Most “AI for cyber” training bolts prompts onto SOC playbooks and calls the result transformation. Treadstone 71 built the opposite. The new five-day flagship, AI-Augmented Cyber Intelligence Tradecraft, wraps Anthropic Claude — Projects, Skills, MCP, Agent Teams, Computer Use — around two decades of operational doctrine: the Adaptive Cyber Intelligence Lifecycle, the 30-technique Advanced SATs arsenal, STEMPLES Plus, Hofstede cultural integration, ICD 203 estimative language, and BLUF analytic writing. Students leave on Friday with a deployable 9-component AI-assisted intelligence stack. Inspectable. Portable. Theirs.
The mantra governs everything: if it does not change a decision, it is not Intelligence.
Doctrine First. Then Automation.
The discipline is the moat. Claude is the amplifier. The curriculum treats AI as a de-biasing analytic partner — one that earns trust through structured technique, deterministic guardrails, and bias scoring — never as a magic answer machine. Heuer’s matrix-based SATs (ACH, Key Assumptions Check, Devil’s Advocacy) anchor the vocabulary as foundational orientation. The operational arsenal belongs to Treadstone 71’s Advanced Analytic Dominance library: DBNA, RMCA, DUM, MVHT, CARM, MRA, ITBP, CIDD, and twenty-two more techniques built for AI-automated disinformation, weaponized cognitive bias, and hybrid cyber-economic coercion — threats Heuer never faced.
Two Tracks. One Doctrinal Spine.
Greenfield charters a cyber intelligence cell from zero. CISOs, founding analysts, and program managers build a cell-in-a-box against the MERIDIAN fintech scenario: chartered mission, governance, PIR Plus requirements, and a 90-day maturity roadmap on the Cyber Intelligence CMM.
Brownfield modernizes mature programs without breaking them. Heads of intelligence and senior analysts diagnose tradecraft drift, refactor a bloated PIR backlog, batch-contextualize 6–12 months of historical reporting, wire MISP or OpenCTI through custom MCP servers, and instrument an AI ROI dashboard a board accepts — against the NORTHWIND Fortune 500 industrial scenario with deliberately introduced drift.
Five Days, Mapped to the Lifecycle
Day 1 — Strategic Target Framing. Charter the cell as a Claude Project. Elicit PIRs from a named executive sponsor. Build ATCRI paired-comparison threat tournaments, ATVA multi-vector assessments, HWVM vulnerability matrices, and DTTM emerging-technology monitors as Skills and Agent Teams.
Day 2 — Smart Collection. Sign a collection plan. Construct two passive personas with MBTI, Big Five, Seven Radicals, and Enneagram scaffolding plus Hofstede-consistent legends. Stand up Postgres with pgvector and Anthropic Contextual Retrieval. Wire RMCA stylometric attribution, CTCA convergence analysis, and the defensive AABDA/AARD detection hooks.
Day 3 — Predictive Intervention. Heuer is foundational, not operational. Build the analysis arsenal as Agent Teams: DBNA runs prior/likelihood/posterior arithmetic across competing narratives; CARM and MRA forecast adversary pivots before the next disruption; multi-model ACH debate replaces single-agent theater. Every output is math-based, ICD-203-bounded, and scored at 80 or above on the Cognitive Bias Validator.
Day 4 — Production, Counterintelligence, Economics. Generate a four-product fan-out from one analytic line: executive micro-brief, board estimative paragraph, STIX 2.1 IOC bundle, RFI response. Wire ITBP and CIDD as Claude Code hook chains. Build EICA economic coercion analysis and SCIM supply-chain mapping.
Day 5 — Cognitive Warfare and Capstone. The full cognitive-warfare suite — Detect, Analyze, Expose, Counter, Contain — followed by Operation Silent Horizon: a 20-minute capstone brief in strict BLUF. Bottom line in the first 50 words. No exceptions. A Stop hook enforces the rule.
The 9-Component Capstone Stack
Every graduate ships the same working stack: a PIR Generator and Validator, a sponsor-signable Collection Planner, a Persona Library with OPSEC SOP, an automated STEMPLES Plus Analyzer cutting analyst hours per quarterly assessment by 50 percent or more, a multi-agent ACH Workbench, a Contextual Retrieval RAG repository with enforced citations, a BLUF/TL;DR Report Generator auto-scored for bias, a multi-product Dissemination Workflow, and a Feedback/AAR Loop that turns Slack and Jira signal into PIR-refresh recommendations.
Hooks act as deterministic counterintelligence guardrails. Drafts containing soft modal verbs without a confidence band get rejected before a human ever reads them. Every finished product carries a provenance footer: model, sources, bias score, analyst signature.
Ethics and OPSEC, Stated Plainly
The classroom posture is observation-only. Personas are designed, never registered or engaged. Active elicitation and pretexting remain reserved for sponsored, lawyered programs under documented rules of engagement. Influence operations appear strictly in the defensive posture; offensive influence sits firmly out of scope.
Florida 2026: Three Cities
The in-person tour delivers Greenfield and Brownfield tracks in parallel:
- Orlando — July 13–17, 2026
- Tampa Bay — August 3–7, 2026
- Miami — September 14–18, 2026
Public online cohorts run at $4,995 per seat with 90-day post-class Slack support and a Practitioner Certificate. Private onsite cohorts run at $59,995 for up to 15 seats with curriculum tailoring and 30-day modernization advisory. Sovereign engagements by RFP include air-gapped open-weights delivery (Llama, Qwen), Claude Gov substitution where qualified, and the 13-week Cyber Cognitive Warfighter combination.
The Bottom Line
Tradecraft you defend. A stack you deploy. Reserve a seat, commission a private cohort, or open an RFP at treadstone71.com, contact the team through the T71 contact form, or call +1 (424) 234-3629.
Treadstone 71 LLC. Pure-play cyber intelligence and cognitive warfare consultancy. Veteran-owned. NICCS-listed. Operational since 2002.
