Cyber Threat Intelligence Podcast
Welcome to the Cyber Threat Intelligence Podcast—your go-to source for staying ahead in the ever-evolving world of cybersecurity by harnessing the full potential of CTI.
In each episode, we dive into the latest cyber threats, emerging trends, best practices, and real-world experiences—all centered around how CTI can help us defend against cybercrime.
Whether you’re a seasoned CTI analyst, a CTI leader, or simply curious about the digital battlefield, our expert guests and host break down complex topics into actionable insights. From ransomware attacks and insider threats to geopolitical cyber risks and AI-driven security solutions, we cover all things CTI.
Join us for in-depth interviews with industry leaders and experienced professionals in the Cyber Threat Intelligence space. If, like me, you’re always in learning mode—seeking to understand today’s threats, anticipate tomorrow’s, and stay ahead of adversaries—this podcast is your essential companion.
Stay informed. Stay vigilant. Tune in to the Cyber Threat Intelligence Podcast.
Cyber Threat Intelligence Podcast
Mindset Deepens Technical CTI Skills (Cat Self & Pedro Kertzman)
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Imposter syndrome shows up in Cyber Threat Intelligence like clockwork, but we do not let it run the room. Cat Self, Senior Director of Adversary Research at Tidal Cyber, joins me to get practical about what actually helps CTI analysts perform: turning open source intelligence and vendor reporting into actionable intelligence your org can use, even if you do not have a massive telemetry stack or a dedicated reverse engineering team.
We dig into the real problem with OSINT: noise that looks like signal. When six write-ups trace back to the same original report, repetition can feel like validation, and marketing content can drown out what matters. Cat shares how she filters for credibility by tracking specific authors and expertise areas, building a short list of sources she trusts, and keeping accountability front and center when publishing anything under her name. If you rely on MITRE ATT&CK mappings, threat actor reporting, or rapid intel notes for detection engineering, this part will sharpen your sourcing instincts.
We also tackle AI in CTI without the hype. AI can help reduce the haystack, but it is still “rearview” and cannot replace judgment. Cat walks through lessons from building an intelligence pipeline with “vibe coding,” why debugging AI can be chaotic, and how guardrails and human agency keep automation useful instead of risky. Then we shift into analyst mindset: small role-play exercises, making intelligence fun, and creating psychological safety so teams learn faster and burn out less.
References:
Batman Effect:
https://academic.oup.com/chidev/article/88/5/1563/82578
Lego Study:
https://cms.learningthroughplay.com/media/wmtlmbe0/learning-through-play_web.pdf
Problem solve improvement:
https://tu-dresden.de/mn/psychologie/ifap/allgpsy/ressourcen/dateien/lehre/lehreveranstaltungen/bolte_lehre/ala/Isen_1987.pdf?lang=en
Subscribe for more cyber threat intelligence conversations, share this with a teammate who lives in OSINT, and leave a review so more analysts can find the show.
Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!
Imposter Syndrome And Quick Reality Check
Cat SelfWe all talk about imposter syndrome, and why we all have it. Move on.
Meet Cat Self And Her CTI Path
Cat SelfRachael Tyrell
Hello and welcome to episode 12, season two of your Cyber Threat Intelligence Podcast. Whether you're a seasoned CTI expert, a cybersecurity professional, or simply curious about the digital battlefield, our expert guests and hosts will break down complex topics into actionable insight. On this episode, our host, Pedro Kertzman, will chat with Cat Self, who is senior director of adversary research at Tidal Cyber. She previously spent years at Niger as macOS and Linux leaders for attack, and founded the CTI team behind evaluations. Her career started at Target, where she became the company's first woman red team operator and first full-time threat hunter. Before that, she served in U.S. Army Airborne Military Intelligence with two combat deployments. You'll find her on a remote mountain or down a dark alley chasing a restaurant recommendation, which is partly why she trains in martial arts. Over to you, Pedro.
Pedro KertzmanThank you so much for coming to the show. I'm really happy to have you here.
Cat SelfIt is my honor to be here. Just thank you so much for inviting me, and then also just giving me an opportunity to talk about what I love.
