Cyber Threat Intelligence Podcast
Welcome to the Cyber Threat Intelligence Podcast—your go-to source for staying ahead in the ever-evolving world of cybersecurity by harnessing the full potential of CTI.
In each episode, we dive into the latest cyber threats, emerging trends, best practices, and real-world experiences—all centered around how CTI can help us defend against cybercrime.
Whether you’re a seasoned CTI analyst, a CTI leader, or simply curious about the digital battlefield, our expert guests and host break down complex topics into actionable insights. From ransomware attacks and insider threats to geopolitical cyber risks and AI-driven security solutions, we cover all things CTI.
Join us for in-depth interviews with industry leaders and experienced professionals in the Cyber Threat Intelligence space. If, like me, you’re always in learning mode—seeking to understand today’s threats, anticipate tomorrow’s, and stay ahead of adversaries—this podcast is your essential companion.
Stay informed. Stay vigilant. Tune in to the Cyber Threat Intelligence Podcast.
Cyber Threat Intelligence Podcast
Inside the Red Team and CTI Relationship: Intel Quality, Feedback Loops, and Blind Spots (William Wright & Pedro Kertzman)
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
A single sentence from the right threat intel analyst can blow up weeks of planning and that’s exactly why we love it. Pedro Kertzman sits down with William Wright, CEO of Closed Door Security, to dig into cyber threat intelligence from the attacker’s end of the table: red teaming, threat-led penetration testing, and the real-world frictions between CTI, SOC teams, and offensive security.
We get specific about what “actionable intelligence” actually means when you’re the person who has to run the TTPs. William breaks down how DORA and TIBER-EU style engagements push CTI reports toward clearer structure, and why some deliverables still miss the mark. If a report is just a dump of IOCs, file hashes, or a heat map that paints nearly everything red, it doesn’t guide testing or improve detection and response. The value shows up when intelligence connects threat actor behavior to runnable scenarios and helps defenders tune telemetry and playbooks.
The best part: the human layer. We talk about why a short report plus a walkthrough call can beat a “perfect” document, and how those conversations uncover fresh leads, nuance, and the kind of context that never fits on a page. William shares a memorable example from a trading platform where internal CTI advice changed a phishing plan instantly by steering the team toward contractors instead of traders.
If you want stronger CTI programs, better red team outcomes, and tighter feedback loops between CTI and security operations, hit subscribe, share this with your team, and leave a review. What’s the most useful thing you’ve ever gotten from threat intelligence?
Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!
Welcome And Guest Setup
William WrightBeing able to confidently say that and black out with evidence is a super power...
Rachael Tyrellhello and welcome to episode 13, season two of your Cyber Threat Intelligence podcast. Whether you're a seasoned DTI expert, a cybersecurity professional, or simply curious about the digital battlefield, our expert guests and hosts will break down complex topics into actionable insights. On this episode of season two, our host Pedro Curtisman will chat with William Wright, who is CEO of Closed Door Security and a Chartered Security Professional, an offensive security firm based in Scotland. He works at the attacker end of the discipline, running red team and penetration engagements that surface how organizations actually get free and turning what his team finds into intelligence clients can act on. Over to you, Pedro.
Pedro KertzmanWilliam, thank you so much for joining the show. I'm really happy to have you here.
William WrightThanks, Petro. I'm really excited to be on. This is my first Threat Intel specific podcast, so it's gonna be interesting.
