Selected research · evidence first · full catalogue below

Selected Security Research

Actor profiles, tradecraft methodology, detection engineering, threat hunting, and sector intelligence. Structured repositories with evidence labels, confidence tiering, and detection-ready outputs. Published across Medium, GitHub, and the 1200km documentation ecosystem.

Ten evidence-backed starting points

Selected by method and reusable evidence, not recency

Each entry states the question, method, evidence boundary, finding, limitations, reusable artifacts, lifecycle, and date status. “Source-backed” means linked public sources exist; “lab-validated” means the documented workflow includes reproducible lab evidence. Neither label proves production effectiveness.

Operation Desert Hydra

Question: How can MuddyWater reporting be converted into a traceable CTI-to-detection workflow?

Operational relevance
Connects source review, ATT&CK mapping, detection engineering, and Kibana validation.
Method
Phased public-source analysis followed by OpenCTI graphing, rule development, and controlled lab validation.
Evidence
Repository, documentation, detection atlas, coverage matrix, and validation-result pages.
Principal finding
A documented evidence chain makes CTI-derived detection assumptions reviewable and testable.
Limitations
A bounded MuddyWater scenario and lab telemetry; not evidence of production detection rates.
Reusable artifacts
Queries, mappings, workflow phases, coverage records, and reproduction guidance.
Status / date
Released · lab-validated · authoritative update date not published; catalogue verified 2026-07-21.

AdversaryGraph case studies and validation

Question: Which CTI-to-detection workflows can be demonstrated with explicit evidence boundaries?

Operational relevance
Shows how analysts move from reports, indicators, malware, assets, and telemetry to reviewable outputs.
Method
Stepwise v6 workflows using sanitized demo data, screenshots, acceptance criteria, and analyst checks.
Evidence
Release documentation, screenshots, fixtures, and linked platform surfaces.
Principal finding
The platform supports repeatable investigation and validation paths while preserving human review.
Limitations
Examples do not prove compromise, attribution, customer adoption, or universal detection quality.
Reusable artifacts
Demo datasets, checklists, case-study procedures, and export paths.
Status / date
Maintained · release evidence · updated 2026-07-12.

Newest Detection Engineering Techniques

Question: What changes when detection engineering is treated as validated telemetry engineering?

Operational relevance
Frames detection as data quality, state, validation, and lifecycle management rather than isolated rules.
Method
Synthesis of telemetry-first, detection-as-code, cloud, runtime, data-lake, and AI-agent practices.
Evidence
Source-linked article, local companion page, figures, and related implementation paths.
Principal finding
Useful detection programmes connect observable behavior to testable data and controlled delivery.
Limitations
Research synthesis; techniques require environment-specific field and performance validation.
Reusable artifacts
Architecture patterns, validation questions, and links into detection workflows.
Status / date
Maintained · source-backed · updated 2026-07-11.

CTI as Code

Question: Can intelligence analysis be maintained as reviewable, version-controlled evidence and detection artifacts?

Operational relevance
Supports repeatable handoff between intelligence, hunting, detection, and incident-response roles.
Method
File-backed investigations, evidence registers, confidence labels, ATT&CK mappings, and lab workflows.
Evidence
Published documentation and repository artifacts for worked investigations and detections.
Principal finding
Version control makes analytical changes, assumptions, and derived detection content auditable.
Limitations
Training and reference workflow; operational governance must be adapted locally.
Reusable artifacts
Schemas, investigation structure, IOC triage, detection content, and review workflow.
Status / date
Maintained · lab-validated · authoritative update date not published; catalogue verified 2026-07-21.

CTI Analyst Field Manual

Question: Which analytical controls make actor research and CTI-to-detection work defensible?

Operational relevance
Provides a shared working reference for source handling, confidence, attribution, and detection handoff.
Method
Structured tradecraft guidance with worked examples and explicit evidence-quality controls.
Evidence
Source-backed manual, actor-research examples, and linked ATT&CK workflows.
Principal finding
Separating observations, assessments, and confidence reduces unsupported analytical certainty.
Limitations
A practice guide, not an intelligence standard or guarantee of attribution accuracy.
Reusable artifacts
Research questions, evidence labels, confidence language, and handoff checklists.
Status / date
Maintained · source-backed · authoritative update date not published; catalogue verified 2026-07-21.