Pedro KertzmanIt's absolutely my pleasure, especially having one of the unsung heroes of our industry, having someone that contributed so much to the miter that we all use on a daily basis, and you know, helped as a whole our industry advance so much. So I really appreciate you taking the time to talk with us today. I really appreciate
Turning Open Source Reports Into Action
Pedro Kertzmanit. So if we can jump right in, I think one of the uh big chunks of our career was when you had some uh experience, you know, collecting open source throughout intelligence and try to make sense of that to transform in more operational or to transform in things that CTI teams could actually make sense of, right? Could you tell us a little bit about that particular uh part of your career?
Cat SelfYeah, I could definitely tell you kind of how I came about that approach. Um, so working at MITRE, something that you get to have a lot of exposure to, like I miss, I miss the fact that they changed their motto. I was like so upset. We were all so upset when they changed their motto to like something like people first, whatever. But like they really mentioned people first. I forgot this is how irrelevant it is to me now. I don't even remember it. Um, but when I joined five years ago, um, it was make the world a better place. And so it really gives you this like appreciation for that problem. How do I actually make the world a better place? And so when we start with CTI people, what which I have a very varied background, which I kind of love how I've turned into CTI, but I absolutely was software dev, internal red teamer, and then Thread Hunter, and then now CTI. So it's kind of been this really beautiful blend, like a marbled cake. And one of the problems that I really wanted to target was what's accessibility to this methodology look like? Like what is practical applications for someone that doesn't have a CTI team, someone that doesn't have a data lake of logs, that doesn't necessarily even know about all the technical information to do a reverse engineering report to be able to tell you the traversal of the kill chain and where they probably did what. For someone who doesn't have the resources to do domain hunting, to be able to look at the old expired users using, you know, who is and then being able to track them over time and having all these pivot tables and Excel files, you know, like there's a lot of random skills that we have to collect just to do a like answer one question. Absolutely. So, right? Like, that's how I scaled it down to okay, what if we only have open source reporting? That's it. We rely on all of these, like I mean, the vendors, but also awesome vendors because vendors are the ones that provide us these incredible teams that are doing the research and that are publishing the blogs that we need to be able to do our under to gain our understanding. So these vendors produce these reports. How can I take these reports and then make them into actionable intelligence that I can then provide my organization? And so that is essentially one of the facets of the problems that I tried to solve with at MITRE. It's like, how do I provide a methodology where you can take what's available to you and make something that's good enough to move your organization forward at least a little bit, right? Because that's better
Noise, Regurgitation, And Marketing Fodder
Cat Selfthan nothing. Oh no, well, a question for you.
Pedro KertzmanUh oh.
Cat SelfWhat do you think the analysts struggle with when it comes to open source reporting and making it actionable?
Pedro KertzmanMy best guess, it's usually too much noisy information. It can it can be. I don't wanna it's hard to be generic because it's usually unfair, but it can be too much information, too noisy. The good and bad things about free, it's always there available, and it's not necessarily the right information for what you need.
Cat Self100% agree with that. That was actually one of the things I just did a LinkedIn post where someone asked me, they were like, Kat, how do you filter out the noise? How do you even learn to identify what noise is? Right? Because that's even a precursor. It's like, what is noise? Because when I first started looking at open source reporting, I was like, oh, well, all of it's good because it's like puzzle pieces to create the entire picture until you realize six reports were like literally cited the same trend micro report. And you're like, wait a minute. All of you read a trend micro report, pulled down the samples, did some analysis, and we're like, yep, that looks right, and then just regurgitated trend micro's report without actually publishing your own confirming findings using your own tools. And I was like, seriously? So then we've gotten noise because and I I almost fell into this trap. I started at um this cut the startup that I am, and we were talking about like what I should talk about in the media. And I say this as because I think this is something that as individuals, we do get a say in. And I really encourage anybody that blogs or wants to share information or knowledge, like you are at the end of the day, responsible for what you publish and what you push out, not your company. So the moment you put your name on it, you unfortunately like you have to hold accountability for it. So what do you want that to look like? Like, take ownership in it. Don't just let it be a part of your job role, take ownership in it. Because they asked me, they were like, hey, Kat, so what should we tell our customers? And I'm like, I feel like the customers can read the report. And they're like, Well, no, we need to give our own take on it. And I was like, but I don't have another take. I don't have those samples, I wasn't a part of the intrusion analysis. Why would I give another take when they already have a good one? And it was a really interesting conversation because it was like, wait a minute. I could post an opinion, but it's an opinion. It's like it's just hot air. At the end of the day, I'm not giving new information, I'm not moving anything forward. And so I declined to post on that type of information. And then I started watching and paying attention to people that might also be in my situation. And then I started realizing, oh, this is this is a trend. Cause at the end of the day, all of us want to just be helpful. And it's very hard to discern the loud voices that are coming at us on if what they're telling us to do is actually helpful for the community. Like it's not a knock on anyone, it's a discernment point that we figure out after we've stumbled a couple of times. So there's a lot of noise. I don't think all of the noise is intentional. I think some of it's just like social pressure and like people not really like they're figuring it out, they're finding their voice. And then other noise is absolutely marketing fodder that I really wish would just go away.