Pedro KertzmanAmazing. And I think it's really uh interesting to have you here today because your experience is mostly focused on offensive security. So it's really also interesting because no security team works alone, as we shouldn't. So it's gonna be really nice to hear your perspective working with CTI teams and your experience in interacting with the CTI folks and hearing you know best practices around this, these experiences and all that. So would you mind kicking it off? You know, talking maybe, you know, one or one of those stories uh that you had in the past about interacting with CTI teams? Yeah,
Threat-Led Pen Testing Basics
Pedro Kertzmansure. So I think we can kind of go through what I do day to day and then how that how that actually comes into uh CTI. So my my job day-to-day is really red teaming or threat-led pen testing. So for most of the people listening to this, they will understand what threat-led pen testing is. But for the uninitiated, what that is is uh a standard methodical pen test that's enriched with TI at the beginning to set up scenarios, so not quite a red team, but also not too far away either. It is a planned process rather than you know, red team is an objective-based thing. It's go and try and do this however you can. Whereas the threat-led pen test is really looking at okay, these threat actors are targeting this industry, this company specifically. Here's the TTPs, here's some information about them, off you go, try and emulate those. So, quite often what we're doing is around Dora or um something aligned to Dora and the the Tiber uh EU rules. What that is, is it means that there's either a regulator sitting in checking the threat intel aligns with what they want, and that the pen test being, or sorry rather, the threat-led pen test being done aligns with what they want, or that it's uh to follow the rules loosely. So if it's not a regulated one, it just means here's the rules, here's what you need to follow in order to meet the requirements. Now, the the interesting thing about um the Tibber stuff specifically is it gives you a really good structure for the TI
DORA And TIBER-EU Intel Structure
Pedro Kertzmanreport. What's also interesting is not everybody's good at putting stuff in that structure. You I've seen everything from absolutely incredible reports which are really precise, give you clear guidance right the way up to you know a 240-page threat intel report which is full of like 400 file hashes. And it's like, okay, come on, what am I going to do with this? There's no guidance, there's no there's no real pointing on what I'm gonna do. Um, but the the reports are made up uh of uh a couple of different sections, and there's there's it it almost works through in like steps. So you've got like the overall scope that's being covered, actionable intelligence assessment, and you've got the threat intelligence analysis, the threat actor profiles, TTPs, threat scenarios, and then really interesting is at the end of the reports, it's almost like this carte blanche for the the CTI analyst to say, yeah, all this stuff above, but these scenarios and these threat actors actually might also apply. So it gives them a little bit of creative liberty to go off and think about the process and what's actually going on. And I've seen some really interesting stuff, especially in that last section, you know, where there'll be uh an attribution made to an attack that a threat actor's done in a totally different industry, but they'll provide really good evidence that points to say actually this threat actor might be specifically targeting like this bank or or industry or whatever it is that we're looking at. And you can completely uh from a red team perspective, you can go from thinking, okay, I'm gonna go down this line of attack, I'm gonna go down these scenarios, look at these TTPs, and then there's this just curveball comes in like, well, where did that come from? You know, and you're one one minute you're looking at identity stuff specifically, you know, maybe fishing, social engineering, that kind of stuff, and this curveball comes in. Actually, there's there's some IOCs over here that you might want to take a look at from a totally different threat actor, but we think they're inside that network. It's like, where did that come from? Didn't expect that. So it it's a really interesting to be on the opposite side of that. Now I know the work that goes into um generating these reports. I've got a few friends who work in Threat Intel, and I love to just say they just sit on Twitter and Telegram all day reading posts and share me. I think that's I think that sums up the industry. But they you know, I get I get as good as a give, no doubt. Um, but they it it's such an interesting world to be able to take a huge amount of data and narrow it down, especially with attribution. I find that such a fascinating uh theme. How they can just go, right, I'm looking at this whole industry, this this business in specific, uh, this business specifically. I've got tons of data, literally petabytes of data available, and I'm gonna crawl through this and find the exact attributions that I need in order to make your job
When Intel Derails The Test Plan
Pedro Kertzmanas easy as possible, or in some senses to make a really long bedtime read. Yeah, that's that's the very tricky part. No, that's that's very interesting. To to double down on the uh threat led pen testing. Is it fair to to say that that initial assessment can completely derail your work? So if the initial assumptions are um even slightly wrong, it completely derail the results of your you know work down the line. Yeah, and and but because the the there's a couple of different outcomes expected from a threat-led pen test, and one of them is the detection and response. So, in order to have accurate detection and response, you need to be running accurate GTPs against whatever the infrastructure is. So if you make assumptions, you know, so when we're initially scoping it, obviously we don't have the threat intelligence at the start. So we um in fact, I I can state this we we don't do threat intelligence. So whenever we're working on a threat-led pen test, either the regulator or the bank will bring in their own threat intelligence team, or they'll go to market and find um whichever threat intelligence they want to use. So you can you you have to make some assumptions, um, do a little bit of threat modeling. I'm again not an expert, absolutely. I've got it wrong many more times than I've got it right, but you usually from experience you can kind of guess what it's going to be. So you align, you you make your initial test plan, scope it out based off of that, and then a good threat analyst out then. This is this is key, a good threat analyst will come and ruin my day because they'll go, actually, here's where you're wrong, here's what you should be doing. Of course, that's a bit of a pain, but it means the customer ends up getting a much better product and everybody's safer. But the just being able to come in, and I think that's the powerful thing about threat intelligence, if it's done right, is you can completely change a program of works with a couple of sentences, yeah. Like literally a couple of sentences. Like I've had I've I've received reports, like I said, hundreds of pages long, so ones that are a couple of pages long, but some of the best ones I've ever had, and uh any any guys that work in um in the regulated uh Dora and um CBS, etc., will understand this as well. The best ones are short, concise, straight to the point, but are then delivered to the testing team by a call.