Israel Government Threat Actors CTI

Question: How can public-source regional actor research remain source-traceable and operationally useful?

Operational relevance
Supports actor, infrastructure, malware, and TTP pivots for regional threat analysis.
Method
Public-source profiles, deep research reports, intelligence updates, and detection mappings.
Evidence
Maintained source repository and published report collection.
Principal finding
Separating source evidence from attribution judgment improves reuse and review.
Limitations
Open-source visibility is incomplete and changes over time; profiles are not attribution proof.
Reusable artifacts
Actor profiles, IOC context, report templates, and ATT&CK-oriented detection material.
Status / date
Maintained · source-backed · authoritative update date not published; catalogue verified 2026-07-21.

Identity Threat Detection and Response

Question: How do identity protocols, attack paths, detections, and simulations connect in one defensive reference?

Operational relevance
Connects Active Directory, Entra, SaaS, cloud identity, and certificate abuse to detection design.
Method
Protocol foundations, attack walkthroughs, detection guidance, and simulation scenarios.
Evidence
Checked-in documentation pages with ATT&CK references and explicit validation boundaries.
Principal finding
Identity detections require protocol semantics and telemetry prerequisites, not indicator matching alone.
Limitations
Reference material requires testing against the reader’s identity stack and logging configuration.
Reusable artifacts
Attack taxonomy, detection prerequisites, simulation scenarios, and lab architecture.
Status / date
Maintained · source-backed · updated 2026-06-14.

Anomaly Detection Atlas

Question: How should defenders describe and validate observable deviation without treating every anomaly as malicious?

Operational relevance
Supports behavioral detection design, baseline reasoning, and alert-triage expectations.
Method
Reference patterns linking observable change, data requirements, ATT&CK behavior, and validation questions.
Evidence
Source-backed atlas and detection-rule catalogue.
Principal finding
Anomaly value depends on baseline quality, context, and an explicit route to investigation.
Limitations
Patterns are reference designs, not calibrated production models.
Reusable artifacts
Detection patterns, feature questions, and validation checklists.
Status / date
Maintained · source-backed · authoritative update date not published; catalogue verified 2026-07-21.

Insider Threat Detection Engineering Guide

Question: How can insider-risk hypotheses be translated into observable, privacy-aware detection requirements?

Operational relevance
Supports behavior-focused detection while making data and interpretation limits visible.
Method
Threat scenarios, telemetry requirements, analytic patterns, and validation guidance.
Evidence
Source-backed guide and linked detection material.
Principal finding
Contextual, multi-signal reasoning is safer than treating one anomalous action as intent.
Limitations
Requires local legal, privacy, HR, and data-governance review.
Reusable artifacts
Hypotheses, telemetry maps, triage questions, and control boundaries.
Status / date
Maintained · source-backed · authoritative update date not published; catalogue verified 2026-07-21.

From Log to Report with AdversaryGraph

Question: How can noisy firewall and EDR records become a bounded CTI investigation and report?

Operational relevance
Demonstrates IOC extraction, enrichment, relationship review, ATT&CK leads, and reporting.
Method
Synthetic telemetry is processed through a stepwise AdversaryGraph investigation.
Evidence
Local case-study article with screenshots and explicit synthetic-data boundary.
Principal finding
A repeatable enrichment and review sequence makes noisy signals easier to qualify and communicate.
Limitations
Illustrative data and AI suggestions; no claim of real compromise or automatic verdict.
Reusable artifacts
Workflow sequence, enrichment tiers, graph-review steps, and report structure.
Status / date
Released · illustrative · updated 2026-07-21.

Flagship CTI Platform

AdversaryGraph

Turn threat reports into evidence-backed ATT&CK mappings, actor overlap analysis, interactive heatmaps, detection guidance, mitigation actions, and threat-hunting hypotheses. Use the browser-native explorer or deploy the AI-assisted Docker platform.

