- ThreatMapper: I Built a Self-Hosted AI Threat Intelligence Platform Medium · Jun 7, 2026
- CTI as a Code in Practice: Reactive Investigation — LifeTech Pharma InfoSec Write-ups · May 30, 2026
- CTI as a Code: Complete Step-by-Step Methodology InfoSec Write-ups · May 29, 2026
Latest
Most recent articles, guides, and tools — newest first. Full lists below.
- Anomaly Detection Atlas Docusaurus · Jun 9, 2026
- ThreatMapper Documentation Docusaurus · Jun 7, 2026
- Insider Threat Detection Engineering Guide Docusaurus · Jun 7, 2026
- ThreatMapper — ATT&CK threat-intel platform GitHub · Jun 9, 2026
- StratusAI — AWS/GCP cloud security scanner GitHub · May 2026
- AIDebug — CTI-first malware RE debugger GitHub · May 2026
Choose Your Review Path
Start with the path that matches what you are evaluating. Each path keeps the top story defensive and CTI-to-detection oriented.
CTI / Threat Intelligence
Detection Engineering
Malware / Reverse Engineering
Cloud / Kubernetes Security
Offensive Security / AI-Driven
AI-Assisted Security Workflows
Workflows where candidate enrichment, summaries, mappings, and scores require analyst validation before use. AI accelerates mechanical steps — analysts own every decision gate.
Full Library
Use the full Medium navigator only after the selected paths. The homepage keeps selected work visible first so the portfolio stays scannable.
Flagship Projects
Ten top-tier projects that define the main body of work, followed by supporting pieces.
Top-tier flagships
CTI Analyst Field Manual
Practitioner operating manual: evidence labels, source reliability (Admiralty A-F/1-6), confidence language, attribution methodology, infrastructure pivoting, AI controls, hunting hypotheses, detection backlog, and 10 reusable analyst templates. 80 pages, 10 modules, CI-validated.
Operation Desert Hydra
Complete CTI-to-detection pipeline on MuddyWater / Seedworm — widely reported by government and vendor sources as Iran-linked activity associated with MOIS. 71 candidate sources reviewed, 8 promoted, 10 procedure records with Observed/Reported/Assessed evidence labels, OpenCTI 6.2 knowledge graph, 11 detection records with SIEM-agnostic pseudologic, and an Ansible-provisioned Windows 10 lab validated against Kibana. 14 PASS / 1 PARTIAL / 1 FAIL across 16 rule checks. 16 of 21 ATT&CK techniques (76%) fully validated. One-command reproducible.
Israel Government Threat Actors CTI
Sector CTI covering Iranian, Palestinian, and regional threat actors targeting Israeli government, public-sector, critical infrastructure, and adjacent suppliers. Actor profiles, ATT&CK mappings, IOC reference locations, and detection examples. Blue-team only — no binaries or exploit code.
Customer-Driven CTI-to-Detection Methodology
End-to-end methodology for structured CTI engagements: scoping, collection, analysis, and delivery with human validation gates throughout. 15-phase cycle with AI assistance under analyst control. Three-part article series and full Docusaurus reference site.
OpenCTI Intelligent Shield
OpenCTI platform with a custom Claude-powered enrichment connector: Docker Compose deployment, STIX 2.1 workflows, confidence-scored IOC enrichment, and an analyst gate before any object enters the threat intelligence graph. Sanitized env example; real credentials excluded from repo.
Operation DragonRx
Full-stack APT41 pharmaceutical-sector attack simulation: Log4Shell initial access → Sliver C2 implant → Active Directory lateral movement → LSASS credential dump. Dual-layer detection with Wazuh + Zeek + Elastic. Published CTI report, lab architecture, and step-by-step attack playbook.
AIDebug
Reverse engineering walker for malware analysts: Capstone disassembly, FLIRT signature matching, CFG extraction, Frida-based dynamic tracing, INetSim isolation, 8 behavioral pattern detectors, and SIEM-ready JSON output. TUI interface — no sandbox required for static analysis passes.
