Andrey Pautov
CTI-to-detection practitioner. Threat Intelligence Research Engineer. AI security tooling builder.
Public contact is available by phone, email, LinkedIn, and GitHub.
Professional Summary
I am a cybersecurity researcher and CTI-to-detection practitioner focused on turning threat intelligence, adversary behavior, and security telemetry into evidence-based defensive outputs.
My work connects Cyber Threat Intelligence, detection engineering, threat hunting, log analytics, ATT&CK mapping, OpenCTI workflows, malware analysis, cloud/Kubernetes security, and AI-assisted analyst workflows.
My public portfolio includes Medium research, GitHub tools, and Docusaurus field guides focused on practical CTI outcomes: evidence-labeled reports, actor profiles, infrastructure pivoting, hunting hypotheses, detection backlog items, SOC handoff notes, executive summaries, and reusable analyst templates.
Professional Experience
Threat Intelligence Research Engineer
May 2025 – PresentXPLG — Enterprise Security Data Platform · Tel Aviv, Israel
- Maps adversary TTPs (Iran-nexus campaigns, hacktivist clusters, cloud-native threats) to XPLG platform telemetry fields; ships log-based detection use cases covering endpoint, network, cloud audit log, and IOC-enrichment sources.
- Translates CTI assessments into Sigma/YARA-compatible detection content, hunting hypotheses, and ATT&CK coverage logic; raises platform technique coverage for priority threat actors.
- Builds and documents CTI enrichment workflows covering parser field mapping, anomaly detection logic, and structured threat reporting pipelines used by security operations teams.
Head of Red Team — Cyber Defence Unit
Jul 2023 – May 2025Israel Police, Cyber Defence Unit · Jerusalem, On-site
- Directed red-team engagements against national law-enforcement infrastructure: reconnaissance, vulnerability chaining, privilege escalation, lateral movement, and attack-path validation in sensitive operational environments.
- Converted offensive findings into structured defensive intelligence: detection hypotheses mapped to observed attacker behavior, telemetry coverage gap analysis, hardening recommendations, and incident response runbooks converted into deployed detections.
- Produced adversary behavior research and hands-on lab environments used by blue team and SOC personnel for detection development and threat hunting training.
Operator — Special Reconnaissance and AntiTerror Unit
2016 – 2023Israel Ministry of Public Security · Israel
- Served 7 years as operator and fighter-paramedic in a special reconnaissance unit conducting field operations in high-threat environments.
- Developed deep understanding of adversary tactics, operational security, and mission planning under real-world conditions — experience that directly shapes current threat actor profiling and red-team methodology.
Independent Cybersecurity Researcher & Technical Author
Oct 2024 – PresentSelf-employed · Israel, Remote · concurrent with full-time roles above
- Publishes CTI research and detection-engineering field guides at 1200km.com, including evidence-labeled threat actor profiles, infrastructure-pivoting methodology, and ATT&CK-mapped detection tradecraft.
- Built and ships AdversaryGraph, a self-hosted CTI-to-detection platform, plus AIDebug, AuditAI, and String-Analyzer — three tools accepted into the Kali Linux 2026.2 distribution, with 8 additional contributions accepted upstream across MISP Galaxy and other open-source security projects.
Skills
Open-Source Tooling & Validation
- AdversaryGraph — self-hosted CTI-to-detection workbench. IOC investigation → Tier 1/2/3 relationship expansion → ATT&CK/ATLAS mapping → detection candidate → SIEM validation, in one loop. GitHub · Docs · Use-case article
- OpenCTI symmetric sync, MISP/STIX/TAXII import/export, nine enrichment sources (VirusTotal, OTX, ThreatFox, Malpedia, urlscan, GreyNoise, AbuseIPDB, Shodan, Censys), enterprise RBAC and MFA, and a CVE Library with NVD/CISA KEV correlation.
- AIDebug, AuditAI, String-Analyzer — analyst tooling for malware static triage, function-level disassembly explanation, code auditing, and string extraction. Three tools accepted into the Kali Linux 2026.2 distribution by the Kali maintainer (g0tmi1k); 8 additional contributions accepted upstream across MISP Galaxy, security resource collections, and Kali packaging.
Research & Publications
- From Log to Report: Using AdversaryGraph to Turn Firewall and EDR Noise Into a CTI Investigation — AI log analysis, IOC extraction, Tier 1/2/3 investigation, relationship graph review, and report generation. Jun 2026
- MuddyWater / Seedworm / Mango Sandstorm — ATT&CK-mapped kill chain, infrastructure pivot, detection candidates. Mar 2026
- Infrastructure Pivoting: IOC to Actor Network — Passive DNS, reverse IP, ASN reuse, TLS cert, WHOIS field manual. Mar 2026
- ATT&CK as a Working Tool — Gap analysis, Sigma mapping, adversary emulation beyond compliance. Mar 2026
Certifications, Earlier Career & Languages
- 120+ completed courses and certificates in cybersecurity, threat intelligence, and detection engineering.
- ICU Paramedic — Magen David Adom (2011–2016).
- Languages: Russian — native · Hebrew — bilingual · English — professional working proficiency.