Documentation Sites

8 Docusaurus-style sites

Published · CTI Syllabus · 69 Defined Terms

Cyber Knowledge — CTI Zero to Hero

A structured, 10-module CTI course: foundations, the intelligence cycle, core frameworks (ATT&CK, Diamond Model, Pyramid of Pain, STIX/TAXII), collection, analytic tradecraft, the threat actor landscape, intelligence products, CTI-to-detection operationalization, tooling, and career path. Every module links to AdversaryGraph and Threat Matrix where the concept maps to a real platform feature, and cites the author's own published research inline. First domain of the wider Cyber Knowledge syllabus hub, covering red team, blue team, DFIR, cloud security, and more.

Published · Detection Engineering · Validated Telemetry

Newest Detection Engineering Techniques

Ecosystem companion page for the Medium article on telemetry-first detection engineering, detection-as-code validation, stateful identity correlation, risk-based alerting, cloud/SaaS data-plane coverage, CI/CD workflow detection, eBPF runtime telemetry, OCSF/data-lake architecture, and LLM/agent workflow telemetry. Includes all 25 article figures mirrored locally and linked into AdversaryGraph, Threat Matrix, and validation workflows.

Docusaurus-style · Published · Embedded / Firmware CTI

Embedded Systems, Hardware, Firmware

Full research page for the embedded, hardware, firmware, edge-appliance, BMC, UEFI, SOHO/IoT, OT/IoT, and silicon-level attack surface. Includes all article infographics, case-study context for Volt Typhoon, UNC3886, UNC5221, UNC4841, Sandworm, ArcaneDoor/FIRESTARTER, and inline links into AdversaryGraph, ATT&CK Matrix, CVE Library, asset-surface mapping, attack simulation, CTI methodology, and defensive validation workflows.

Docusaurus · Published

Operation Desert Hydra

Full AI-assisted CTI pipeline documentation: source gathering with review gate, procedure dataset, OpenCTI knowledge graph, detection atlas (11 detections with pseudologic and proof screenshots), validation lab architecture, coverage matrix, and production scars. One-command reproducible lab.

Docusaurus · Published

CTI Analyst Field Manual

Practitioner operating manual covering the full CTI-to-detection chain. Evidence labels, source reliability, confidence language, attribution methodology, infrastructure pivoting, AI-assisted workflows, and detection candidate mapping. 80+ pages across 10 modules. Readiness score 8.8/10.

Docusaurus · Published

Customer-Driven AI CTI Project

End-to-end methodology for delivering structured CTI engagements with AI assistance. Scoping, collection, analysis, and delivery phases. Human validation gates throughout. Includes Phase 1 Foundations, Phase 2A Execution Guide, and Phase 2B Reference Toolkit.

Docusaurus · Published

Israel Government Threat Actors CTI

Blue-team defensive CTI repository: public-source reporting on threat actors, personas, malware families, TTPs, and detection opportunities relevant to Israeli government, public-sector, critical infrastructure, and adjacent suppliers. Iranian, Palestinian, and regional activity clusters with ATT&CK mappings.

Docusaurus · Published · Lab + Training

CTI as a Code

Full CTI analyst lab and structured methodology framework on Docker Compose. Eight training assignments (reactive, proactive, full-cycle, adversary emulation) across private-sector and government scenarios. Includes published case studies, Sigma rules, evidence files, and the complete step-by-step reactive investigation methodology.

Docusaurus · Published

The Intelligent Shield — OpenCTI

Complete deployment guide for an AI-powered CTI platform on OpenCTI with STIX 2.1. Free, commercial, and ISAC feed integration. Custom Claude AI enrichment connector with automated entity extraction and STIX relationship writing. Inference rules, 9-step security hardening, monitoring, and real investigation workflows with all 31 article screenshots placed in context.

Docusaurus · Published · Self-Hosted Tool · v0.4.0

AdversaryGraph

Self-hosted AI-assisted CTI platform. Upload a threat report, paste logs or PCAP-derived telemetry, investigate IOCs through Tier 1/Tier 2/Tier 3 pivots, and get ATT&CK technique extraction with evidence, actor/campaign overlap scoring, relationship graph review, OpenCTI sync, and PDF reports.

