<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber Threat Intelligence - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/cyber-threat-intelligence/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/cyber-threat-intelligence/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Wed, 24 Jun 2026 10:32:25 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Cyber Threat Intelligence - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/cyber-threat-intelligence/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Automated CTI-powered Purple Teams</title>
		<link>https://www.riskinsight-wavestone.com/en/2026/06/automated-cti-powered-purple-teams/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/06/automated-cti-powered-purple-teams/#respond</comments>
		
		<dc:creator><![CDATA[Marouane Akassab]]></dc:creator>
		<pubDate>Wed, 24 Jun 2026 08:53:31 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[Caldera]]></category>
		<category><![CDATA[CTI-powered Puprle Team]]></category>
		<category><![CDATA[Cyber Threat Intelligence]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[MITRE ATT&CK]]></category>
		<category><![CDATA[Mythic C2]]></category>
		<category><![CDATA[Purple Team]]></category>
		<category><![CDATA[SOC]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=30227</guid>

					<description><![CDATA[<p>Purple Teaming has become a key practice for organizations looking to assess and improve their detection and response capabilities. By bringing together offensive and defensive teams, Purple Team exercises help validate security controls, identify detection gaps, and strengthen incident response...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/06/automated-cti-powered-purple-teams/">Automated CTI-powered Purple Teams</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;"><strong>Purple Teaming</strong> has become a key practice for organizations looking to assess and improve their detection and response capabilities. <strong>By bringing together offensive and defensive teams</strong>, Purple Team exercises <strong>help validate security controls, identify detection gaps, and strengthen incident response processes</strong>.</p>
<p style="text-align: justify;">However, <strong>traditional Purple Team exercises</strong> provide only a snapshot of an organization&#8217;s security posture at a given time. In rapidly evolving environments, where infrastructure, applications, security controls, and <strong>threats continuously evolve</strong>, <strong>assessment results can quickly become outdated</strong>. Consequently, organizations are left with a critical question: <strong>are the detections that worked yesterday still effective today? </strong>To answer that question, <strong>Purple Teaming must evolve from a periodic exercise into a continuous validation capability</strong>.</p>
<p style="text-align: justify;">This article presents a <strong>modular workflow we developed to</strong> <strong>transform threat intelligence into automated adversary simulations</strong>. The workflow combines <strong>Caldera</strong> for attack orchestration, <strong>Mythic</strong> for realistic Command &amp; Control simulation, and <strong>VECTR</strong> for measurable Security Operation Center (SOC) assessments: <strong>an automated workflow that only needs to be configured once and can be executed whenever needed</strong>.</p>
<figure id="attachment_30228" aria-describedby="caption-attachment-30228" style="width: 1037px" class="wp-caption aligncenter"><img fetchpriority="high" decoding="async" class="size-full wp-image-30228" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/1-Automated-Purple-Team-overview.png" alt="Automated Purple Team overview" width="1037" height="304" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/1-Automated-Purple-Team-overview.png 1037w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/1-Automated-Purple-Team-overview-437x128.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/1-Automated-Purple-Team-overview-71x21.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/1-Automated-Purple-Team-overview-768x225.png 768w" sizes="(max-width: 1037px) 100vw, 1037px" /><figcaption id="caption-attachment-30228" class="wp-caption-text">Automated Purple Team overview</figcaption></figure>
<p> </p>
<h2 style="text-align: left;">Wavestone’s Purple Team vision and expertise</h2>
<p style="text-align: justify;"><strong>At Wavestone, we have been performing Purple Team exercises for several years</strong> to help our clients ensure that their <strong>detection methodologies</strong> are not only theoretically sound but <strong>truly functional in practice.</strong></p>
