Threat Intelligence Research Engineer · XPLG · Tel Aviv, Israel

Threat intelligence that turns into detection.

For analysts, detection engineers, and learners: investigate adversary behavior, test a detection candidate, and build a repeatable malware-analysis workflow.

Research and an example you can reuse

AI in cyberattacks: original study of 111 publications — inspect the dataset, provenance, and denominator boundaries.

Validate a command-shell detection candidate — six benign events, expected results, and documented limitations. Follow substantive updates via RSS.

Security research: direct answers

Practical definitions with links to methods, evidence, and reusable tools.

Who is Andrey Pautov?

Andrey Pautov is a Threat Intelligence Research Engineer at XPLG in Tel Aviv and a former Head of Red Team at the Israel Police Cyber Defence Unit. His work covers CTI-to-detection workflows, adversary profiling, ATT&CK mapping, malware analysis, and analyst-reviewed AI tooling.

Profile and experience

What is AdversaryGraph?

AdversaryGraph is a self-hosted CTI-to-detection workbench for turning reports, IOCs, malware findings, assets, and telemetry into ATT&CK-mapped investigations, hunting hypotheses, detection candidates, and validation evidence.

AdversaryGraph project hub

What is CTI as Code?

CTI as Code is a version-controlled method for maintaining structured intelligence, evidence, confidence, ATT&CK mappings, and detection artifacts as reviewable files with a clear change history.

CTI as Code guide

What is a CTI-to-detection workflow?

It is the controlled path from source-rated intelligence through behavior mapping, telemetry requirements, hunting hypotheses, detection logic, lab validation, and SOC handoff. Generated suggestions remain subject to analyst review.

CTI Analyst Field Manual

What does public research show about AI in cyberattacks?

A purposive 111-publication corpus most often describes AI as an accelerator for familiar identity, research, evasion, and malware workflows. The 103-publication statistical denominator measures reporting coverage—not attacks, victims, prevalence, or provider abuse rates.

Read the statistical CTI study

Start an ordered learning path · Run the benign command-shell detection example · Follow substantive updates via RSS

Practical research paths

Short on time? Pick the path that matches your role. Each route points to the strongest evidence first.

One-page summary

CTI / Threat Intelligence

Adversary profiling, attribution, and CTI-to-detection methodology.

  1. CTI as a Code
  2. CTI Analyst Field Manual
  3. Operation Desert Hydra
  4. AdversaryGraph docs

Detection Engineering

Validated detections, coverage matrices, and hunting content.

  1. Newest Detection Engineering Techniques
  2. Desert Hydra Detection Atlas
  3. Validation Results
  4. Insider Threat Detection
  5. Threat hunting hypotheses

Malware / Tooling

Reverse engineering workflows, cloud scanning, and CLI tools.

  1. AIDebug
  2. stratus-ai
  3. cvss_4.0
  4. All projects

Hiring Managers

Fastest overall read of scope, depth, and evidence.

  1. CV and PDF download
  2. About and experience
  3. Flagship projects
  4. GitHub profile

Flagship Projects

Reusable research and tools. Each project links to its methods and evidence.

See all ->

Live Evidence

Six verified captures from release fixtures, reproducible labs, and published research. Each card states what the image demonstrates—and its evidence boundary.

Explore all projects

Latest

Three recent research publications and three current tools. Use Articles and Projects for the full archive.

Updated Aug 2026