Web Tool · No install · Browser-native

Threat Matrix

Pure browser-based MITRE ATT&CK explorer across four frameworks — Enterprise, Mobile, ICS, and ATLAS (AI/ML) — no server, no Docker, no LLM required. Domain switcher in the header; each framework loads on demand and is cached for instant re-switching. Current-release threat-actor and ATLAS case-study library, TTP selection and overlay, Jaccard-similarity comparison, Group vs Group overlap analysis, and one-click report export (JSON / CSV / PDF). Every technique ID opens a detail panel with the full MITRE description and section-level deep-links into the CTI Field Manual and ITDR Handbook — jumping directly to the paragraph in the article that mentions the technique.

Git Repositories

12 repos
CTI_as_a_Code
lab training methodology

Full CTI analyst lab — Docker Compose stack with OpenCTI, TheHive, Elastic SIEM, and Cortex. Eight structured assignments, 194 analytical files, methodology templates, and Sigma rules. Includes the published LifeTech Pharma reactive investigation case study.

operation-desert-hydra
MuddyWater Elastic OpenCTI

AI-assisted CTI pipeline: 8 promoted public sources → OpenCTI 6.2 knowledge graph → 11 ATT&CK-mapped detection rules → Ansible-validated Kibana screenshots. Sysmon + Winlogbeat on Vagrant Windows 10 VM. Docusaurus documentation site. One-command deploy: bash start.sh.

CTI
reports evidence

Evidence-labeled cyber threat intelligence reports built for analysts, SOC leads, and detection engineers. Each report carries explicit confidence discipline — what is Observed, Reported, Assessed, or Inferred. Outputs: PDF reports, pivoting notes, detection candidates.

CTI Detection Pack
detection Sigma YARA

Detection artifacts derived from CTI reports, malware-analysis output, and threat-hunting articles. Explicit report → hypothesis → detection → validation handoff. Includes Sigma rules, YARA signatures, ATT&CK Navigator layers, IOC sets, and hunt queries.

CTI Enrichment Tool
Python VirusTotal Neo4j

Modular pipeline: extract public IPs from logs → enrich with VirusTotal → compute deterministic risk scores → build entity graph → load into Neo4j → run graph queries. Config-driven, per-step JSON outputs. Optional in-memory graph and browser visualization.

CTI MCP Server
MCP Claude 15-phase

Model Context Protocol server implementing a 15-phase CTI production cycle inside Claude. Human validation gates after every phase; formal quality-gate sign-off at six milestones. Claude cannot silently advance the workflow — each phase returns a STOP + analyst checklist. Integrates VirusTotal and MISP.

CTI in the AI Era
learning path FOR578-derived

Complete CTI learning path derived from FOR578 structure and adapted for modern AI-assisted workflows. Weekly schedule, capstone guide, and original instructional material. Does not redistribute SANS courseware — designed to complement licensed study.

Threat Hunting Hypotheses
hunting KQL Splunk

Structured hunting hypotheses extracted from CTI and threat-hunting research. Each hypothesis carries data sources, query logic (Splunk SPL + KQL), false-positive notes, and ATT&CK technique mapping.

Cloud Identity Kill Chain
cloud SaaS detection

Reproducible detection engineering research for cloud identity and SaaS intrusions. Uses fully synthetic telemetry — no real tenants, tokens, or users. Each scenario: problem → real-world CTI evidence (Mandiant, IBM X-Force, Unit 42, CISA) → synthetic lab scenario + detection rules.

Israel Gov. Threat Actors CTI
threat actors blue team

Source repository for the deployed Docusaurus site. Actor and persona profiles, ATT&CK mappings, IOC reference locations, and detection examples. Intentionally blue-team only — no binaries, leaked data, or exploit code. GitHub Actions CI validates links and structure.