Why A Walkthrough Call Wins
Pedro KertzmanNot yep, send the report in advance, but then sit down and talk with the team actually delivering it. There's so many little tidbits that come up when you're actually speaking to somebody that you just can't quite write on a report. You know, you go through, go through it, go through the intelligence, say, Yeah, we'll find these TPs. But you know, actually, when I was looking and digging through, I did see some other stuff, and this is you know, I can't write on the report, but have a look into this stuff now. It and it it becomes a much more um valuable experience for for for me and for for my team interacting with the threat intel teams like that. That's that's very interesting. Would you say that is this because it's almost like it's gonna guide everybody through the thought process around the report and not only the verbatim, like it's more like to tell the story behind the report, or what that is? What why is it so important when you have that call to actually walk people through the report? I think a lot of us, and I fall follow of this as well, in our industry are not very good at communicating in written form. In written form, it's it's a struggle to get the technical details, the experience, the knowledge, the wider knowledge condensed down into a report. Some people are fantastic at it, but the vast majority we all we we struggle a bit. So being able to have a call with somebody who understands what you're talking with. I know threat intel teams usually depending on where they work, they usually get the cold shoulder, like, yeah, yeah, yeah, another report. Yeah, cool, cool. That threat actors doing something interesting, cool, cool um ex-feed that. Yeah, uh, but actually, somebody who's interested in it and and uses that threat intelligence, the conversation opens up. And I've I've seen on a personal level, like people who uh we work with open up and become really friendly, and and you know, where they're generally pretty shy and non-communicative and stick to the reports, especially over email, can be pretty dry. But you get on a call and it's really friendly, really talking if a 15-minute call ends up being two hours and you're chatting about all stuff, but in between that you get the their experience and their almost um innate knowledge that you just cannot write down, and that's what I think. So obviously, a lot of people are using AHI for threat until now. That's it's just what's happening, it's where the world's going. And I don't have a problem with it, as long as it's done right, don't care. Yep. But the great thing about having a person at least interpret and and understand the results and put them across to us verbally means that we can understand all of those tiny little details that just can't get written down, or maybe something gets forgotten, you know, they they might have seen something, and in the conversation you go, actually, you know what? I saw something on a forum a couple of weeks ago after I wrote this report that's totally different from what's on there. It's like, oh great, wonderful. That's really useful. Show me that, give me the link. That's interesting. So you can uncover more things to all that conversation that's not necessarily part of the initial uh report. Yeah, and then obviously, if it's a regulated um test, they go back and update it if there's anything new. If we think it's valuable, go back, update it, resubmit it to the regulator, get them to approve. Um, but when it's a non-regulated test, it it just lets us steer the test more accurately. Um obviously the the end result is value for the client. We want we want to accurately as possible um simulate doing these attacks of threat actors would so that they can build their detections and exercise the response. Like that's that's one of the main purposes. So making sure that we can do that the best and most efficient way possible means they get the best value for money, which means everybody wins. That's that's that's really awesome, William. Thank you. Any other interesting stories about interactions with um CTI teams, or you know, any time you had a chance to interact with CTI folks um internally or during your um offensive security exercises?