<p style="text-align: justify;">The primary objective of our Purple Team approach is to <strong>identify technical attack scenarios that go undetected by current security controls</strong>, and to <strong>identify tailored detection methods that close those gaps</strong>. Rather than simply simulating attacks, we systematically evaluate detection across three critical criteria: <strong>is the activity logged, has an alert been generated on those logs, and finally, has the alert been properly handled by the SOC team</strong>.</p>
<p style="text-align: justify;">With the help of the Blue Team through regular meetings, this structured assessment allows us to identify <strong>quick wins (fast, high-impact improvements) and major projects</strong> that require deeper architectural changes or long-term investment, all of which are <strong>tailored for our client’s environment</strong>.</p>
<p style="text-align: justify;">To do so, our Purple Team operations rely on <strong>multiple complementary approaches</strong>, each with its own <strong>strengths and limitations</strong>.</p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: left;">Unit Testing</h3>
<p style="text-align: justify;">Unit testing is the foundational approach focused on <strong>testing specific, isolated TTPs to validate the effectiveness of individual detection rules</strong>. By playing these attacks without context or environmental adaptation, security teams can verify that <strong>specific log sources, correlations, and alerts are correctly configured and generated as expected</strong>. While highly effective for validating individual controls, unit testing provides a <strong>restricted view</strong> of an organization&#8217;s global defensive posture: success against a single, isolated technique <strong>does not guarantee the ability to detect and respond to a complex, multi-stage attack chain</strong>.</p>
<p style="text-align: justify;">In addition, unit testing introduces several important<strong> biases</strong> that can <strong>distort the realism</strong> of detection assessments. First, <strong>it requires collaboration with a Blue Team accomplice</strong> that provides the required assistance and <strong>prevents escalation from becoming too severe</strong>. This prevents the identification of some incident response gaps and <strong>greatly limits the secrecy of the operation</strong>.</p>
<p style="text-align: justify;">Furthermore, <strong>once the SOC knows a Purple Team operation is underway</strong>, the incident response becomes <strong>biased</strong>, often for the worse. Since <strong>the surprise factor and the pressure of a real incident are absent</strong>, these tests do not accurately measure how the SOC would perform under <strong>the stress and ambiguity of a genuine, ongoing intrusion</strong>.</p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: left;">Trophy-Driven Engagements</h3>
<p style="text-align: justify;">Our second approach, trophy-driven engagements, allows us to <strong>assess detection through a more realistic scenario</strong>. These operations are designed for <strong>mature organizations</strong>, aiming to evaluate and elevate <strong>advanced detection processes and threat hunting capabilities</strong> rather than simply validating automated rules.</p>
<p style="text-align: justify;">Similar to a <strong>Red Team</strong> <strong>operation</strong>, <strong>the offensive team executes a full-scale attack on the information system</strong>, not following a pre-defined test list but <strong>pursuing predefined trophies</strong>. An advantage of this approach is the ability to <strong>identify end-to-end scenarios</strong>.</p>
<p style="text-align: justify;">Specifically, our trophy-driven engagements often follow <strong>the Red to Purple approach</strong>: <strong>while the Red Team has not been detected</strong>, <strong>the Blue Team is unaware of the operation </strong>which forces genuine and unscripted response. It provides a unique opportunity to evaluate the actual reactions of the security team, <strong>effectively</strong> <strong>bridging the gap between theoretical procedure and real incident response</strong>.</p>
<p style="text-align: justify;">However, unlike the unit tests approach, <strong>these engagements are not exhaustive</strong>: they do not aim to map every specific unit rule on the environment, but rather to test the organization’s overall resilience against a defined adversary <strong>blending the detection rules, the escalation processes, the threat hunting and the correlation capability of the team</strong>.</p>
<p style="text-align: justify;">Ultimately, trophy-driven engagements represent the final evolution in the Purple Team lifecycle, shifting the focus from<strong> “What are our detection flaws?” </strong>to<strong> “Would a real attacker actually be detected?”</strong></p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: left;">SOC Assessments</h3>
