
CTI in Agentic Times: Practical, Verifiable, and Hybrid AI Deployment in Cyber Threat Intelligence // Costin Raiu, Vincente Diaz
In-Person | November 2-4 | 3 Days
BOOK NOWABSTRACT
This intensive training course is specifically designed to modernize the operational capabilities of Cyber Threat Intelligence (CTI) teams through the realistic, pragmatic, and unbiased integration of Artificial Intelligence. Tailored for CTI analysts, this program skips the commercial AI hype to focus on immediately deployable CTI use cases: from automated OSINT ingestion to localized malware analysis and AI-assisted detection engineering.
Our approach is based on hybrid architectures where traditional deterministic systems coexist with local and remote language models. We move past basic prompt engineering to teach analysts how to build secure, localized, and auditable CTI pipelines using containerized infrastructures, strict multi-agent validation loops, and automated verification layers.
WHY THIS TRAINING?
In the current technological landscape, organizations face heavy corporate pressure to adopt centralized, cloud-based AI tools. However, this "cloud lock-in" presents severe risks for high-security environments—including data leaks of sensitive indicators, high token costs, and a lack of control over model updates. Furthermore, government and critical infrastructure entities must navigate the geopolitical and privacy implications of using proprietary models or foreign open-source models.
Worse still, AI outputs carry an "authority bias," delivering highly convincing threat reports that can contain silent, critical failures. This training is essential because it provides CTI professionals with the architecture to build their own ownable, secure, and fully auditable agentic pipelines. By focusing heavily on local model execution, deterministic guardrails, and multi-agent validation, this course transforms AI from an opaque, rented service into a sovereign, defensive capability.
KEY LEARNING OBJECTIVES
Automate Core CTI Use Cases: Build practical workflows for OSINT collection, campaign tracking, actor profile generation, alert triage, and vulnerability evolution.
Accelerate Detection & Analysis: Use AI to generate syntactically valid detection rules (YARA, Splunk SPL, Sigma) and securely assist in script and malware decompilation.
Master Hybrid CTI Architectures and agentic governance: Learn when to use simple LLM skills, iterative loops, full agentic workflows, or secure micro-VMs (like Firecracker/isolated Docker sandboxes) for different analytical loads.
COURSE AGENDA
Module 1 - Foundations, Hybrid Architectures, Local Infrastructure and Multi-Agent Governance
Core CTI AI architectures (Skills vs. Loops vs. Agents). Local vs. Frontier LLMs: privacy, costs, and data sovereignty. Evaluating the geopolitical and security risks of using open-source variants (e.g., Chinese models) in government/enterprise. Introduction to isolated execution (Docker vs. Firecracker sandboxes).
Lab 1: Deploying a Sovereign CTI Sandbox
Setting up a localized inference stack (Ollama/vLLM) on private infrastructure to run specialized small models (8B-70B parameters) for CTI processing without external network dependencies.
Module 2 - OSINT, Campaign Tracking, and Alert Triage
Automated OSINT collection and report summarization. Building structural databases to track threat actor profiles, vulnerability evolution, and historical campaign records. Designing automated alert triage models to screen and prioritize high-volume security alerts.
Lab 2: The Automated Campaign Tracker & OSINT Ingestor
Building an agentic pipeline that ingests raw, unstructured threat blogs and automatically maps them into structured threat actor profiles, logging vulnerability timelines and updating campaign timelines.
Module 3 - AI-Assisted Investigation and Detection Engineering
Leveraging LLMs as co-analysts to guide active investigations. Translating raw CTI intelligence into actionable detection rules. Prompt engineering and validation frameworks for generating error-free YARA rules, Splunk SPL queries, and Sigma rules.
Lab 3: Automated Rule Generation and Syntax Verification
Developing a pipeline that takes raw threat indicators and context, automatically generates YARA and Splunk detection rules, and passes them through a deterministic validation test to ensure syntax validity.
