Who is Andrey Pautov?
Andrey Pautov is a Threat Intelligence Research Engineer at XPLG in Tel Aviv and a former Head of Red Team at the Israel Police Cyber Defence Unit. His work covers CTI-to-detection workflows, adversary profiling, ATT&CK mapping, malware analysis, and analyst-reviewed AI tooling.
Profile and experience
What is AdversaryGraph?
AdversaryGraph is a self-hosted CTI-to-detection workbench for turning reports, IOCs, malware findings, assets, and telemetry into ATT&CK-mapped investigations, hunting hypotheses, detection candidates, and validation evidence.
AdversaryGraph project hub
What is CTI as Code?
CTI as Code is a version-controlled method for maintaining structured intelligence, evidence, confidence, ATT&CK mappings, and detection artifacts as reviewable files with a clear change history.
CTI as Code guide
What is a CTI-to-detection workflow?
It is the controlled path from source-rated intelligence through behavior mapping, telemetry requirements, hunting hypotheses, detection logic, lab validation, and SOC handoff. Generated suggestions remain subject to analyst review.
CTI Analyst Field Manual