<p style="text-align: justify;">SOC assessments focus on evaluating<strong> the operational readiness and performance of the SOC</strong>. Unlike the previous approaches, which validate detection, this approach measures <strong>the human and procedural capacity to detect, qualify, investigate, and remediate threats</strong>. It serves to validate that <strong>standard operation procedures and playbooks are effectively followed by analysts</strong>, while simultaneously <strong>identifying visibility gaps in logging and telemetry across the attack lifecycle</strong>.</p>
<p style="text-align: justify;">However, SOC assessments often <strong>rely on structured scenarios that create a sense of artificiality</strong>. The engagement is still a <strong>trigger-and-response exercise</strong> sugarcoated with procedural validation and human factor evaluation.</p>
<p style="text-align: justify;">Because these tests are <strong>centered on known, pre-planned triggers</strong>, they fail to force analysts to perform deep, investigative log correlation or to detect anomalous patterns across multiple, seemingly benign events : <strong>this test is still designed to « evaluate what is working today » and not « what must work tomorrow »</strong>.</p>
<p style="text-align: justify;">Finally, <strong>this scripted nature leaves no room for genuine Threat Hunting</strong>. Indeed, the SOC is never pushed to <strong>proactively</strong> uncover the plan of the adversary in the long run. By focusing on <strong>reactive playbook execution</strong> rather than <strong>the ambiguity of an evolving campaign</strong>, these assessments miss an important aspect of the human factor evaluation: <strong>the inability to detect a sophisticated threat that does not trigger a predefined, &#8220;noisy&#8221; alert</strong>.</p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: left;">The &#8220;T-Time Trap&#8221;</h3>
<p style="text-align: justify;">Despite their differences, all three approaches suffer from the same fundamental limitation: <strong>they evaluate an organization&#8217;s security posture at a specific point in time</strong>.</p>
<p style="text-align: justify;"><strong>Modern information systems are constantly evolving</strong>. Infrastructure migrations, cloud transformations, software deployments, and changes to security tooling can all <strong>affect the effectiveness of detection and response capabilities</strong>. A detection rule validated during a Purple Team exercise <strong>may no longer function as expected</strong> following a routine infrastructure change.</p>
<p style="text-align: justify;">At the same time, <strong>threat actors continuously adapt their tactics, techniques, and procedures</strong>. With <strong>the</strong> <strong>development of AI augmented attacks</strong>, the defensive profile is constantly evolving: what was secured yesterday can be obsolete today.</p>
<p style="text-align: justify;">Consequently, organizations must <strong>regularly reassess their defensive capabilities</strong> to ensure they remain aligned with the <strong>evolving threat landscape</strong>.</p>
<p style="text-align: justify;">Yet <strong>the cost, complexity, and manual effort</strong> associated with traditional Purple Team engagements often prevent organizations from performing assessments at <strong>the required frequency</strong>. This creates <strong>a gap between security validation and operational reality</strong>, leaving defenders with only <strong>a periodic view of their true defensive readiness</strong>.</p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: left;">Empowering the Defense: Self-Service &amp; CTI-Driven Automation</h2>
<p style="text-align: justify;">The limitations of traditional Purple Teaming raise an important question: <strong>how can organizations validate their defensive capabilities more frequently without significantly increasing costs and operational overhead?</strong></p>
<p style="text-align: justify;">The answer lies in <strong>shifting from consultant-driven assessments to defender-driven validation</strong>. Rather than waiting for periodic Purple Team engagements, <strong>security teams should be able to continuously assess their detection and response capabilities whenever needed</strong>.</p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: left;">CTI as the Engine of the workflow</h3>
<p style="text-align: justify;"><strong>Cyber Threat Intelligence (CTI)</strong> provides a valuable source of information on how threat actors operate. By documenting <strong>adversaries&#8217; tactics, techniques, and procedures (TTPs)</strong>, CTI enables organizations to move beyond generic attack simulations and focus on <strong>realistic threat scenarios relevant to their environment</strong>.</p>
