Episode 114 -  The Good, Bad, and Ugly of Threat Intelligence with Patrick Coughlin

Episode 114 - The Good, Bad, and Ugly of Threat Intelligence with Patrick Coughlin

In this episode of the Hacker Valley Studio podcast, hosts Ron and Chris interview Patrick Coughlin, Co-Founder and CEO of TruSTAR. Patrick began his career as a security analyst in Washington D.C. and the middle east. By working with government contractors, multinational corporations, and counter-terrorism units, Patrick learned that the biggest challenge that security analysts have is retrieving the needed information from disparate data sources. This discovery led Patrick to founding TruStar. Patrick’s focus is to help organizations automate the collection and curation of threat intelligence data.

Patrick’s analytical prowess originated from working at Booz Allen Hamilton where he learned a fundamental skill that all cybersecurity analysts should have - how to put together a slide deck. This skill helped Patrick articulate the importance of threat intelligence to leaders in the government and private sector.

As the episode progresses, Patrick details the differences between threat intelligence requirements for national security and enterprise. For enterprise threat intelligence programs, the goal is to accelerate automation of detection and rarely attribution. Patrick also mentions automation is only as effective as the data is cleaned, normalized, and prioritized.

What about the good, bad, and ugly of threat intelligence? Patrick describes that an organization can thrive by leveraging internal intelligence. This can be overlooked when organizations are fixated on buying threat data feeds and subscribing to ISAC feeds. Most enterprise organizations have a detection and response stack that is constantly providing information about threats relevant to their organization - which serves as great threat intelligence data.

Chris and Ron ask Patrick about the science vs art aspects of cybersecurity and threat intelligence. Patrick describes that there is room for both art and science in threat intelligence. While new concepts are being discovered, there is art in finding the needle in the haystack. However, at some point, intuition can be described into steps that a machine can repeat. For example, after years of analytical practice an analyst can describe how and why they are tagging threat intelligence related data in such a way that can be repeated by other analysts or automation.

This episode covers an abundance of tactics and techniques for threat intelligence analysts. Patrick describes the best place to begin automating threat intelligence is detection. An analyst can ask the question, “How do I get sources of known bad indicators into my detection stack so that I could drive high fidelity detections?”. As false positives decrease, your mean time to detection (MTTD) and resolution (MTTR) decrease which makes your threat intelligence and security operation team members more effective.

0:00 - Intro

1:53 - This episode features Patrick Coughlin, Co-Founder and CEO of TruSTAR

2:30 - Patrick’s background and start as a security analyst

5:19 - How to automate threat intelligence while reducing analyst fatigue

7:05 - How Patrick cultivated his analyst prowess

8:43 - Articulating threat intelligence to government and enterprise organizations

11:09 - Can a threat intelligence program be automated?

17:21 - Patrick’s experience of “good” and “bad” threat intelligence programs

20:31 - Logic vs Intuition in threat intelligence

27:04 - Artificial Intelligence and Machine Learning to make threat intelligence decisions

28:42 - Where to start when automating threat intelligence

30:02 - How to stay in touch with Patrick Coughlin

Links:

Connect with Patrick Coughlin on LinkedIn

Link to Patrick’s company TruSTAR

Learn more about Hacker Valley Studio.

Support Hacker Valley Studio on Patreon.

Follow Hacker Valley Studio on Twitter.

Follow hosts Ron Eddings and Chris Cochran on Twitter.

Learn more about our sponsor ByteChek.

Take our FREE course for building threat intelligence programs by visiting www.hackervalley.com/easy

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(443)

Giving Your AI Agent Its Own Identity with Ashish Rajan

Giving Your AI Agent Its Own Identity with Ashish Rajan

Your newest hire has a Google Workspace account, a Slack login and a laptop. It never sleeps, and it never asks before it acts. So who owns its identity? Ron welcomes back Ashish Rajan, CISO at Techri...

30 Syys 32min

From Read Access to Admin with just an AI Agent

From Read Access to Admin with just an AI Agent

What if someone got full admin access to your company's platform, including your CRM, your payments app, and your private messages, and the only tool they used was an AI chatbot? Can AI models really ...

23 Syys 31min

Do You Know What Your Agent is Doing at 3AM? with Amir Ofek

Do You Know What Your Agent is Doing at 3AM? with Amir Ofek

Every AI agent in your environment inherits someone's permissions, and most teams have no idea what those agents are actually doing with them. Amir Ofek, CEO and co-founder of Aizome, shares how to ma...

16 Syys 38min

Cloud Broke My World Before AI Did with Dr. Jay Abdullah

Cloud Broke My World Before AI Did with Dr. Jay Abdullah

Cybersecurity has survived cloud, mobile, and a dozen other "biggest disruptions of our lifetime," and each one felt unprecedented in the moment. In this episode, Ron sits down with Alyssa "Dr. Jay" A...

9 Syys 36min

The Dashboard Is Dead, Long Live the Harness with Myke Lyons

The Dashboard Is Dead, Long Live the Harness with Myke Lyons

Security teams spent decades begging for more logs. Now the enterprise is generating petabytes a day, and the thing drowning in it isn't just the SOC anymore, it's your AI agents too. In this episode,...

1 Syys 35min

The AI Already Inside Your Company with Russell Spitler & Richard Penshorn

The AI Already Inside Your Company with Russell Spitler & Richard Penshorn

A year ago, the average employee held about 30 OAuth grants. Today that number has risen to 88, and it isn't slowing down. Ron sits down with Russell Spitler, co-founder and CEO of Nudge Security, and...

25 Elo 35min

Humans First: Adobe's Rule for Building AI Security Tools with John Gillis

Humans First: Adobe's Rule for Building AI Security Tools with John Gillis

Imagine how much investigation time your SOC could get back if the busywork just disappeared. Ron sits down with John Gillis, Staff Security AI Engineer at Adobe, who built an in-house AI investigatio...

19 Elo 34min

Let AI Do More Without Surrendering Your Judgment with Jen Easterly

Let AI Do More Without Surrendering Your Judgment with Jen Easterly

Fresh off the showroom floor at Black Hat 2026, Ron brings back some hot takes from the crowd. Nearly every booth he visited, including the Exaforce booth, was pushing in the same direction. Trust in ...

14 Elo 23min

Suosittua kategoriassa Koulutus

rss-murhan-anatomia
psykopodiaa-podcast
aamukahvilla
adhd-podi
rss-hereilla
voi-hyvin-meditaatiot-2
psykologia
rss-arkea-ja-aurinkoa-podcast-espanjasta
rss-valo-minussa-2
koulu-podcast-2
rss-liian-kuuma-peruna
kesken
rss-niinku-asia-on
rss-vapaudu-voimaasi
rss-rahamania
ihminen-tavattavissa-tommy-hellsten-instituutti
queen-talk
rss-finnish-with-eemeli-podcast
rss-paikoillenne-valmiit-laakikseen
rss-onks-ok