CTI Project Ecosystem
Purpose
This page connects the CTI documentation projects into one practitioner ecosystem. Each project has a different role, but they are designed to be used together.
The Ecosystem
CTI Portfolio — Andrey Pautov is the top-level entry point: four documentation sites, 11 repositories, 36 articles. Start there to navigate the full body of work, then come back to the specific project you need.
| Project | Role | Use When |
|---|---|---|
| CTI Portfolio | Top-level hub — all CTI work in one place | You want an overview of the full body of work: actor research, methodology, detection engineering, labs |
| CTI as a Code | Lab platform + structured training assignments + published case studies | You want a hands-on lab, worked case studies, Sigma rules, and methodology scaffolds |
| CTI Analyst Field Manual | General CTI tradecraft and analytic operating manual | You need evidence discipline, analytic judgment, attribution methodology, infrastructure pivoting, or CTI-to-detection reasoning |
| Customer-Driven AI CTI Project | Delivery methodology and customer engagement model | CTI work must become a managed project with phases, quality gates, and customer acceptance criteria |
| Israel Government Threat Actors CTI | Israeli sector and actor knowledge base | The question involves Israeli government, municipal, telecom, critical infrastructure, or supplier exposure |
| HexStrike AI | AI-powered offensive security automation | Adversarially validating detection coverage built in A04 or A08 against real TTPs |
Published Case Studies
Real investigations worked end-to-end using the CTI as a Code methodology — from first alert through stakeholder deliverables. Each article is a complete, reproducible walkthrough with evidence files, queries, and detection rules.
| Case Study | Scenario | Key Techniques | Article |
|---|---|---|---|
| LifeTech Pharma — Reactive IR | Dual-entry pharmaceutical IP theft — AiTM + CFO phishing, DCSync, 381 MB exfiltration | T1557 · T1003.006 · T1133 · RBQL anomaly detection · Cobalt Strike beacon analysis | Medium |
| CelltronX Telecom — Proactive Assessment | MuddyWater targeting Israeli telecom — crown jewels analysis, 5 attack scenarios, detection gap mapping, 5 Sigma rules | T1219 · T1133 · T1505.003 · T1572 · DeTT&CT scoring · SimpleHelp RMM detection | — |
Each case study maps directly to a training assignment, a full technical walkthrough, and an ATT&CK Navigator layer:
- LifeTech Pharma: Case study · Technical walkthrough · Assignment A01 · ATT&CK Navigator layer
- CelltronX Telecom: Case study · Proactive walkthrough · Assignment A02
How CTI as a Code Fits
CTI as a Code is the practice environment. It provides:
- The Docker Compose lab stack where you run OpenCTI, TheHive, and Elastic SIEM
- The structured training assignments (A01–A08) as worked case studies
- Published case studies with full evidence analysis, detection gaps, and Sigma rules
- Distributed analytical files demonstrating the methodology in action
- Sigma rules derived from incident TTPs — ready for lab validation
The Field Manual is the reasoning standard behind everything. When CTI as a Code says "rate sources with the Admiralty Scale," "label claims," or "convert TTPs to detection logic" — the Field Manual explains the precise methodology those phrases refer to.
The Israel CTI knowledge base is the threat context for the NDSA narrative arc (A05–A08). The Iranian-nexus actor cluster, supply chain compromise patterns, and INCD regulatory context in those assignments are grounded in Israeli sector CTI documented there.
Cross-Project Workflows
Reactive Investigation → Sigma Rule → Lab Validation
- Read the LifeTech Pharma case study as a worked example of the full flow
- Run the same investigation yourself with Assignment A01 or A05 as the scenario
- Apply Field Manual — Evidence Labels and Source Reliability to each timeline event
- Convert findings to detection logic using Field Manual — CTI to Detection
- Deploy the Sigma rule to Elastic SIEM in the lab and validate with A04 or A08 emulation methodology
- Use HexStrike AI for adversarial red-team validation of coverage
Threat Modeling → Detection Backlog → Customer Project
- Use A02 or A06 as the proactive threat modeling framework
- Reference Israel Government Threat Actors CTI for sector-specific threat actor TTPs
- Produce a detection backlog with Sigma rules (CTI as a Code template structure)
- Hand off to Customer-Driven AI CTI Project for managed delivery with quality gates and customer acceptance criteria
CTI Program Build → INCD Compliance
- Use A07 (NDSA full-cycle program) as the governance framework template
- Apply Field Manual — PIR/SIR framework for requirement design
- Use A08 compliance report as the detection validation evidence format
- Cross-reference Israel Government Threat Actors CTI for INCD regulatory framework context
Actor Profile → Sector Context → Detection
- Use Field Manual — Actor Research to structure the actor profile
- Use Israel Government Threat Actors CTI for the Iranian-nexus cluster context relevant to A05–A08
- Extract detection-relevant TTPs using A04 TTP extraction methodology
- Turn the profile into a customer project with Customer-Driven AI CTI
NDSA Narrative Arc and the Israel CTI Project
The government assignments (A05–A08) are grounded in the Israeli public-sector threat landscape documented in the Israel Government Threat Actors CTI project:
| CTI as a Code | Israel CTI cross-reference |
|---|---|
| A05 — Iranian-nexus contractor breach | Iranian-nexus actor cluster targeting Israeli government digital identity systems |
| A06 — GovID 2.0 threat model | BiometricTech supply chain risk; vendor API abuse patterns |
| A07 — INCD regulatory program | INCD-CID framework; Israeli CII operator obligations |
| A08 — INCD Section 8 emulation | Detection validation methodology for Israeli government CTI programs |
Repository Links
- CTI Portfolio — full work index
- CTI as a Code
- CTI Analyst Field Manual
- Customer-Driven AI CTI Project
- Israel Government Threat Actors CTI
- HexStrike AI
Boundary
All CTI documentation projects (CTI as a Code, Field Manual, Customer project, Israel CTI) are defensive and public-source oriented. They do not provide exploit instructions, malware source code, leaked data, credentials, or unauthorized-access guidance. HexStrike AI is an authorized offensive security and penetration testing platform; use it only in authorized engagements.