
DEF CON 33 Recon Village - CTI Agent Automated Battlecards from CTI Reports - Mohamed Nabeel
Source: YouTube · DEFCONConference · published Dec 31, 2025 · 25:09
This video introduces CTI Agent, an agentic system designed to automate the synthesis of cyber threat intelligence reports into structured battle cards 0:55-1:13.
Key Takeaways:
• Existing CTI reports are difficult to process because they are unstructured, contain conflicting data, and often require manual inference of implicit TTPs 1:27-2:14.
• Grouping reports by threat actor is most effective when using LLM-generated summaries for embedding rather than raw document text, resulting in superior cluster separation 6:33-7:30.
• The system utilizes a ReAct agentic pattern with specific tools for report collection, searching, and extracting data via a map-reduce synthesis process that writes code to consolidate findings 12:50-16:10.
• To combat outdated IOCs in published reports, a graph expansion technique identifies new malicious infrastructure by analyzing relationships and clustering known threat actor assets 18:30-20:00.
The presentation concludes by noting the system's ability to proactively detect new threats and outlines future work involving visual data integration 23:22-24:00.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
All right, let's move on with the next talk which is brought up by Mohammad Nabil. Mohammad Nabir is a PhD in cyber and is also a cyber security veteran. He has leading efforts on proactive detection and graph-based threat intelligent research. He is an open-source enthusiast and a member of Apache software foundation. So it's really someone who special that has joined us today. He also works with Palo Alto Networks. We all know who Palo Alto is, right? His talk for today is CTI agent automated battle cards from CTI reports where you'll come across an agent agentic system to automate the collection and synthesis of cyber threat intelligence from threat reports using LLM agents. So, please give it up for Mohammed Nabil. All the way back. >> Hello everyone. Good afternoon. Can you all hear m…