali wanted participants to experience how threat intelligence supports real security operations.
Connect Product Capabilities to Real-World Scenarios
Participants needed to understand where capabilities such as intelligence analysis, threat actor profiling, feed prioritization, reporting, and threat hunting fit into their day-to-day security workflows.
Engage Experienced Security Professionals
The program targeted practitioners including threat intelligence analysts, CTI leads, SOC analysts, SOC managers, incident response teams, and security operations professionals. The experience therefore needed to provide practical value beyond introductory product education.
Create an Interactive Learning Experience
Anomali wanted participants to learn a concept, apply it immediately, and understand its operational impact rather than passively consuming content.
Solution
Anomali used Simulations Labs to deliver “From Threat Intelligence to Action: Building an Effective CTI Program,” an exclusive two-day workshop combining expert-led sessions with hands-on threat intelligence simulations.
Expert-Led CTI Sessions
Participants explored key areas of building and operating an effective Cyber Threat Intelligence program, including intelligence frameworks, CTI reports, Threat Intelligence Platform capabilities, feed integration and curation, intelligence sharing, threat hunting, and AI-assisted security operations.
Hands-On CTI Simulations
Each major topic was reinforced through a practical simulation, enabling participants to immediately apply what they had learned.
The simulations included:
- Intelligence Maturity Assessment
- Threat Actor Profiling
- Intelligence Analysis Exercise
- Platform Evaluation Scenario
- Feed Prioritization Simulation
- Executive Reporting Exercise
- Intelligence-Driven Hunting Scenario
- AI-Assisted Investigation
Product Capabilities in Context
Instead of showcasing technology as a list of features, the program demonstrated how threat intelligence capabilities can support realistic security workflows.
Participants could understand the value of the technology in the context of actual analyst decisions, investigations, and operational challenges.
Dedicated Simulations Labs Environment
Simulations Labs provided a dedicated environment for the workshop, allowing participants to safely interact with realistic scenarios without requiring Anomali to build and maintain a separate hands-on training infrastructure.
Practitioner-Focused Experience
The combination of expert sessions, realistic simulations, and practical exercises created an environment where participants could discuss challenges, experiment with approaches, and connect technology capabilities directly to their own security operations.
Outcome
By combining product education with hands-on simulations, Anomali transformed a traditional technology showcase into an immersive CTI learning experience.
The program helped:
- Demonstrate Anomali's capabilities through realistic cybersecurity scenarios
- Show how threat intelligence can move from data collection to operational action
- Give participants practical experience with CTI workflows
- Connect platform capabilities to real security operations challenges
- Create deeper engagement with security decision-makers and practitioners
- Provide participants with practical takeaways they could apply within their organizations
- Position Anomali as both a technology provider and a trusted partner in building effective threat intelligence programs
Rather than simply showing participants what the technology could do, the program enabled them to experience how threat intelligence could be operationalized in practice.