Customer-Driven AI CTI Project
Docusaurus methodology

Source repository for the Customer-Driven AI CTI Project Docusaurus site. Contains the full methodology, article series content, and cross-links to the CTI Analyst Field Manual. Published entry point: Medium series overview + Docusaurus documentation site.

CTI Analyst Field Manual
Docusaurus 80+ pages

Source repository for the CTI Analyst Field Manual Docusaurus site. 80 source markdown files across 10 modules: foundations, analytic discipline, frameworks, attribution, infrastructure pivoting, actor research, sector CTI, CTI-to-detection, AI-assisted CTI, and templates. CI: GitHub Actions link check + build.

Actor Research & Profiles

5 articles
CTI Research: Handala Hack Group

Full actor profile — aliases, attribution, claimed operations, TTPs, malware families, and detection opportunities for the Handala Hack Team hacktivist cluster.

hacktivistIran-linkedIsrael-targeting
CTI Research: Sandworm / APT44

Profile of Sandworm (APT44 / FROZENBARENTS): destructive operations, wiper malware families, ICS/OT targeting, and Ukraine conflict-related activity.

Russia-stateGRUdestructive
CTI Research: MuddyWater / Seedworm (Mango Sandstorm)

Profile of MuddyWater: MOIS-linked actor, RMM tool abuse, spear-phishing tradecraft, persistent access methodology, and detection candidates.

Iran-stateMOISMiddle East
CTI Research: Kubernetes & Cloud-Native Threat Landscape

Structured threat landscape assessment for container and Kubernetes environments: tracked actor activity, common TTPs, and detection priorities.

cloudKubernetesthreat landscape
APT41 Targeting Pharmaceutical Sector: Log4Shell to Domain Compromise

CTI report underpinning Operation DragonRx: APT41 initial access via Log4Shell, lateral movement to Active Directory, credential harvesting, and detection hypotheses.

APT41China-nexuspharma

CTI Tradecraft & Methodology

8 articles
CTI as a Code — Complete Step-by-Step Methodology

End-to-end reactive and proactive CTI methodology: version-controlled investigations, evidence-traced claims, ATT&CK gap mapping, and Sigma rule derivation. From first alert to deployed detection.

methodologyreactiveproactiveSigma
CTI as a Code in Practice — LifeTech Pharma Reactive Investigation

Worked case study: dual-entry pharmaceutical IP theft — AiTM credential theft, DCSync, 381 MB formula exfiltration, 0/12 detection coverage. Full VS Code investigation walkthrough with real RBQL queries and Cobalt Strike sandbox analysis.

Iranian-nexuscase studyworked exampleDCSync
CTI Analyst Field Manual — Complete Reference

Full tradecraft reference: evidence labeling, source reliability, confidence tiering, attribution methodology, infrastructure pivoting, and detection candidate mapping.

tradecraftfield manual
CTI Kill Chain: An Analyst Guide With Real-World Evidence

Applying kill chain analysis to real adversary behavior — evidence labeling at each stage with worked examples drawn from public reporting.

kill chaintradecraft
ATT&CK as a Working Tool: Theory and Hands-On Practical Usage

Moving beyond the matrix: technique selection, sub-technique context, ATT&CK Navigator usage, and detection hypothesis construction from real reports.

ATT&CKMITRE
Tools by MITRE ATT&CK Guide

Tool-to-technique mapping reference: which adversary tools map to which ATT&CK techniques, how to use this for detection prioritization.

ATT&CKtooling
Threat Matrix — Interactive ATT&CK Explorer ↗

Browser-native ATT&CK workspace: select techniques, compare TTP overlap with current group profiles, review detection gaps, and export analyst-ready outputs.

toolATT&CKAPT comparison
Attribution Methodology: How to Build, Defend, and Challenge

Structured approach to attribution: evidence strength ladder, false-flag considerations, confidence levels, and how to defend attribution claims under scrutiny.

attributionmethodology
Infrastructure Pivoting: Single IOC to Full Attacker Network

Passive DNS, certificate transparency, ASN/hosting pivots, and JARM/JA3 fingerprinting — turning one IOC into a defensible infrastructure cluster.

pivotingpassive DNSIOC
Applying Sherman Kent's Analytic Discipline to CTI

Words of estimative probability, source critique, assumption tracking, and cognitive bias mitigation applied to practical CTI production.

analytic disciplineSherman Kent
Manual CTI vs. AI-Assisted CTI: Step-by-Step Clock Comparison

Side-by-side workflow timing: same CTI task completed manually vs. with AI assistance — where time is saved, where analyst judgment remains irreplaceable.