<p style="text-align: justify;">Instead of being treated as static reports consumed once and archived, <strong>CTI can serve as the foundation for repeatable defensive assessments</strong>. Every newly identified technique, campaign, or threat actor profile can become an opportunity to <strong>validate existing security controls and identify detection gaps</strong>.</p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: left;">Translating TTPs into Automated Scenarios</h3>
<p style="text-align: justify;">While CTI identifies what adversaries do, organizations still need a way to <strong>reproduce those behaviors in a controlled and repeatable manner</strong>.</p>
<p style="text-align: justify;">By <strong>translating documented TTPs into automated attack scenarios</strong>, security teams can <strong>continuously test their ability to detect and investigate activities</strong> associated with specific threat actors. While <strong>this translation effort must be performed once</strong>, the resulting scenarios can be <strong>executed repeatedly with minimal overhead</strong>, allowing organizations to validate their defenses whenever needed.</p>
<p style="text-align: justify;">This approach significantly <strong>reduces the manual effort traditionally required to prepare and execute Purple Team exercises</strong> while ensuring consistency across assessments.</p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: left;">Enabling Autonomous Defensive Assessments</h3>
<p style="text-align: justify;">Automation <strong>empowers the Blue Team to operate more autonomously</strong>. Instead of depending on external engagements or dedicated Red Team resources, <strong>defenders can execute assessments themselves</strong> whenever operational changes occur.</p>
<p style="text-align: justify;">For example, <strong>assessments can be triggered</strong> following major infrastructure migrations, the deployment of new security controls, or the publication of <strong>threat intelligence</strong> related to a relevant adversary.</p>
<p style="text-align: justify;">This self-service approach enables organizations to <strong>validate their defensive posture at the required frequency</strong>, ensuring that <strong>detection capabilities remain aligned with both infrastructure changes and the evolving threat landscape</strong>.</p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: left;">Overcoming Market Automation Limits: The Caldera &amp; Mythic Integration</h2>
<p style="text-align: justify;">While attack orchestration frameworks already exist, they often come with operational limitations. For instance, <strong>Caldera</strong> relies on generic agents that <strong>do not implement advanced Command and Control (C2) capabilities </strong>such as <strong>in-memory PowerShell execution, Inline Assembly execution, or Beacon Object Files (BOFs)</strong>. As a result, while <strong>Caldera</strong> excels at automating adversary emulation scenarios, it may not accurately reproduce the tradecraft employed by <strong>sophisticated threat actors</strong>. Furthermore, in environments where <strong>realism is a key objective</strong>, the presence and behavior of the <strong>Caldera agent</strong> may allow defenders to <strong>quickly identify the exercise</strong>, limiting the fidelity of the assessment<strong>.</strong></p>
<p style="text-align: justify;">Conversely, modern <strong>Command and Control frameworks</strong> such as <strong>Mythic</strong> provide realistic adversary simulation capabilities and advanced execution methods, but they <strong>lack the orchestration and automation features</strong> required to perform <strong>repeatable Purple Team assessments at scale</strong>.</p>
<p style="text-align: justify;">To bridge this gap, <strong>we developed</strong> <strong>the</strong> <strong>Mythic plugin for Caldera</strong>, which integrates directly with the <strong>Mythic C2 framework</strong>. The objective was to <strong>combine Caldera&#8217;s automation and orchestration capabilities with Mythic&#8217;s realistic Command and Control capabilities</strong>. Within this architecture, <strong>Caldera</strong> remains responsible for <strong>orchestrating CTI-driven attack scenarios</strong>, while <strong>Mythic provides the execution layer</strong> used to simulate advanced adversary tradecraft.</p>
<p style="text-align: justify;">This integration enables organizations to <strong>automate complex attack chains</strong> while <strong>maintaining a level of realism closer to that of real-world intrusions</strong>.</p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: left;">Mythic Caldera plugin: Adversary Emulation Library</h3>
