John Doyle
Certified InstructorDirector of CTI Services at Palo Alto Networks Unit 42
Specialities
Digital Forensics and Incident Response

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsDigital Forensics and Incident Response

John has over 20 years of experience working in Cyber Threat Intelligence (CTI), Digital Forensics, Cyber Policy, and Security Awareness and Education. John is the Director of CTI Services at Palo Alto Networks’ Unit 42 where he runs a customer-facing threat intelligence and dark web service line. He previously worked at Mandiant as a principal analyst before moving into an intelligence consulting role where he helped CTI teams in the financial, healthcare, retail, defense, and government sectors mature their CTI programs, upskilling team capability and organizational reach. John developed the Mandiant CTI Analyst Core Competencies Framework to fill a key industry gap, helping aspirant and current analysts establish growth pathways for a career within this field.
Before joining Mandiant, John served as the team lead for a transnational cyber threats and technologies team at the Central Intelligence Agency (CIA) where he drove intelligence collection, curated analytic production, and examined paradigm shifts in the cyber threat landscape. John’s CIA experience included extensive tracking of intrusion activities from Russian, North Korean, Chinese, Iranian, and emergent cyber threats to include private sector offensive actors (PSAOs). His interests largely reside in tracking adversary operations, building and enriching intrusion clusters, and identifying shifts in adversary tradecraft to drive defensive cybersecurity actions for organizations.
During his time in government service, John regularly would provide surge support to large-scale cyber incidents like WannaCry, NotPetya, OlympicDestroyer, and other high-profile media reported cyber events. He has leveraged this background since moving to the private sector to support the Department of Homeland Security’s Joint Cyber Defense Collaborative initiative and industry specific ISACs.
John has previously developed and taught cybersecurity and cyber threat courses at Mandiant, in the U.S. government, and at George Mason University. John is the coauthor for the SANS FOR478: Cyber Threat Intelligence Foundations course and is a Certified Instructor for FOR578: Cyber Threat Intelligence course. John translates two decades of tracking state-sponsored tradecraft and high-profile adversary campaigns into practical, actionable tradecraft during classroom instruction.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
Review relevant educational resources made with contribution from this instructor.