Learn to leverage threat intelligence for Red Team engagements using both manual analysis and AI-assisted workflows. Participants will research the HAFNIUM state-sponsored threat group, extract TTPs from multiple intelligence sources (Microsoft, Mandiant, Volexity reports), and map techniques to the MITRE ATT&CK framework.
The workshop introduces CrewAI, an open-source framework for orchestrating AI agents, to validate and enhance threat intelligence analysis. Participants will build multi-agent workflows that automatically read threat reports, extract technical indicators, and generate comprehensive adversary profiles—demonstrating how AI can augment human expertise in Red Team planning.
Learning Objectives:
- Apply the threat intelligence methodology for Red Team engagements
- Identify and research adversaries using MITRE ATT&CK
- Extract TTPs from multiple threat intelligence sources
- Use MITRE ATT&CK Navigator to visualize adversary techniques
- Build AI-assisted workflows with CrewAI to automate TTP extraction
- Create threat profile tables for adversary emulation planning
- Compare manual vs. AI-assisted analysis approaches