Pedro KertzmanYeah, no, that's that's a good point. I think, especially these days, the amount of marketing bombardment is I know it's a harsh word word, maybe, but sometimes it's really damaging and competing with the important information that we actually need to be focused on. But yeah, no, that's sorry, go ahead.
Cat SelfNo, that you
AI Hype, Vibe Coding, And Agency
Cat Selfactually make a perfect point. I think, especially like so DEF CON was uh all about agency, right? Like there was a lot of complaints out of Black Hat where they were like, Cool, you used AI and it did the thing. However, you didn't really tell us the way in which you manipulated the AI. You didn't really tell us like the guardrails in which you put in place, you didn't tell us the follow-on training, you didn't tell us the like stages in which you built out the skill, right? You didn't tell us the the rabbit holes that went down that were wrong. Like there was a lot of like glossing over, which is like I literally just built a pipeline just using vibe coding. I did not want to code because I loathe coding because it's too tedious, unless it's malware. But so like normal software dev is now boring to me. So I was like, I'm vibe coding this, right? Like, I will make myself an intelligence pipeline, no problem. Wow, that was five months of misery and like 14-hour days. There is a joke about how like the only worse thing than debugging is debugging AI, like how like AI, like there is no god, there was this image, and it was a guy. Like, have you do you travel much? Uh-ish. No, have you ever been over to I don't want to pick on Southeast Asia, but I kind of do because it's absolutely hilarious to me. But I was in Southeast Asia traveling and I was looking at the power lines outside of the buildings, and you're like, it's a jungle, it looks like the Congo.
Pedro KertzmanLike, there is so many, like you don't know where they're coming from, going to, yeah.
Cat SelfNo idea. Yeah, that is what debugging AI looks like. You have no idea at what house this wire is actually going to and where it originates from. Don't touch it. Which is completely confused. Don't touch it. Just pray to God it keeps working, right? Yeah. And that was what I experienced with vibe coding.
Pedro KertzmanYeah.
Cat SelfDo not do not like, and then I had to rewrite the entire pipeline, which I realized when you're working with AI, treat it like it's AI. Don't treat it like a human engineered production code. You can trash it just as quick as you built it. It's just expensive because of tokens. So, and treat it like that because it's not reliable. It's basing it off of whatever model it's been trained on. So I had to rewrite it this time with guardrails. All of this is to say, getting back to my point of agency, when it comes down to it, I think a lot of us are now really cherishing personal relationships. We're very much cherry, like I started to follow authors. I've stopped following like the actual blogs and started following authors of specific blogs that I'm really interested in. Because not everyone is going to work the same campaigns. They're going to work specifically, usually on a certain area. And I found that there's really small key individuals that really know what's going on with these different threat actors today. And so for me, the solution has actually been not so much as in using AI. AI is really great for filtering down the noise into who the key authors are or who the key source reporting is at. But the real work comes in and me specifically screening who gets on my short list. And that's been super helpful in that. And then I'll even reach out to them and just be like, can I just pick your brain about this and understand this? And there's like two people that I just truly trust on DPRK. Like those are my people for DPRK. I don't even like look up anything. They tell me that. That is already fact-checked for me. I don't even go to AI because the reality is AI can only be knowledgeable about what it knows. It cannot create new things yet, right? It's still, it's still at the biggest point of its day. It's still just math. Very, very, very fancy math of stuff that's already known to humans. 100%. So that's how I've kind of cut out the noise.
