
Even with so many threat intelligence available, many institutions still struggle to operationalize that intelligence beyond briefings and indicator feeds.
Modern attackers operate with discipline: they share intelligence, automate techniques and continuously test their tradecrafts. Defenders, however, rarely share procedural threat intelligence. They silo purple teaming, detection engineering, and threat hunting into disconnected activities.
This talk introduces a practical framework for integrating:
Cyber Threat Intelligence as structured, actionable input and actually focused on adversary behaviour, rather than generalized tactics and techniques
Continuous Purple Teaming as validation and focused on threat-informed simulation attacks which are actually relevant to you.
Detection & Response as Code as the operational backbone. No more reports and waiting several weeks for implementation. Immediate detection-as-code ready to implement in your environment. And how relevant is a detection rule without a response rule?
Threat Hunting to proactively search for intelligence-aligned behaviours or hypothesis-driven hunts.
We will explore how intelligence on sector-specific threats like ransomware groups, payment fraud actors, supply-chain compromises and state-sponsored actors can be translated into detection hypotheses, adversary simulations, and codified detection logic that is version-controlled, testable, and continuously validated.
Date: 22nd September 2026
Time: 13:00 - 13:40
MSP
We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. By clicking 'Accept All', you consent to our use of cookies.