Module 4 - Malware Analysis
Safe execution of code/script-analysis tasks using long-horizon agents in micro-sandboxes. Governing agent behavior: managing non-deterministic outputs. Multi-agent validation: using model diversity and "critique agents" to peer-review, verify, and audit output quality.
Lab 4: The Multi-Agent Peer-Review Sandbox
Deploying an execution agent inside an isolated container to parse a malicious obfuscated script. A separate "validation agent" automatically cross-examines the analyst agent's findings against a structured rubric to detect errors.
APPROACH
During training planning, the team consolidated several essential strategic factors to ensure maximum business utility:
Analytical Flexibility and Costs: Demonstrate how using small, specialized local models can compete in analytical quality with frontier models for bounded tasks, reducing operational costs to one-tenth and breaking dependency on excessive token consumption.
Local Model Evaluation: Investigate the operational feasibility and real trustworthiness of safely deploying open-source models or models from diverse backgrounds (including variants from the Chinese AI ecosystem), evaluating privacy benefits vs. local performance.
The Accumulated Context Problem: Analyze the disproportionate growth of context windows in agentic workflows, the progressive accumulation of errors in execution loops, and the drastic loss of quality when providers unilaterally modify safety alignments or token pricing.
MATERIALS
For the practical labs, the course will require the provision of the following technical infrastructure:
Local Orchestration Environment: Preconfigured repositories with structured Docker Compose files to spin up local inference layers (Ollama/llama.cpp), vector databases, and isolated execution sandboxes.
Adversarial Dataset: Samples of documented multi-turn sessions containing Crescendo-type attack patterns, goal hijacking, and indirect injections to validate session monitoring systems.
Malware and CTI Artifacts: Controlled malicious binaries (scripts, macros) and clean/annotated analytical databases (IDBs) for practical exercises in reverse engineering automation and report generation.
YOUR INSTRUCTORS: Costin Raiu, Vincente Diaz
Costin Raiu is a cyber paleontologist and researcher specializing in analyzing advanced persistent threats and high-level malware attacks. He was most recently the director of GReAT, the team that researched the inner workings of Stuxnet, Flame, Duqu, Turla, Lazarus, Moonlight Maze or the Equation Group.
Costin has over 30 years of experience in ITSec, having written his first antivirus when was 16. He is a member of the Virus Bulletin Technical Advisory Board, a member of the Computer AntiVirus Researchers’ Organization (CARO) and a founding member of TLPBLACK, a visionary cybersecurity company.
Costin enjoys playing chess, taking photos and reading science fiction literature. He holds a 2 DAN black belt in Taekwondo.
LinkedIn: https://www.linkedin.com/in/craiu/
Twitter/X: @craiu
Vicente Díaz is a cybersecurity researcher and specialist in threat intelligence, threat hunting and the investigation of advanced threats. Most recently, he worked at Google, where he was a Threat Intelligence Strategist for VirusTotal and a Product Manager for Google Threat Intelligence.
Vicente has more than 15 years of experience in cybersecurity. Before joining Google, he spent almost a decade with Kaspersky’s Global Research and Analysis Team—GReAT—where he served as Deputy Director for Europe and co-created and managed the company’s APT Intelligence Reporting service. Earlier in his career, he was the e-crime manager at S21sec for five years.
His work focuses on turning large-scale security telemetry into actionable intelligence, tracking sophisticated threat actors and developing practical methods for malware investigation and threat hunting. He has also researched the application of artificial intelligence to malware analysis and security operations.
Vicente holds a degree in Computer Science and a master’s degree in Artificial Intelligence. He is a progressive metal fan and has previously delivered many joint training sessions with Costin on practical threat hunting and writing effective YARA rules.
LinkedIn: https://www.linkedin.com/in/vicented/
Twitter/X: @trompi
Cancellations are not permitted but attendee changes can be accommodated anytime prior to the start of the course.
Note: In the event of a class cancellation, Ringzer0 will endeavor to offer transfer to another training at no additional charge.