Pedro KertzmanI think, especially without going too deep into the AI like rabbit hole, I think you you bring up a good point. Like AI is always rear view. It's never going to, at least as far as I understand it, it's not going to create new like creative things. If we never did it, I don't think AI will. It doesn't have that ability. It's going to copy whatever we did in the past, do a mathematical probability calculation, something something. Does that apply to that to this situation? Then it will apply if it makes numerical sense. And that that's it. But to our, you know, filtering out the massive amount of information and digesting that into the into the CTI frames. What about the analyst
Analyst Mindset And The Batman Effect
Pedro Kertzmanmindset? What was some of our are there like any lessons learned you think we could share?
Cat SelfMindsets are really hard thing. When I first joined a red team, actually, that was the one thing that they were like, uh, I just need you to learn the mindset. I just need you to learn to think offensively. And it was it was a hard one, right? Because you're it's a it's it's changing the perspective of which you see life. Um fun fact, there was actually a study done. I don't have all my references in front of me, um, so I can send them to you later. But there was a study done, and they call it the Batman effect. And what's really neat about this is this scientist took ages four and ages six. And then what he did was he gave them a task, a very tedious, boring task. Like, go clean up your toys. And what he did with this, these different age sets was he was like, okay, he gave them the task, asked them to do it. And then he, you know, monitored the rate of completion, how long it took them, did they actually even complete it? Did they like stop halfway? We all know, like me, even at my ripe old age in my 40s, I barely finish all my tasks. I'm like jumping between 17 of them, right? So I can only imagine what baby cat would look like. And so what he did was he was like, okay, now I want you to go do all those tasks again, but this time I want you to be Batman. Go pretend to be Batman while you're doing it. And they had a what was a 65% increase in completion.
Pedro KertzmanHoly right?
Cat SelfSo that tells you that when our mind is in a suspended state where we're putting ourselves in a different mindset, our ability to actually follow through on tedious tasks skyrockets. So if you can imagine looking at logs that are tedious, boring, and dull, because they are like I don't know anyone that makes logs sexy. So tell me if you are an editor that made logs sexy, I'm buying stock in you. But like, what if I was looking at those logs, but I'm actually the adversary looking for my footprint, you know, or whatever. Like you can play a game with it, but the point of it is is to have a little fun with it, right? And use tools that we know are good, no matter how silly they are, and just see. Like, what have you got to lose? And so for me, like what would it look like if so I love false flag operations? Those are my favorite, because that's where you're like, I'm gonna go pretend to be Russia, I'm gonna go pretend to be DPRK, I'm gonna go pretend to be little Lady Lou over here, and she's actually not Lady Lou. She's actually the cyber criminal that's taking advantage of old people, you know, like whoever it is, what would I do? How would I go about this? Right. So there's a lot of actual exercises that you can do to be able to practice this mindset. Um, I came up, there was a I'm gonna release it eventually, I promise. You know, every time you do a talk, the moment you finish your talk, you're like, hey, I'm gonna release my slides and all the technical details. And then you start work the next day. And then that goes away. So it's almost like if you don't do it before you present, you're probably not gonna do it. Anyways, I will eventually release a scenario that kind of walks through this, but you can do like little 15-minute exercises and they can be super simple where it's like, okay, I like like what about the who am I game? Like, I'm just coming up this off the top of my head. So you're getting a bit of raw cat right now. But let's say I love the color red, I am super efficient in my operations, I get in and I get out. I really believe in representing my city or region in which I live in, and I'm given free reign to do whatever I want to do, as long as I don't touch Russia, and there's a couple of considerations, and um, and my practice ground is Southeast Asia. Who am I? Like, you can kind of play these games, right? And then like change the information up, and then you can actually, with your analyst, be like, okay, well, who you could be this person because this, because regionally, this is what they do, and you're like, oh, that's a good common thread. And then you suddenly start making these common threads, you're like, wait a minute, actually, these three countries all match that criteria. And then suddenly you're actually like, okay, well, well, what would be the distinguishing factors that really make them them? And then suddenly it's like, okay, now what if we did that in a technical manner, not just general? Right? Like, what if we did that on a strategic policy manner, not just general or technical? And then those little games really, I think, teach the mindset of like, what information do I have? What information do I need to confirm? And what information is volatile? What information can change depending on the day, the season, the economic plunder, you know? What's like what does that look like? And so then that kind of really starts creating a personality. And to me, that's when you actually know someone is when you actually like if you can actually be like, hmm, that doesn't sound like them, then you know someone. It's only in I think in those, like if you even think about friendships, like you're like, oh, that doesn't sound like cat. You you know me. I feel seen because you can say, Oh yeah, that sounds like cat. Like, well, yeah, because you're probably like everyone's usually like no one wants to counter, right? Confrontation is like most of us want to avoid it. So I always think that's a good telltale if you can discern and be like, okay, that doesn't sound like that, or it needs this to confirm it.