AIworkflow

Detection Engineering

8 articles
Newest Detection Engineering Techniques: From Rules to Validated Security Telemetry

Local 1200km ecosystem page for telemetry-first detection, detection-as-code validation, stateful correlation, risk-based alerting, cloud/SaaS data-plane coverage, CI/CD, eBPF runtime telemetry, OCSF/data-lake architecture, and LLM/agent detection.

validated telemetrydetection engineeringAI-era
From Threat Intelligence to Detection: A Practitioner's Guide

End-to-end workflow: actor assessment → TTP extraction → detection candidate → hunting hypothesis → backlog item → production rule.

CTI-to-detectionworkflow
The Atomic Standard: Compendium for Single-Event Threat Detection

Practitioner reference for building and evaluating atomic detection rules — coverage gaps, noise thresholds, and the tradeoffs between specificity and recall.

detectionatomic rules
Single-Event Detection Rules in Cybersecurity

When and how to write single-event rules: signal strength requirements, false-positive budgets, and integration with correlation layers.

detectionrules
Correlation-Based Detection Rules: Atomic Events to Behavioral Insight

Stacking atomic signals into behavioral patterns — temporal windows, entity pivots, and MITRE ATT&CK tactic-level correlation logic.

detectioncorrelation
What AI-Assisted Offensive Work Means for Your Detection Program

Practitioner analysis: how AI-augmented offensive operations change attacker tempo, tradecraft diversity, and the assumptions underlying existing detection coverage.

AIdetection
Malicious Activity as a Statistical Signal: Anomaly-Based Detection

Framing detection as statistical inference — baseline construction, drift detection, and reducing false-positive rates in anomaly-based rules.

detectionanomaly
Detecting Malicious Insider Activity: Technical Detection Engineering Guide

Data source requirements, behavioral baselines, and detection logic for identifying malicious insider patterns across endpoint, identity, and data-access telemetry.

detectioninsider threat

Threat Hunting

3 articles
Threat Hunting with the Pyramid of Pain

Using the Pyramid of Pain to prioritize hunt targets — moving from hash-based detection toward behavioral and TTP-level hunting with practical examples.

pyramid of painhunting
Protocol-Level Network Threat Hunting: A Wireshark-Centric Guide

Wireshark-driven hunt methodology: protocol anomalies, C2 communication patterns, DNS tunneling indicators, and SSL/TLS fingerprinting in captured traffic.

networkWiresharkhunting
Endpoint Threat Hunting: Windows, Linux, and macOS

Platform-specific hunt playbooks: process genealogy analysis, persistence mechanism review, and lateral movement artifacts across Windows, Linux, and macOS endpoints.

endpointWindowsLinux

Threat Landscape & Sector Intelligence

7 articles
Comprehensive Cyber Intelligence Research: Attacks Against Embedded Systems, Hardware, Firmware

Full ecosystem page for the source-verified Medium research on edge appliances, firmware, BMCs, UEFI, SOHO routers, OT/IoT devices, silicon-level vulnerabilities, and hardware trust boundaries. Connects Volt Typhoon, UNC3886, UNC5221, UNC4841, Sandworm, ArcaneDoor/FIRESTARTER, KEV/CVE pressure, and defensive collection requirements.

embedded systemsfirmwareedge appliancesBMC / UEFICTI research
Cyberattacks on 4G/LTE Telecom Networks: Threat Mapping and Defense

Protocol-level threat mapping for 4G/LTE infrastructure: GTP exploitation, SS7 abuse, and defensive controls for cellular network operators.