Old Defense vs New-Age Attacks
Defender-focused guide on how AI collapses the attacker skill floor and breaks assumptions behind legacy IOC-heavy defense. Covers the old capability-tier model, the Pyramid of Pain after AI, why legacy controls fail, and what SOC teams should change in logging, behavioral detection, CTI, and response.
ThreatMapper
Self-hosted AI threat intelligence platform. Uploads a threat report (PDF, DOCX, or raw text), picks Claude / GPT-4o / Gemini, and extracts ATT&CK techniques with evidence and confidence scores in real time — streamed token by token. Built-in APT group attribution (Jaccard similarity over all 174+ groups), interactive ATT&CK Navigator heatmap, campaign overlay, named layer library, comparison modes (Groups / Campaigns / Stored Reports), and one-click PDF reports. Docker Compose, no cloud dependencies.
Insider Threat Detection Engineering Guide
Detection reference covering 14 documented insider threat cases (Manning → Barile) with structured detection engineering across 4 tiers — deterministic rules, behavioural heuristics, UEBA, and deception. 30 pages, 32 infographics, 4-phase implementation programme, telemetry requirements, and legal constraints. Built from CERT/CMU research, DOJ case records, and regulatory findings.
Strong supporting work
CVSS v4.0
CVSS v4.0 enrichment CLI (BTE scoring) that turns CVEs into prioritized vulnerability-management work using NVD, CISA KEV, EPSS, and configurable asset profiles. Companion Docusaurus field guide site with scoring explanations and practitioner decision frameworks.
StratusAI
Multi-cloud security scanner: 9 AWS modules + 7 GCP modules, 125-test suite, ECS Fargate / Cloud Run deployment. Multi-LLM finding analysis with attack-chain synthesis and severity classification in 2–4 minutes per scan.
Android Malware Analysis
Android APK analysis toolkit: AI-powered static analysis from the terminal, OWASP Mobile Top 10 coverage, decompilation, manifest inspection, permission risk scoring, and output formatted for mobile security assessment reports.
Vulnerable AI Lab
Intentionally vulnerable AI security training lab — DVWA/WebGoat for modern AI systems. Pre-built OWASP LLM Top 10 2025 scenarios: prompt injection, RAG poisoning, tool-call manipulation, and data exfiltration via LLM agents in a realistic RAG pipeline.
Medium Blog Navigator
Docusaurus navigation layer for 200+ Medium articles — organized by topic, difficulty, and content cluster. Makes cross-article research and topic discovery practical at scale without relying on Medium's own recommendation engine.
Work by Domain
Start here before opening the full article library.
CTI Work
Kill chain, attribution, infrastructure pivoting, ATT&CK usage, and public-source actor research.
Detection Engineering
Threat hunting, atomic detections, correlation rules, detection backlog thinking, and telemetry coverage gap analysis.
Malware Analysis
Malware analysis tools, APK analysis, YARA-related work, file triage, import analysis, strings, and unpacking utilities.
Cloud / Kubernetes Security
Cloud-native threat research, cloud scanning, vulnerable cloud labs, audit-log thinking, and prioritization support.
AI / Workflow
AI-assisted CTI tooling, enrichment source confidence management, OpenCTI operations, and structured analyst workflows.
Offensive Security
Authorized offensive security research and adversary simulation: red-team labs, attack playbooks, and AI-assisted lab workflows used for defensive context.
Live Evidence
Real screenshots from published research — tool outputs, malware analysis, infrastructure pivots, and attack simulations. Click any image to open the source article.
Selected Article Library
Direct Medium links only. The blog navigator is listed separately as an index resource, not used as a substitute article link.
CTI, Attribution, Pivoting
One Place for My Cybersecurity Projects, Guides, Articles, Labs, Tools, and Research Workflows
Meta map of the full ecosystem: main site, Medium, GitHub, and Docusaurus as one structured cybersecurity knowledge base.
CTI Research: Kubernetes & Cloud-Native Threat Landscape
Technical kill chain analysis, detection engineering, and defensive architecture for cloud-native threats.
