From OSINT to Detection: Building an Agentic CTI Pipeline (<– add to your schedule)
Modern threat intelligence moves fast, but detection engineering lags. This talk presents an agentic workflow that transforms OSINT into actionable detections using structured extraction, LLM reasoning, and automated validation. Transparent, auditable pipelines accelerate the CTI lifecycle, from ingestion to Sigma rules, while preserving analyst control, reducing time-to-detection from days to hours.
Andrew Skatoff:
Andrew is a cybersecurity senior leader with over 20 years of experience protecting critical financial infrastructure within the national financial infrastructure. He leads large-scale programs spanning incident response, threat hunting, and detection engineering, and has served as Incident Commander for nationally significant cyber events.
He is the creator of Huntable CTI Studio, an open-source agentic workbench that transforms threat intelligence reports into actionable detections using transparent, auditable AI workflows. His work focuses on applying AI as a force multiplier for security teams—without sacrificing rigor, trust, or control.