The Contractor Phishing Twist
Pedro KertzmanSo the the there was one, so there was an um we were working with a trading platform is the best way to describe it. Working with a trading platform, um, and they had their own internal threat intelligence team, and we were allowed to speak to them all almost purple team, but not quite. Like we had a line in, we could speak to them, discuss what we were planning so that they could feed it back. Uh and I remember on the call, he said to me, because we we were going to go down fishing, fishing was the number one threat for them. That was the model, that's what we were gonna try and do. Um, and he said to me, he said, Don't even bother trying to fish the actual traders because they report everything. Said, however, go for the contractors. I was like, Oh, that's a really juicy bit of information, and obviously we avoided the traders within that company, went to the contractors, fished them successfully, nothing got reported, and then started building out the TTPs beyond that. So those little tidbits of information that you normally wouldn't know because the first thing you think in a trading platform is right, I'm gonna go straight for the traders, they're doing really high focus work, they're not gonna pay attention. Turns out that high focus is also on the security side of stuff, they're really conscious about it. Uh, that's a really interesting um titbit that came from inside the company to help us, and their um value in doing that was they got to see what actually happens if one of the contractors do it so they can go out and and actually enhance their own intelligence because if we just went straight for the the traders, they'd report it and you know the scenarios would be dead essentially. You know, you'd be you you'd struggle then to get a foothold. But because we were able to get a foothold for them, it's much more interesting because then they can follow us through, look at what's going on, do some threat on it, figure figure out where we are, um, watch the socks struggle to find us and laugh at them. You know, they can have a bit of fun with it. Um, the I I know I mentioned already the uh you know the on calls, um, but I did once uh a few years ago, we'd ordered threat intel for a specific job, and no report ever came through. And it was me and the guy just sat on a call for four or five hours, and he talked me through all of the intelligence he had gathered bit by bit. So we went through the the full payment pyramid, like right away from file hashes all the way up to the TVs, everything. He was like, Here's everything that I've got. What are you interested in? Help, and he his question to me was help me shape this so that it's useful for you. Now, to be fair to him, um, he wasn't inexperienced, but it was his first time doing that style of report. So he was looking for a bit of help. Um, but going through that process, he learned massively. But I also meant I could use my experience and say, right, I know what we can run against this company, I know the kind of stuff that we and tooling that we've got available, so I can narrow this down and we can really start to refine this report together. And that's something I think a lot of uh TI folk maybe forget, especially if you're feeding into the red team. It's we are the ones running it. Speak to us. Like we can help make your product better, which makes us better, which makes the whole function of security better. Like there's just there's no downside to having a good communication link with um with your red team. Um, we do we do we've got a number of partners who have their own threat intelligence teams. We have open teams with them constantly. Whenever they find something interesting, even if it's not us, like you should have a look at this, it's really cool. It's like, okay, great, let's go, let's go have a look and play about with it, start running in the lab,
Shaping Intel With The Team
Pedro Kertzmansee what we can bring up. Um, and we'll sometimes actually run IOCs that they say and try and um backtrack them to to build the tooling so that we can build the full detection with them, and that's come from somebody in TI going, actually, this looks really cool. I found this repo with a really cool exploit. Can you see if that works? And then going through it together. It's a rare thing as well, which is I I find weird. Um the there should be that communication now. Typically, or at least in my experience, threat intel um informs the stock. Yeah, that's the way it usually or or if it's uh if it's a customer buying it, whatever. They're usually going inwards, not outwards. And I think if there's a dedicated team anyway, obviously not just willy-nilly throwing intelligence around, but if you've got a dedicated team, they should be involved in the process and just it makes everybody better, helps us sharpen our sword, helps them find better intelligence, helps the sock detect things better. It's a win-win-win. Yeah, no, I I love this example because it's uh it's in other words, it's also like focusing more on the end goal and not necessarily on the task, right? So you're you're literally like teaming up to get a better or even faster, if you will, instead of going back and forth, or here's the report, or here's like some information, do whatever with it, and then you wait for somebody to come back, and then back and forth multiple times, and and expecting that at some point somebody will have results, like proper results out of it. So instead, like you mentioned, you jump on a call, here's everything I got. Doesn't make sense. How can I fine-tune this for you? Right, and then and then you can get that's that's very interesting. Yeah, it's definitely uh an interesting best practice suggestions to have with your um like you mentioned, it could be a red, purple teaming exercise to to have that first um, if you will, alignment call, initial kickoff call, or so on and so forth. Yeah, yeah. I like to I like to physically sit next to people when I can. Um I like to go and sit with them. Obviously, it's not possible all the time. Um, but I've had so many interesting conversations over lunch when we're trying to, you know, maybe uh go through a threat intel report together rather than go on a teams call. It's right. How about uh, you know, if I'm if I'm nearby, I'll pop along in the office, go for lunch, talk me through. And it really takes the barriers down and it lets the the the guys and girls doing the threat intelligence really come out of their shell. Because sometimes uh I I know that from from experience working in offices and stuff, you end up kind of fitting your specialisms around what is the requirement of the business you're working in. As soon as you come out of that environment, you're almost got this um creativity that comes out. And let's be honest, that threat intel is a form of creativity in my mind. You have to be creative in a specific way to be able to pull all this data in and and have all the tools in the world, but if you can't think about it creatively, you're not gonna get anywhere.
