Group Purchasing
Group Purchasing

Agentic CTI Automation For Fun and Profit

  • Tue, Jun 30, 2026
  • 1:00PM - 2:00PM EDT
  • English
  • Rebekah Brown
  • Technical Presentation
Login to register
Webcast Hero

Thank You To Our Sponsor

In the age of LLMs, the volume of new threat reports, CVEs, actor TTPs, and fragmented signals are often arriving faster than analysts can process them. AI is often positioned as the solution, but in practice, most implementations stop at summarization or basic enrichment.

This hands-on technical session focuses on how to build and deploy modern AI-backed agents inside real CTI workflows - systems that continuously ingest, reason, and take action, including automatically opening and enriching tickets tied to real exposure.

We’ll break down how AI can automate key stages of the CTI lifecycle: parsing unstructured intelligence, extracting IOCs and TTPs, correlating activity, mapping threats to your environment, and triggering operational workflows like detection updates and ticket creation.

Lessons Learned

  • How to automate and scale OSINT and underground streams into usable intelligence
  • Using AI to normalize and map activity to frameworks like MITRE ATT&CK
  • Quickly generating net new hunting and detection candidates (Sigma, KQL, SQL, etc)
  • Identifying threat actor tactics and procedures - as they change
  • Identification and remediation for novel attack techniques
  • Automating exposure analysis by mapping threats to internal assets, SBOMs, and vendors

Meet Your Speaker

Rebekah Brown
Rebekah Brown

Rebekah Brown

Senior Researcher at Citizen Lab

Rebekah Brown has been instrumental in advancing cyber threat intelligence, serving as a network warfare analyst at the NSA, Operations Chief of a U.S. Marine Corps cyber unit, and training lead at U.S. Cyber Command.

Read more about Rebekah Brown
Agentic CTI Automation For Fun and Profit | SANS Institute