CTI in Agentic Times: Practical, Verifiable, and Hybrid AI Deployment in Cyber Threat Intelligence // Costin Raiu, Vicente Diaz

In-Person | November 2-4 | 3 Days

BOOK NOW

ABSTRACT

This intensive training course is specifically designed to modernize the operational capabilities of Cyber Threat Intelligence (CTI) teams through the realistic, pragmatic, and unbiased integration of Artificial Intelligence. Tailored for CTI analysts, this program skips the commercial AI hype to focus on immediately deployable CTI use cases: from automated OSINT ingestion to localized malware analysis and AI-assisted detection engineering.

Our approach is based on hybrid architectures where traditional deterministic systems coexist with local and remote language models. We move past basic prompt engineering to teach analysts how to build secure, localized, and auditable CTI pipelines using containerized infrastructures, strict multi-agent validation loops, and automated verification layers.

WHY THIS TRAINING?

In the current technological landscape, organizations face heavy corporate pressure to adopt centralized, cloud-based AI tools. However, this "cloud lock-in" presents severe risks for high-security environments—including data leaks of sensitive indicators, high token costs, and a lack of control over model updates. Furthermore, government and critical infrastructure entities must navigate the geopolitical and privacy implications of using proprietary models or foreign open-source models.

Worse still, AI outputs carry an "authority bias," delivering highly convincing threat reports that can contain silent, critical failures. This training is essential because it provides CTI professionals with the architecture to build their own ownable, secure, and fully auditable agentic pipelines. By focusing heavily on local model execution, deterministic guardrails, and multi-agent validation, this course transforms AI from an opaque, rented service into a sovereign, defensive capability.

KEY LEARNING OBJECTIVES

Automate Core CTI Use Cases: Build practical workflows for OSINT collection, campaign tracking, actor profile generation, alert triage, and vulnerability evolution.

Accelerate Detection & Analysis: Use AI to generate syntactically valid detection rules (YARA, Splunk SPL, Sigma) and securely assist in script and malware decompilation.

Master Hybrid CTI Architectures and agentic governance: Learn when to use simple LLM skills, iterative loops, full agentic workflows, or secure micro-VMs (like Firecracker/isolated Docker sandboxes) for different analytical loads.

COURSE AGENDA

Module 1 - Foundations, Hybrid Architectures, Local Infrastructure and Multi-Agent Governance

Core CTI AI architectures (Skills vs. Loops vs. Agents). Local vs. Frontier LLMs: privacy, costs, and data sovereignty. Evaluating the geopolitical and security risks of using open-source variants (e.g., Chinese models) in government/enterprise. Introduction to isolated execution (Docker vs. Firecracker sandboxes).

Lab 1: Deploying a Sovereign CTI Sandbox
Setting up a localized inference stack (Ollama/vLLM) on private infrastructure to run specialized small models (8B-70B parameters) for CTI processing without external network dependencies.

Module 2 - OSINT, Campaign Tracking, and Alert Triage

Automated OSINT collection and report summarization. Building structural databases to track threat actor profiles, vulnerability evolution, and historical campaign records. Designing automated alert triage models to screen and prioritize high-volume security alerts.

Lab 2: The Automated Campaign Tracker & OSINT Ingestor
Building an agentic pipeline that ingests raw, unstructured threat blogs and automatically maps them into structured threat actor profiles, logging vulnerability timelines and updating campaign timelines.

Module 3 - AI-Assisted Investigation and Detection Engineering

Leveraging LLMs as co-analysts to guide active investigations. Translating raw CTI intelligence into actionable detection rules. Prompt engineering and validation frameworks for generating error-free YARA rules, Splunk SPL queries, and Sigma rules.

Lab 3: Automated Rule Generation and Syntax Verification
Developing a pipeline that takes raw threat indicators and context, automatically generates YARA and Splunk detection rules, and passes them through a deterministic validation test to ensure syntax validity.

Module 4 - Malware Analysis

Safe execution of code/script-analysis tasks using long-horizon agents in micro-sandboxes. Governing agent behavior: managing non-deterministic outputs. Multi-agent validation: using model diversity and "critique agents" to peer-review, verify, and audit output quality.

Lab 4: The Multi-Agent Peer-Review Sandbox
Deploying an execution agent inside an isolated container to parse a malicious obfuscated script. A separate "validation agent" automatically cross-examines the analyst agent's findings against a structured rubric to detect errors.