The Intelligent Shield. OpenCTI
OpenCTI deployment, connector engineering, STIX workflows, enrichment source confidence management, and platform operations.
CTI Research: MuddyWater/Seedworm
Evidence-labeled assessment, technical timeline, defensive priorities, and SOC guidance.
CTI Research: Handala Hack Group
Threat persona and cluster analysis with evidence labels, IOC handling, and defensive guidance.
Infrastructure Pivoting: From One IOC to a Full Attacker Network
Field manual for passive DNS, reverse IP, ASN reuse, TLS certificates, internet search, and WHOIS pivots.
Attribution Methodology
How to build, defend, and challenge attribution claims without overstating the evidence.
ATT&CK as a Working Tool
Hands-on ATT&CK use for mapping, gap analysis, Sigma thinking, hunting, and adversary emulation.
CTI Kill Chain: An Analyst Guide With Real-World Evidence
Kill-chain thinking for analysts who need evidence, not generic phase labels.
Manual CTI vs. AI-Assisted CTI
Step-by-step comparison of where AI compresses CTI work and where analyst judgment remains non-negotiable.
CTI Program Design
Customer-Driven AI CTI Project
End-to-end CTI-to-detection methodology and project workflow overview.
Customer-Driven AI CTI Project Template: Part 1
Foundations and methodology for a customer-driven CTI lifecycle.
Customer-Driven AI CTI Project Template: Part 2A
Phase-by-phase execution guide from requirements to hunts and detections.
Customer-Driven AI CTI Project Template: Part 2B
Reference toolkit for artifacts, gates, delivery materials, and validation.
Detection And Hunting
Detecting Malicious Insider Activity: A Technical Detection Engineering Guide
14 documented cases, detection tiers 1–4, CERT kill chain, UEBA, deception controls, legal constraints, and a 4-phase implementation programme.
Endpoint Threat Hunting: Windows, Linux, and macOS
Telemetry, artifacts, MITRE ATT&CK tactics, and practical playbooks for endpoint hunting.
Protocol-Level Network Threat Hunting
Wireshark-centric guide to IOCs, protocol anomalies, C2 signals, and packet-level hunting.
Threat Hunting with the Pyramid of Pain
How to move defenders from brittle IOCs toward artifacts and TTPs that cost attackers more.
Single-Event Detection Rules in Cybersecurity
Atomic detection rules for SIEM, XDR, and log-based detection platforms.
Correlation-Based Detection Rules
Multi-event analytics, temporal logic, and behavioral detection across SIEM and XDR.
The Atomic Standard
Practitioner compendium for single-event threat detection and rule design.
The Invisible Pipeline
Defending CI/CD systems from targeted attacks with concrete controls and detection ideas.
Malware, Cloud, AI Security
Android APK Analysis Tool
AI-assisted static APK malware analysis with YARA, VirusTotal context, candidate MITRE mapping, and Frida hooks.
AI-Powered Malware Debugger
AIDebug walkthrough: FLIRT, patterns, CFGs, Frida, unpacking detection, YARA, and reports.
StratusAI Cloud Security Scanner
AWS and GCP scanner architecture, multi-LLM routing, Terraform deployment, and test coverage.
AI in Offensive Operations
Evidence-based research on attacker AI use, TTPs, incidents, confidence, and forecast judgments.
CVSS v4.0 Field Guide
CVSS-BTE, KEV, EPSS, environmental scoring, examples, scanner triage, and automation.
Tools And Repositories
Repositories are grouped by defender output, not by programming language.
Malware Analysis Stack
AIDebug, Android-Malware-Analysis, Static Malware Orchestrator, Unpacker, PE Import Analyzer, String Analyzer, and file triage.
CTI Engineering
Reports, pivoting automations, detection packs, and hunting hypotheses that move intelligence into operational use.
Vulnerability And Cloud
CVSS-BTE enrichment, cloud scanning, and vulnerable cloud labs for realistic prioritization and testing.
Guides & Docs
Docusaurus knowledge bases, field manuals, and structured references. 52+ step-by-step guides on Medium.