Bad Reports Come From Bad Process
Pedro KertzmanI mean, uh don't get me wrong, I've also seen some really bad stuff. Like I remember once um we got uh a report uh with the quotation marks, and it was uh it was a heat map of the the the uh ATT and CK navigator map, and it was just 90% red, like almost all of it was red. I was like, great, thanks. This isn't intelligence, this is a mood board. What am I gonna do with this? And then the the the the flip side as well is you know, I've um like I said I mentioned earlier, there's one report with just like 400 file hashes and IP addresses in it. Great. How am I gonna behave as an IP address? Thank you. There's there's there is the downsides to it as well. We've seen some really, really bad stuff over the years, but thankfully the individuals usually fix it, and I think it's more just the processes that they get made to follow. Like I've never met a bad TI person ever. I've met bad processes. That's interesting, yeah. So we um you know, gotta team up to fix those bad processes, exactly. Yeah, yeah. Yeah, because it's in in our line of work, we don't get to choose who gives us the threat intel. We get told this is who's given you it. So if it happens to be bad or or not useful, it's very in my interest to be able to work with them to give us the what we need. And if that's just says, you know, if it's if it's spending an hour or so with them, said here's here's the you know, the IOCs I need, here's the TTPs, please structure them this way, get out, you know, here's a reference to work off for building the reports, etc. That hour will pay off way more than that further down the line for me when we actually start running the engagement. So I I think it's really valuable. Any other interesting stories about your CTI interactions? I think there's there's so many who really but what I can say is I've made some great friends over the years from this kind of engagement, so from just having having uh use having as as the literal word, having to work with specific people to get threat intelligence. Some of those people we become really good friends, great acquaintances, you know, uh spend time together. And and I would say I've I've built a a repertoire of friends in threat intel who I can call on at any time and who can call on me at any time, knowing that you know it's friendly terms, not professional, and it's just such such a weird thing as a as a pen tester to say like some of my friends are in threat intel. It's like it should be the opposite, should be friends in the sock, not in threat intel. Nice, and um that's that's amazing, man. Glad to hear that. And um any final thoughts for the for the listeners?
William WrightI think um it's
Attribution As A True Superpower
William Wrightknown the limits, you know. I I I genuinely believe, genuinely believe attribution is the hardest job in the world. I I do not think there's anything more difficult to say accurately than attributing that was them when they don't announce it, and even when they do announce it, that was that threat actor that did it. Um and being able to confidently say that and back it up with evidence is a superpower. So anybody who's working in threat intel, if you're able to accurately attribute um IOCs, TTPs, etc., to a threat actor, you're at the top of the game and awesome work. Keep it up, keep going because that is incredible.
Pedro KertzmanThat's amazing, William. Thank you so much for sharing your experience with us and all those awesome stories. Thank you so much for coming to the show, and I'll hope I'll see you around. Thank you so much.
William WrightPleasure, Pedro. Thank you.
Rachael TyrellAnd that's a wrap. Thanks for tuning in. If you found this episode valuable, don't forget to subscribe, share, and leave a review. If you've got thoughts or questions, connect with us on our LinkedIn group, Cyber Threat Intelligence Podcast. We'd love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the channel, just let us know. Until next time, please talk and then you're not going to be able to