Who is Andrey Pautov?
Andrey Pautov is a Threat Intelligence Research Engineer at XPLG in Tel Aviv and a former Head of Red Team at the Israel Police Cyber Defence Unit. His work covers CTI-to-detection workflows, adversary profiling, ATT&CK mapping, malware analysis, and analyst-reviewed AI tooling.
Profile and experience
What is AdversaryGraph?
AdversaryGraph is a self-hosted CTI-to-detection workbench for turning reports, IOCs, malware findings, assets, and telemetry into ATT&CK-mapped investigations, hunting hypotheses, detection candidates, and validation evidence.
AdversaryGraph project hub
What is CTI as Code?
CTI as Code is a version-controlled method for maintaining structured intelligence, evidence, confidence, ATT&CK mappings, and detection artifacts as reviewable files with a clear change history.
CTI as Code guide
What is a CTI-to-detection workflow?
It is the controlled path from source-rated intelligence through behavior mapping, telemetry requirements, hunting hypotheses, detection logic, lab validation, and SOC handoff. Generated suggestions remain subject to analyst review.
CTI Analyst Field Manual
What does public research show about AI in cyberattacks?
A purposive 111-publication corpus most often describes AI as an accelerator for familiar identity, research, evasion, and malware workflows. The 103-publication statistical denominator measures reporting coverage—not attacks, victims, prevalence, or provider abuse rates.
Read the statistical CTI study