Prerequisites

  • Core CTI Knowledge: Familiarity with threat actor profiling, indicators of compromise (IoCs), and traditional threat reporting workflows.
  • Basic Python Programming: Ability to read and understand scripts used in automated pipelines, local inference tools, and agentic orchestration.
  • Command-Line Familiarity: Comfortable navigating terminal environments (Linux, macOS, or Windows PowerShell) and editing JSON, Markdown, or YAML configuration files.
  • Container Fundamentals: Basic knowledge of running and managing Docker or containerized environments for local sandboxing.
  • Reverse Engineering Awareness: Basic familiarity with script analysis and compiled binaries (such as PE structures or .NET assemblies) for malware analysis automation modules. Detailed reversing experience is not necessary.

What Students Need to Bring

A student setup guide will be provided to students prior to the course start date.

  • Admin-Privileged Laptop: Full root or administrator access to install software, modify firewalls, and run container environments. Alternatively, running everything inside a dedicated local Virtual Machine (such as VMware or VirtualBox with nested virtualization) is recommended for clean malware isolation and uniform environment setup.
  • Hardware Specs: A modern multi-core processor (Intel/AMD or Apple Silicon) with at least 16GB of RAM (32GB recommended for local open-weight models) and 50GB of free SSD space for model weights, containers, and malware artifacts. An NVIDIA GPU with 8GB+ VRAM is heavily recommended for local inference engines.
  • Pre-Installed Software: Docker & Docker Compose, Git, a code editor/IDE (VS Code or Cursor), and optionally Ollama or vLLM for local inference.
  • Antivirus/EDR Exclusions: Pre-configured exclusions for designated course working directories to prevent live malware samples and scripts from being automatically flagged and deleted.
  • Optional LLM Subscriptions & Keys: Bring your own personal or corporate API keys (Anthropic, OpenAI, Google Gemini) for benchmarking and testing against pipelines alongside provided local open-weight models.

YOUR INSTRUCTORS: Costin Raiu, Vincente Diaz

Costin Raiu is a cyber paleontologist and researcher specializing in analyzing advanced persistent threats and high-level malware attacks. He was most recently the director of GReAT, the team that researched the inner workings of Stuxnet, Flame, Duqu, Turla, Lazarus, Moonlight Maze or the Equation Group.

Costin has over 30 years of experience in ITSec, having written his first antivirus when was 16. He is a member of the Virus Bulletin Technical Advisory Board, a member of the Computer AntiVirus Researchers’ Organization (CARO) and a founding member of TLPBLACK, a visionary cybersecurity company.

Costin enjoys playing chess, taking photos and reading science fiction literature. He holds a 2 DAN black belt in Taekwondo.

LinkedIn: https://www.linkedin.com/in/craiu/
Twitter/X: @craiu

Vicente Díaz is a cybersecurity researcher and specialist in threat intelligence, threat hunting and the investigation of advanced threats. Most recently, he worked at Google, where he was a Threat Intelligence Strategist for VirusTotal and a Product Manager for Google Threat Intelligence.

Vicente has more than 15 years of experience in cybersecurity. Before joining Google, he spent almost a decade with Kaspersky’s Global Research and Analysis Team—GReAT—where he served as Deputy Director for Europe and co-created and managed the company’s APT Intelligence Reporting service. Earlier in his career, he was the e-crime manager at S21sec for five years.

His work focuses on turning large-scale security telemetry into actionable intelligence, tracking sophisticated threat actors and developing practical methods for malware investigation and threat hunting. He has also researched the application of artificial intelligence to malware analysis and security operations.

Vicente holds a degree in Computer Science and a master’s degree in Artificial Intelligence. He is a progressive metal fan and has previously delivered many joint training sessions with Costin on practical threat hunting and writing effective YARA rules.

LinkedIn: https://www.linkedin.com/in/vicented/
Twitter/X: @trompi

Cancellation Policy

Cancellations are not permitted but attendee changes can be accommodated anytime prior to the start of the course.

Note: In the event of a class cancellation, Ringzer0 will endeavor to offer transfer to another training at no additional charge.
Virtual Training Oct 26-31 // In-Person Training Nov 2-4 / Conference Nov 5,6

OTHER IN-PERSON TRAINING COURSES

Great! Next, complete checkout for full access to Ringzer0
Welcome back! You've successfully signed in
You've successfully subscribed to Ringzer0
Success! Your account is fully activated, you now have access to all content
Success! Your billing info has been updated
Your billing was not updated