Pedro KertzmanThat is very interesting, and it honestly feels like it could be the difference between you know super a super overwhelming activity. Most analysts go through from initially like log analysis, a bunch of report analysis, and and all that, like all things involved uh on an intelligence life cycle, uh, and going into a more like uh role play or playing a game type of activity. And I don't know, it's uh have you ever had the chance to would that qualify for like I don't know, make intelligence fun or something like that?
Making Intelligence Fun With Play
Cat SelfI love I love the idea of making intelligence fun. I honestly think it's really one of the only ways that we can kind of remove this toxicity that's kind of set in and actually like be excited about going to work the next day. I don't know about you, but it can get real serious real fast. And that just because I'm having fun doesn't mean I don't care.
Pedro Kertzman100%.
Cat SelfJust because I'm smiling doesn't mean I'm not taking it seriously.
Pedro KertzmanA hundred percent. Yes.
Cat SelfRight, like just because I leave work at 5 p.m. doesn't mean I don't have passion. There's a lot of these misunderstandings that are happening that I think we've forg we've we've been silent on, and thereby since we have been silent, we have confirmed, not intentionally, unintentionally, have confirmed that that is the way you're supposed to be, and so and it's not sustainable, nor is it a job no one wants to do, and then you get all bitter because you're underpaid, because like let's be real, like most of us don't care a lot, like we are definitely not enjoying cushy jobs, like we probably all work more hours than we should. We all take our private research time, like to move things forward. We're doing podcasts like this, we're like, there's so much, like it's not like and I'm off peace, yo. It's like, and now what else can I do? It's a very different question. So, but all that be said, like I want people to keep coming into this field, and I want them to love it, and I want them to like find this a sustainable, enjoyable, and growable field. And I think we need play in order for that to happen. I think actually, if you base if you actually go off the research that Is I haven't done research on this specific aspect actually. Specifically the aspect of the longevity of career as it relates to those that enjoy their career and have played. I haven't done that research, but I'm sure there's some research out there. So if there's any listeners and you do the research, please ping me directly and let me know. But I do know that the environment in which play can be performed is very specific. So Lego did a study and they found like five characteristics that kind of had to be um in play to have play. And that was like, oh man, I really should have all my research pulled up. I don't have it right now. Um so we're gonna go off of memory. This is gonna tell you how smart cat is right now. My recall. Um, but one of them was psychological safety. It was that safe environment, right? I need to be able to blurt something out and it be totally wrong in the wrong direction and it be received in such a way that I can be wrong and then steered, not reprimanded into what's right. Whatever that looks like. Um, it needs to have engagement. So there actually has to be something to interact with. It needs to have social engagement, which means it's not an isolation. Um, and then there was another one. I forgot the other two, but um, but the point is that there's a lot of factors in there that I think if we have all those factors present and we focus that on our side of our culture of our teams, it will naturally facilitate a different way to walk through our field in a way that we actually grow quicker, we understand deeper, and we accelerate faster because we have the environment in which to absorb.
Pedro KertzmanThat's that's really inspiring.
Coaching, Feedback, And Who You Choose
Pedro KertzmanAll right. Uh, I think also I read quite a few things about your experience with coaching. Is that was that a thing? Coaching, yeah. Was that a thing? Yeah, I do a lot of coaching. There we go. Any for people listening, any common things that you notice are common throughout coaching sessions uh that might be common across people coming into the industry that I think might be worth highlighting. So if people listening feel the same or experience similar situations, don't feel alone and uh know how to navigate that. Anything around that?
