Andrey Pautov

CTI-to-detection practitioner. Threat Intelligence Research Engineer. AI security tooling builder.

Public contact is available by phone, email, LinkedIn, and GitHub.

Professional Summary

I am a cybersecurity researcher and CTI-to-detection practitioner focused on turning threat intelligence, adversary behavior, and security telemetry into evidence-based defensive outputs.

My work connects Cyber Threat Intelligence, detection engineering, threat hunting, log analytics, ATT&CK mapping, OpenCTI workflows, malware analysis, cloud/Kubernetes security, and AI-assisted analyst workflows.

My public portfolio includes Medium research, GitHub tools, and Docusaurus field guides focused on practical CTI outcomes: evidence-labeled reports, actor profiles, infrastructure pivoting, hunting hypotheses, detection backlog items, SOC handoff notes, executive summaries, and reusable analyst templates.

Professional Experience

Threat Intelligence Research Engineer

May 2025 – Present

XPLG — Enterprise Security Data Platform · Tel Aviv, Israel

  • Maps adversary TTPs (Iran-nexus campaigns, hacktivist clusters, cloud-native threats) to XPLG platform telemetry fields; ships log-based detection use cases covering endpoint, network, cloud audit log, and IOC-enrichment sources.
  • Translates CTI assessments into Sigma/YARA-compatible detection content, hunting hypotheses, and ATT&CK coverage logic; raises platform technique coverage for priority threat actors.
  • Builds and documents CTI enrichment workflows covering parser field mapping, anomaly detection logic, and structured threat reporting pipelines used by security operations teams.

Head of Red Team — Cyber Defence Unit

Jul 2023 – May 2025

Israel Police, Cyber Defence Unit · Jerusalem, On-site

  • Directed red-team engagements against national law-enforcement infrastructure: reconnaissance, vulnerability chaining, privilege escalation, lateral movement, and attack-path validation in sensitive operational environments.
  • Converted offensive findings into structured defensive intelligence: detection hypotheses mapped to observed attacker behavior, telemetry coverage gap analysis, hardening recommendations, and incident response runbooks converted into deployed detections.
  • Produced adversary behavior research and hands-on lab environments used by blue team and SOC personnel for detection development and threat hunting training.

Operator — Special Reconnaissance and AntiTerror Unit

2016 – 2023

Israel Ministry of Public Security · Israel

  • Served 7 years as operator and fighter-paramedic in a special reconnaissance unit conducting field operations in high-threat environments.
  • Developed deep understanding of adversary tactics, operational security, and mission planning under real-world conditions — experience that directly shapes current threat actor profiling and red-team methodology.

Independent Cybersecurity Researcher & Technical Author

Oct 2024 – Present

Self-employed · Israel, Remote · concurrent with full-time roles above

  • Publishes CTI research and detection-engineering field guides at 1200km.com, including evidence-labeled threat actor profiles, infrastructure-pivoting methodology, and ATT&CK-mapped detection tradecraft.
  • Built and ships AdversaryGraph, a self-hosted CTI-to-detection platform, plus AIDebug, AuditAI, and String-Analyzer — three tools accepted into the Kali Linux 2026.2 distribution, with 8 additional contributions accepted upstream across MISP Galaxy and other open-source security projects.

Skills

CTI Tradecraft ATT&CK Navigator · passive DNS · OSINT pivoting · IOC relationship graphs · Tier 1/2/3 pivots · confidence tiering · PIR/SIR frameworks · kill chain reconstruction · attribution methodology · crt.sh · MITRE D3FEND
Detection Engineering Sigma · YARA · YARA-L · hunting hypothesis development · telemetry field mapping · ATT&CK coverage analysis · detection backlog construction · log/PCAP use case design · SIEM / XDR rule logic
Malware Analysis Capstone · FLIRT · Frida · INetSim · LIEF · static PE/ELF analysis · APK analysis · CFG extraction · behavioral pattern detection · import table triage
Cloud Security AWS CloudTrail · GCP Audit Log · Kubernetes threat modeling · ECS Fargate · Cloud Run · Terraform · attack simulation · container attack paths
Offensive Security Deep knowledge — red-team operations · reconnaissance · vulnerability chaining · privilege escalation · lateral movement · adversary simulation · attack-path validation
CTI Platforms & Tooling OpenCTI · STIX 2.1 · TAXII · MISP · connector engineering · VirusTotal · OTX · ThreatFox · Malpedia · urlscan · GreyNoise · AbuseIPDB · Shodan · Censys · NVD API · CISA KEV · EPSS · Python · Bash · C/C++ · PowerShell · Linux · Docker

Open-Source Tooling & Validation

  • AdversaryGraph — self-hosted CTI-to-detection workbench. IOC investigation → Tier 1/2/3 relationship expansion → ATT&CK/ATLAS mapping → detection candidate → SIEM validation, in one loop. GitHub · Docs · Use-case article
  • OpenCTI symmetric sync, MISP/STIX/TAXII import/export, nine enrichment sources (VirusTotal, OTX, ThreatFox, Malpedia, urlscan, GreyNoise, AbuseIPDB, Shodan, Censys), enterprise RBAC and MFA, and a CVE Library with NVD/CISA KEV correlation.
  • AIDebug, AuditAI, String-Analyzer — analyst tooling for malware static triage, function-level disassembly explanation, code auditing, and string extraction. Three tools accepted into the Kali Linux 2026.2 distribution by the Kali maintainer (g0tmi1k); 8 additional contributions accepted upstream across MISP Galaxy, security resource collections, and Kali packaging.

Research & Publications

Certifications, Earlier Career & Languages

  • 120+ completed courses and certificates in cybersecurity, threat intelligence, and detection engineering.
  • ICU Paramedic — Magen David Adom (2011–2016).
  • Languages: Russian — native · Hebrew — bilingual · English — professional working proficiency.