Published · CTI Syllabus · 69 Defined Terms
Cyber Knowledge — CTI Zero to Hero
A structured, 10-module CTI course: foundations, the intelligence cycle, core frameworks
(ATT&CK, Diamond Model, Pyramid of Pain, STIX/TAXII), collection, analytic tradecraft,
the threat actor landscape, intelligence products, CTI-to-detection operationalization,
tooling, and career path. Every module links to AdversaryGraph and Threat Matrix where the
concept maps to a real platform feature, and cites the author's own published research
inline. First domain of the wider Cyber Knowledge syllabus hub, covering red team, blue
team, DFIR, cloud security, and more.
Published · Detection Engineering · Validated Telemetry
Newest Detection Engineering Techniques
Ecosystem companion page for the Medium article on telemetry-first detection engineering,
detection-as-code validation, stateful identity correlation, risk-based alerting,
cloud/SaaS data-plane coverage, CI/CD workflow detection, eBPF runtime telemetry,
OCSF/data-lake architecture, and LLM/agent workflow telemetry. Includes all 25 article
figures mirrored locally and linked into AdversaryGraph, Threat Matrix, and validation workflows.
Docusaurus-style · Published · Embedded / Firmware CTI
Embedded Systems, Hardware, Firmware
Full research page for the embedded, hardware, firmware, edge-appliance, BMC, UEFI,
SOHO/IoT, OT/IoT, and silicon-level attack surface. Includes all article infographics,
case-study context for Volt Typhoon, UNC3886, UNC5221, UNC4841, Sandworm, ArcaneDoor/FIRESTARTER,
and inline links into AdversaryGraph, ATT&CK Matrix, CVE Library, asset-surface mapping,
attack simulation, CTI methodology, and defensive validation workflows.
Docusaurus · Published
Operation Desert Hydra
Full AI-assisted CTI pipeline documentation: source gathering with review gate, procedure dataset,
OpenCTI knowledge graph, detection atlas (11 detections with pseudologic and proof screenshots),
validation lab architecture, coverage matrix, and production scars. One-command reproducible lab.
Docusaurus · Published
CTI Analyst Field Manual
Practitioner operating manual covering the full CTI-to-detection chain. Evidence labels,
source reliability, confidence language, attribution methodology, infrastructure pivoting,
AI-assisted workflows, and detection candidate mapping. 80+ pages across 10 modules.
Readiness score 8.8/10.
Docusaurus · Published
Customer-Driven AI CTI Project
End-to-end methodology for delivering structured CTI engagements with AI assistance.
Scoping, collection, analysis, and delivery phases. Human validation gates throughout.
Includes Phase 1 Foundations, Phase 2A Execution Guide, and Phase 2B Reference Toolkit.
Docusaurus · Published
Israel Government Threat Actors CTI
Blue-team defensive CTI repository: public-source reporting on threat actors, personas,
malware families, TTPs, and detection opportunities relevant to Israeli government,
public-sector, critical infrastructure, and adjacent suppliers. Iranian, Palestinian,
and regional activity clusters with ATT&CK mappings.
Docusaurus · Published · Lab + Training
CTI as a Code
Full CTI analyst lab and structured methodology framework on Docker Compose. Eight training
assignments (reactive, proactive, full-cycle, adversary emulation) across private-sector
and government scenarios. Includes published case studies, Sigma rules, evidence files,
and the complete step-by-step reactive investigation methodology.
Docusaurus · Published
The Intelligent Shield — OpenCTI
Complete deployment guide for an AI-powered CTI platform on OpenCTI with STIX 2.1.
Free, commercial, and ISAC feed integration. Custom Claude AI enrichment connector
with automated entity extraction and STIX relationship writing. Inference rules,
9-step security hardening, monitoring, and real investigation workflows with all
31 article screenshots placed in context.
Docusaurus · Published · Self-Hosted Tool · v0.4.0
AdversaryGraph
Self-hosted AI-assisted CTI platform. Upload a threat report, paste logs or PCAP-derived telemetry,
investigate IOCs through Tier 1/Tier 2/Tier 3 pivots, and get ATT&CK technique extraction with
evidence, actor/campaign overlap scoring, relationship graph review, OpenCTI sync, and PDF reports.
Web Tool · No install · Browser-native
Threat Matrix
Pure browser-based MITRE ATT&CK explorer across four frameworks — Enterprise, Mobile, ICS,
and ATLAS (AI/ML) — no server, no Docker, no LLM required. Domain switcher in the header;
each framework loads on demand and is cached for instant re-switching.
Current-release threat-actor and ATLAS case-study library, TTP selection and
overlay, Jaccard-similarity comparison, Group vs Group overlap analysis, and one-click report
export (JSON / CSV / PDF). Every technique ID opens a detail panel with the full MITRE
description and section-level deep-links into the CTI Field Manual and ITDR Handbook —
jumping directly to the paragraph in the article that mentions the technique.