Cat SelfI have had the blessing of my so the one one analyst that I get to work with, we do not work together anymore, but she made a comment. She was like, Kat, you have been the hardest person I have ever worked for. She was like, however, I grew the most. And and we're actually really good friends today. So that kind of tells you that just because it's really hard to work for someone and they're very specific in what they want, does not mean you can't have a friendly, wonderful, warm friendship with them as well. Right? Like, I actually believe that the best relationships between leaders and peers is and and followers is a really good follower, a really good follower is one that knows exactly how to lead. And they give the leader exactly what they need out of a follower. A really good leader is one that knows how to follow really well, and they know exactly what to tell the follower that they need. A really good peer is one that has their own self-awareness and understanding, and they are honest in a compassionate and gentle way. Like there is a lot to be said. Well, I'm just just what I'm like, I'm I'm just authentic, you know, I'm just blunt. And you're like, no, you're a whole, like, there's a difference. It's called a choice. Like the way in which you give information, oddly, we think bluntly, like blunt, because I'm notorious for being blunt. Blunt is great when you're trying to break through a misconception or a blocker mentally. Like, I can't see something. So then I need someone to be very blunt and sharp with me to give me a very specific example. They even have an acronym for this, but it's like it needs to be specific, it needs to be recent, and it needs to be um tailored to exactly what you're talking about. And that's great, those are great moments to be blunt. But for the most part, most of us grow gently. That's how lasting effect occurs. Just like even in physical fitness, just because you went to the gym for three hours doesn't mean you're gonna have a six-pack apps. It's these little gentle movements over time, right? It's a combination of efforts, but it's usually never harsh. It's usually we only realize the change when we reflect back. And that's when we realize we no longer are technically living at the same address that we once were. We're actually living in an entirely different zip code, and we can't hold ourselves these old beliefs that we had because we're no longer even living there. Our world is completely different now. And so I think there's a couple phases that go with that, right? One's the gentle transformation, and then the other one is letting go of old beliefs and which you used to operate by. So as far as coaching advice goes, I would say there's all of that. There's a lot of context when it comes to coaching that I always try to bring in. Um, but at the end of the day, who do you want to be? Who do you want to present? Because whoever you present is actually who you are. Like we don't like to own that, but the reality is how you act towards other how you act towards people you do not respect is actually a reflection of your character. Everyone can be nice to people that they care about, that they love, that they respect. It's when you don't respect them. That's when it actually matters. Because that's what actually dictates your level of respect for yourself. Right? Because we're all in different seasons of life right now. We're all constantly transforming. Um, and then showing up with that intentionality. What do I think a good employee is? What do I think a good leader is? What do I think a good follower is? And actually, like I've written down these lists of what that is to me, and then I'll pay attention and then I'll watch myself. Am I being a good follower? Am I giving clean feedback? Am I giving objective feedback? Am I objectively receiving feedback and then filtering out what might be some bias? Am I personalizing everything or am I pausing with it, sitting in the ick, the uncomfort, and then making a decision do I want to stay this way or do I want to change? Or confirming with very close friends that I consider white counsel. So to summarize, pay attention to who you are now. Just watch it. Write down who you actually want to be, put it in practice, and then have a lot of grace and forgiveness, and just know the gentle small changes and nudges are what's actually going to last. And the more we treat other people with those same concepts, the more we'll be able to watch our peers, your leaders, and followers grow as well.
Pedro KertzmanWow, that is amazing. Thank you. And Kat,
OBTS Talk And DPRK macOS Research
Pedro Kertzmanwhat's up next? What's gonna coming up down the pipe?