telecom4G/LTE
Cyberattacks on 5G Telecom Networks: Threat Mapping and Defense

5G-specific threat landscape: network slicing attacks, SBA exposure, O-RAN security considerations, and detection priorities for 5G operators.

telecom5G
CTI-Led Defensive Strategy for a Cellular Provider: Case Study

Applied case study: translating telecom threat intelligence into a prioritized defensive roadmap for a cellular provider — from threat model to detection backlog.

telecomcase study
Cloud-Native Security Threats, Attacks, and Detection Strategies

Container and Kubernetes threat landscape: supply chain risks, runtime attacks, lateral movement in ephemeral environments, and cloud-native detection approaches.

cloudKubernetesthreat landscape
AI in Offensive Operations: How Threat Actors Use AI

Evidence-based assessment of AI adoption in offensive tradecraft: phishing automation, malware generation, reconnaissance acceleration, and the detection implications.

AI threatsoffense
AI Offensive Security: Practical Attacks Against LLM Agents

Prompt injection, data exfiltration via LLM agents, tool-call manipulation, and the emerging attack surface introduced by agentic AI deployments.

LLM securityAI attacks

Operation Desert Hydra

MuddyWater CTI pipeline · 1 article · 1 site · 1 repo
Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana

Full end-to-end pipeline: 8 promoted public sources on MuddyWater (Iranian MOIS) → AI-deduplicated source register (71 → 8) → OpenCTI 6.2 knowledge graph → 11 ATT&CK-mapped detection rules → Ansible-validated Kibana proof screenshots. 13 PASS / 1 PARTIAL / 1 FAIL across 16 rule checks.

CTI pipelinedetection engineeringAI-assistedMuddyWater
Operation Desert Hydra — Docusaurus Documentation Site

Full pipeline documentation: Phase 1 source gathering with review gate, Phase 2 procedure dataset, Phase 3 OpenCTI graph, Phase 4 detection atlas (all 11 detections with pseudologic), Phase 5 validation lab with lab architecture, Phase 6 coverage matrix, and production scars.

CTI-to-detectionOpenCTIKibana
operation-desert-hydra
MuddyWater Elastic OpenCTI

AI-assisted CTI pipeline — public-source MuddyWater intelligence through OpenCTI knowledge graph to 11 validated Kibana detections. Vagrant Windows 10 VM + Ansible + Sysmon + Winlogbeat. One-command reproducible lab: bash start.sh.

Operation DragonRx

APT41 simulation · 2 articles · 1 repo
Lab Architecture — Operation DragonRx

Infrastructure design for the APT41 simulation: target network topology, Sliver C2 setup, Wazuh + Zeek + Elastic detection stack, and isolation controls.

APT41labarchitecture
Attack Playbook — Operation DragonRx

Step-by-step attack execution: Log4Shell initial access → Sliver C2 implant → AD lateral movement → LSASS dump → detection trigger analysis.

APT41playbookLog4Shell
dragonrx-lab
APT41 Log4Shell Wazuh

Full-stack APT41 pharmaceutical-sector simulation lab. Log4Shell (CVE-2021-44228) initial access, Sliver C2, Active Directory lateral movement, LSASS credential dump, dual detection layer with Wazuh + Zeek + Elastic. Includes attack playbook and CTI report.

Customer-Driven AI CTI Project Series

4 articles
Customer-Driven AI CTI Project — Overview

Introduction to the methodology: what a structured client-facing CTI engagement looks like, and how AI tooling fits inside a controlled analyst workflow.

AICTI methodology
Customer-Driven AI CTI Project Template — Part 1: Foundations

Project charter, scope definition, stakeholder requirements, and the evidence and confidence framework that governs the entire engagement.

AIfoundations
Customer-Driven AI CTI Project Template — Part 2A: Execution Guide

Phase-by-phase walkthrough: collection, enrichment, analysis, and reporting with explicit human validation checkpoints at each stage.

AIexecution
Customer-Driven AI CTI Project Template — Part 2B: Reference Toolkit

Templates, prompt library, quality gates, output artifact formats, and the cross-reference map tying the methodology to the CTI Analyst Field Manual.

AItemplatestoolkit