CTI as a Code
Version-controlled CTI methodology, evidence-traced investigation workflow, OpenCTI/TheHive/Elastic lab stack, and eight structured training assignments.
CTI Analyst Field Manual
Analytic judgment, evidence discipline, hunting hypotheses, and ATT&CK-mapped detection candidates.
Insider Threat Detection Engineering Guide
14 documented cases, 4-tier detection taxonomy, deterministic rules, UEBA, deception controls, 4-phase implementation programme, telemetry requirements, and legal constraints. 32 infographics.
Operation Desert Hydra
End-to-end CTI-to-detection pipeline: source review gate → procedure dataset → OpenCTI knowledge graph → 11 detection records → benign lab simulation → Kibana proof screenshots. 14 PASS / 1 PARTIAL / 1 FAIL across 16 rule checks.
Israel Government Threat Actors CTI
Defensive CTI knowledge base for Israeli public sector, critical infrastructure, municipal, and supplier exposure.
Customer-Driven AI CTI Project
End-to-end methodology for turning intelligence requirements into hunts, detections, and delivery artifacts.
Customer-Driven AI CTI Template
Reusable templates for requirements, hunts, detections, evidence packs, and customer delivery.
CVSS v4.0 Field Guide
Practical CVSS v4.0 scoring, environmental profiles, scanner triage, and prioritization guidance.
HexStrike AI Guide
Authorized AI-assisted security lab workflows used as operator-context evidence for CTI work.
Medium Blog Navigator
Separate index for browsing the full Medium library by topic, depth, and role. Article cards above use direct article links.
OpenCTI Intelligent Shield
OpenCTI operations and security-team workflows for enrichment source confidence management and threat-intelligence platform work.
Old Defense vs New-Age Attacks
Docusaurus guide on how AI changes the attacker skill floor and what SOC teams must change in logging, detection, and response.
BrittleBench
Defender audit of public detection content robustness, focused on brittle IOC-heavy content and detection assumptions that fail under attacker adaptation.
Anomaly Detection Atlas
Vendor-neutral reference connecting statistical anomalies, ATT&CK-aligned activities, and the security log sources that surface them — a lookup layer between detection ideas and the telemetry needed to build them.
Lab Work
Authorized, controlled environments built to understand attacker behavior, validate detection assumptions, and practice the full attack-to-defend cycle.
Operation DragonRx
APT41 pharmaceutical-sector attack simulation. Log4Shell initial access → Sliver C2 → Active Directory lateral movement. Dual-layer detection with Wazuh + Zeek + Elastic.
Cloud & Kubernetes Labs
Vulnerable cloud infra for cloud pentest practice: GCP + AWS Terraform deployments, 25-issue Kubernetes misconfiguration lab, and IIS / SharePoint / Fluent Bit environment.
Active Directory Labs
Reproducible Windows / AD pentest environments: vulnerable Windows 10, full AD domain with GPOs, Kerberoasting, Pass-the-Hash, and LSASS dump paths. Manual and one-prompt Cursor AI deployments.
Android Security Labs
Android analysis lab on Ubuntu (Androguard + Frida toolchain). Deliberately vulnerable Android app covering all OWASP Mobile Top 10 classes. Autonomous mobile PT walkthrough.
Vulnerable AI Lab
Intentionally vulnerable AI application lab — like DVWA but for modern AI: RAG assistants, tool-calling agents, LLM-powered copilots. Covers prompt injection, data exfiltration, and agent manipulation.
Linux & Web App Labs
Vulnerable Ubuntu 24.04 server with full HexStrike pentest walkthrough. DVWA deployment automated with Ansible for reproducible web-app attack-and-detect practice.
About
I profile adversary behavior, map TTPs to ATT&CK-aligned detection candidates, and ship tools that automate the mechanical parts of CTI and reverse engineering work. Current role: Threat Intelligence Research Engineer at XPLG. Formerly Head of Red Team at Israel Police Cyber Defence Unit. All tooling ships with mandatory analyst review built into the workflow — AI assists with throughput, not with judgment.
Contact
Use the profiles below for code, writing, and professional contact.