Cat SelfSo I just got accepted to Objective by the Sea. Are you familiar with that conference? No, oh, that is probably one of my favorite conferences in the world. Like I've been all over the world, and there's a couple of them that stand out. But OBTS, Objective by the Sea. Okay, hands down my favorite conference. Hands down. Just the people are great, the community is great, it's in Hawaii, sometimes it's in Spain. It's just one of those conferences where it's the elite exploit developers, the elite hackers of Mac OS, we all congregate at this conference, and only 250 of us actually get to go. Oh wow, and we get to share all of the insights and ideas. And the conversations after the talks, just like the conversations during the talk or the the presentations during the conference, they're so rich, and it's just phenomenal. Like just the quality of humans there makes me grateful that I get to exist in this community. So, point is I'll be presenting there because I got accepted. And I think you guys are gonna like it. Um, so I have this whole theme I'm doing because I'm super, super nerdy. And I also used to be an artist in my former life. So I wanted to find a way to integrate art with technical presentations. And I started a couple years ago when I was at MITRE and I was at MITRE attack, and I hired a web artist to uh do a comic strip. We called it drawing out the pandas, and it was here's all the updates, but in comic book form. So I literally walked through a comic and like explained like how gatekeeper works, purely visual, like it's like a legit comic. And then I've kind of wanted to continue that on. So, but this time in my new role at Title Cyber, I'm doing like deep research, right? So I'm tracking actors, I'm breaking on their malware, I'm looking over the last five years of campaigns, understanding different components, when what was run, what was the security landscape like at that time? What how did Apple counter that landscape, right? What were the reactions from the DPRK from that react? Like, where does the innovation at? How have things moved around and shifted? And so that presentation will be done by me and Kate Espree. And so, because we did a black hat presentation for the attack evaluations. So now we're actually going to do like six months of research and then present the macOS like landscape of DPRK at OBTS. And then I'll be using a web comic, which kind of like a web tune, to be able to tell the story all the way from like meat slaps to water in the face to like so-and-so is a secret millionaire, you know, and this is like the the son of a Chibal family. Like, there's our however you pronounce it, I read a lot and I never hear the words. So that comes up with some really word translations. But the it's just a fun way to be able to present information and have fun with it. So we'll be doing that. Um, and I'll be releasing blogs pretty much the entire time on that research until OBTS in November. And so, everyone, if you want to know my methodology for the way I go about hunting actors, if you want to understand um different reports, the way I look at them, analyze them, how I pull procedures from them, pull fingerprints, I'll be publishing those and releasing those.
Pedro KertzmanOh, that's amazing. Well, congrats on presenting there. It looks like a very, very selective top expert group, and you're so deserved to be there. And uh any final thoughts for the listeners for those that are analysts.
Final Advice And A Healthier CTI Culture
Cat SelfIf you're new, it's very normal to be overwhelmed. They I am gonna say this because it annoys me. We all talk about imposter syndrome, FYI, we all have it. Move on. Like, what is next? It's like one of those like and like we all have it. Like it's not a defining factor of us, nor is it something like it's something to be like paused on, wonder where it's coming from, change the way you base your identity, and then move on. Like it's not a defining factor for why you are the way you are. Like, there is nothing that trumps your choice of how you respond to a situation. So just know that, like, absolutely have grace with it, understand it. We all understand it. Um, but also just walk forward in it, right? Like, if you're walking through hell, don't pitch a tent. Keep walking and you'll get through it because eventually you'll find, oh, this was all a lie. We're all learning, and you move through it, and then you know you you have it in a different area, and then you go enjoy walking through that in a different area. So just FYI, it's a very normal thing. Just keep walking, you know, be like Dory, just keep moving, and it'll be okay, it'll work itself out. Just trust, like do the footwork and trust the process. And for those that are seasoned in CTI, just have fun. I know we can get real serious. Um, if you're in classified spaces, like don't forget that there is a world outside, I don't know. I just I've run into a lot of people that are in classified spaces and the toxicity is high. Um and I just I want to empathize, but I also want to throw out there that pay attention to the way you allow people to treat you and and change that atmosphere up. A lot of times there is a law of reciproc reciprocity, and that law is basically think when you walk into a door and like you hold it over from somebody, odds are that person's probably gonna hold it open for the next person. So we have this like social thing. So, with that said, if you're inside of a toxic environment, A, just start looking for another job. Um, but B, also like remember there is that law. So the more we treat others in a way in which we want to be treated, it actually does change the atmosphere, even though it does feel unfair. Because at the end of the day, they just look more like their character that they're displaying. And you get to be at the end of the day, like this is how I conduct myself. So good luck with it. Nothing trumps that, but it's it's one of those things that we face in our industry when we get really, really specialized and really, really isolated. Um, so just hang in there and do your best to make it a better environment.
Pedro KertzmanI love it. I love it, could not agree more. Kat, thank you so much for so many insights. Love the conversation. I really appreciate your coming to the show, and I'll hope I'll see you around. Thank you.
Cat SelfThank you.
Subscribe, Connect, And Closing
Rachael TyrellAnd that's a wrap. Thanks for tuning in. If you found this episode valuable, don't forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn group, Cyber Threat Intelligence Podcast. We'd love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay tough and stay sticky.