
0x2F3 - Teknik - La place du tooling dans le threat intelligence CTI
Keywords
Summary
185 words
Critical Evaluation
Value of the Information & Strength of the Argument
The episode provides valuable insights into the practical application of tooling in a CTI team, offering concrete examples of how automation and AI can significantly enhance efficiency. The argumentation is solid, grounded in real-world experience, and the speakers articulate clear rationales for their tooling decisions, such as the trade-off between manual work and development time. They also highlight the importance of ergonomics and user adoption, which is a nuanced perspective often overlooked in technical discussions. The narrative is coherent and well-structured, moving from specific case studies to broader principles.
Scientific Rigor, Source Quality, Title Accuracy
The scientific rigor is high given the expert nature of the content. The speakers are experienced professionals, and their descriptions of tools and workflows are detailed and plausible. However, no external sources are cited, and the discussion relies solely on their internal experience. The title accurately reflects the content, focusing on the role of tooling in CTI. The episode does not include any promotional segments. No comments were provided for analysis.
175 words
Title / Content Match
The title accurately reflects the content, which focuses on the role of tooling in CTI, with a technical discussion of internal tools and AI integration.
Quality & Reliability
8/10
The episode features two experienced CTI analysts from Sekoya's TDR team, discussing their internal tooling and workflows. The information is practical, based on real-world experience, and includes specific examples (e.g., APT28 campaign, MCP server, Sara orchestrator). No external sources are cited, but the credibility of the speakers and the detailed, coherent narrative support a high reliability score.
Key Moments
Markers derived by PSI from the transcript: the creator did not define chapters.
- Introduction of guests and their roles in the TDR team.
- Discussion of the APT28 campaign and initial reverse engineering challenges.
- Introduction of the MCP server and the Sara orchestrator for automated analysis.
- Overview of the internal tooling ecosystem, including caching server and Maltego transforms.
- Discussion of custom tools like Tracker and Irma for infrastructure tracking and hunting.
- Emphasis on ergonomics and web-based interfaces for tool adoption.
- Impact of AI on prototyping and knowledge capitalization, and future consolidation plans.
Contribution & Novelties
This episode offers a rare, behind-the-scenes look at the internal tooling of a CTI team, highlighting the practical integration of AI and automation in threat intelligence workflows. The discussion provides actionable insights into building an effective tooling ecosystem, emphasizing ergonomics and user adoption. The speakers share specific examples and lessons learned, which are valuable for other CTI practitioners.
Pour aller plus loin :
- Model Context Protocol (MCP) — Official documentation for the protocol used to connect LLMs to tools.
- Maltego — A commercial OSINT tool used for link analysis and data mining, relevant to the discussion of transforms.
- Flosint — An open-source alternative to Maltego, mentioned in the episode as a future migration target.
114 words
Radar Profile
The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level, reflecting the episode's focus on practical tooling rather than deep technical details. The overall balance indicates a well-rounded and informative discussion.