CTI-to-detection practitioner. Threat Intelligence Research Engineer.
CTI-to-detection practitioner. Threat Intelligence Research Engineer.
Tel Aviv, Israel · +972-542-553-383 · 1200km@gmail.com · 1200km.com · linkedin.com/in/andrey-pautov · github.com/anpa1200 · medium.com/@1200km
CTI-to-detection analyst across government cyber defence (Israel Police Cyber Defence Unit) and commercial security engineering (XPLG). Profiles adversary infrastructure, reconstructs kill chains, and maps TTPs to ATT&CK-aligned detection candidates. Builds tooling to automate the mechanical parts of CTI triage, malware analysis, and cloud attack simulation.
Strong offensive security background grounded in real operational environments — 7 years in a special reconnaissance unit (Israel Ministry of Public Security, 2016–2023) and 2 years leading red-team operations against national law-enforcement infrastructure. Offensive experience directly informs detection engineering depth: adversary behavior understood from the inside out.
Published 150+ articles and 8 Docusaurus field guides on CTI tradecraft, detection engineering, malware analysis, and cloud security — all collected at 1200km.com.
XPLG — Enterprise Security Data Platform · Tel Aviv, Israel
Israel Police — יחידת הגנת הסייבר · Jerusalem, On-site
Israel Ministry of Public Security · Israel
Self-employed · Israel, Remote
CTI-to-detection analyst across government cyber defence (Israel Police Cyber Defence Unit) and commercial security engineering (XPLG). Profiles adversary infrastructure, reconstructs kill chains, and maps TTPs to ATT&CK-aligned detection candidates. Strong offensive security background grounded in real operational environments — 7 years in a special reconnaissance unit (Israel Ministry of Public Security, 2016–2023) and 2 years leading red-team operations against national law-enforcement infrastructure. Adversary behavior understood from the inside out. Published 150+ articles and 8 field guides on CTI tradecraft, detection engineering, and cloud security.
| CTI Tradecraft | ATT&CK Navigator · passive DNS · OSINT pivoting · confidence tiering · PIR/SIR · kill chain reconstruction · attribution methodology · Shodan · Censys · crt.sh · MITRE D3FEND |
| Detection Engineering | Sigma · YARA · hunting hypothesis development · telemetry field mapping · detection backlog · SIEM / XDR rule logic · log-based use case design |
| Malware Analysis | Capstone · FLIRT · Frida · INetSim · LIEF · static PE/ELF/APK analysis · CFG extraction · behavioral pattern detection · import table triage |
| Cloud Security | AWS CloudTrail · GCP Audit Log · Kubernetes threat modeling · ECS Fargate · Cloud Run · Terraform · attack simulation · container attack paths |
| Offensive Security | Deep knowledge — red-team operations · reconnaissance · vulnerability chaining · privilege escalation · lateral movement · adversary simulation · attack-path validation |
| Platforms & Languages | OpenCTI · STIX 2.1 · MISP · NVD API · CISA KEV · EPSS · Python · Bash · C/C++ · PowerShell · Linux |
120+ professional certifications across threat intelligence, detection engineering, malware analysis, cloud security, and offensive security. ICU Paramedic — Magen David Adom (2011–2016). Languages: Russian — native · Hebrew — bilingual · English — professional working proficiency.