Threat Intelligence Research Engineer · XPLG · Tel Aviv, Israel

Threat intelligence that turns into detection.

I turn adversary research into ATT&CK-mapped hunts, detection candidates, validation evidence, and analyst-reviewed security tooling.

Security research: direct answers

Concise definitions for readers, search engines, and AI retrieval systems; each answer links to the supporting work.

Who is Andrey Pautov?

Andrey Pautov is a Threat Intelligence Research Engineer at XPLG in Tel Aviv and a former Head of Red Team at the Israel Police Cyber Defence Unit. His work covers CTI-to-detection workflows, adversary profiling, ATT&CK mapping, malware analysis, and analyst-reviewed AI tooling.

Profile and experience

What is AdversaryGraph?

AdversaryGraph is a self-hosted CTI-to-detection workbench for turning reports, IOCs, malware findings, assets, and telemetry into ATT&CK-mapped investigations, hunting hypotheses, detection candidates, and validation evidence.

AdversaryGraph project hub

What is CTI as Code?

CTI as Code is a version-controlled method for maintaining structured intelligence, evidence, confidence, ATT&CK mappings, and detection artifacts as reviewable files with a clear change history.

CTI as Code guide

What is a CTI-to-detection workflow?

It is the controlled path from source-rated intelligence through behavior mapping, telemetry requirements, hunting hypotheses, detection logic, lab validation, and SOC handoff. Generated suggestions remain subject to analyst review.

CTI Analyst Field Manual

10-Minute Reviewer Paths

Short on time? Pick the path that matches your role. Each route points to the strongest evidence first.

One-page summary

Hiring Managers

Fastest overall read of scope, depth, and evidence.

  1. CV and PDF download
  2. About and experience
  3. Flagship projects
  4. GitHub profile

CTI / Threat Intelligence

Adversary profiling, attribution, and CTI-to-detection methodology.

  1. CTI as a Code
  2. CTI Analyst Field Manual
  3. Operation Desert Hydra
  4. AdversaryGraph docs

Detection Engineering

Validated detections, coverage matrices, and hunting content.

  1. Newest Detection Engineering Techniques
  2. Desert Hydra Detection Atlas
  3. Validation Results
  4. Insider Threat Detection
  5. Threat hunting hypotheses

Malware / Tooling

Reverse engineering workflows, cloud scanning, and CLI tools.

  1. AIDebug
  2. stratus-ai
  3. cvss_4.0
  4. All projects

Flagship Projects

Four primary portfolio signals. Deeper domain, lab, and repository lists live on the projects page.

See all ->

Live Evidence

Six verified captures from release fixtures, reproducible labs, and published research. Each card states what the image demonstrates—and its evidence boundary.

Explore all projects

Latest

Three recent articles and three current tools. Use Medium and Projects for the full archive.

Updated Jul 2026