<p style="text-align: justify;">The plugin extends <strong>Caldera</strong> by integrating <strong>Mythic C2</strong> and providing custom<strong> adversary profiles, fact sources, payloads and parsers</strong>. Together, these components <strong>enable operators to quickly turn threat intelligence into automated adversary emulation scenarios</strong> <strong>while</strong> <strong>significantly reducing the need for manual configuration</strong>.</p>
<figure id="attachment_30230" aria-describedby="caption-attachment-30230" style="width: 1680px" class="wp-caption aligncenter"><img decoding="async" class="size-full wp-image-30230" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/2-Mythic-CALDERA-plugin.png" alt="Mythic CALDERA plugin" width="1680" height="896" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/2-Mythic-CALDERA-plugin.png 1680w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/2-Mythic-CALDERA-plugin-358x191.png 358w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/2-Mythic-CALDERA-plugin-71x39.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/2-Mythic-CALDERA-plugin-768x410.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/2-Mythic-CALDERA-plugin-1536x819.png 1536w" sizes="(max-width: 1680px) 100vw, 1680px" /><figcaption id="caption-attachment-30230" class="wp-caption-text">Mythic CALDERA plugin</figcaption></figure>
<p style="text-align: justify;">The plugin includes <strong>5 custom adversary profiles</strong>, each designed to emulate a <strong>distinct threat model</strong> and associated attacker tradecraft:</p>
<ul style="text-align: justify;">
<li><strong>Insider</strong>: Simulates an <strong>internal attacker</strong>, such as a Windows Administrator, with TTPs implemented exclusively using <strong>Windows living-off-the-land binaries (LOLBins)</strong>.</li>
<li><strong>Cybercrime</strong>: Simulates an <strong>opportunistic attacker</strong> leveraging <strong>publicly available offensive tools </strong>and <strong>remote attack techniques</strong> conducted through the <strong>Mythic SOCKS5 proxy infrastructure</strong>.</li>
<li><strong>APT</strong>: Simulates a <strong>sophisticated threat actor</strong> using advanced tradecraft, <strong>including low-level Windows API calls, Apollo built-in commands</strong>, and <strong>in-memory payload execution techniques</strong>.</li>
<li><strong>Linux &#8211; Insider</strong>: Simulates an <strong>internal attacker</strong>, such as a Linux Administrator, with TTPs implemented exclusively using <strong>native Linux commands and utilities</strong>.</li>
<li><strong>Linux- Cybercrime</strong>: Simulates an <strong>opportunistic attacker</strong> targeting Linux environments, with TTPs implemented using <strong>common open-source offensive tools</strong>.</li>
</ul>
<p style="text-align: justify;">To improve reusability, the plugin leverages <strong>Caldera fact sources</strong> to <strong>dynamically parameterize abilities</strong>. Instead of hardcoding environment-specific values, facts such as domain names, IP addresses, credentials, payloads, or operational parameters are <strong>injected at runtime</strong>. This approach <strong>allows the same adversary profile to be</strong> <strong>reused across multiple environments with minimal modifications</strong>.</p>
<figure id="attachment_30232" aria-describedby="caption-attachment-30232" style="width: 660px" class="wp-caption aligncenter"><img decoding="async" class="size-full wp-image-30232" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/3-Example-of-a-Fact-Source.png" alt="Example of a Fact Source" width="660" height="669" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/3-Example-of-a-Fact-Source.png 660w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/3-Example-of-a-Fact-Source-188x191.png 188w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/3-Example-of-a-Fact-Source-38x39.png 38w" sizes="(max-width: 660px) 100vw, 660px" /><figcaption id="caption-attachment-30232" class="wp-caption-text">Example of a Fact Source</figcaption></figure>
<p style="text-align: justify;">The library also includes a collection of <strong>payloads and parsers</strong> used to support advanced attack simulations. <strong>Payloads are automatically synchronized with Mythic</strong> and can be leveraged by abilities during operation execution, while <strong>parsers dynamically extract information from command outputs</strong> and transform it into <strong>facts that can be consumed by subsequent abilities</strong>.</p>
<p style="text-align: justify;">Finally, the plugin provides a <strong>growing library of more than 180 reusable abilities</strong> covering a <strong>wide range of ATT&amp;CK techniques</strong>. These abilities can be <strong>combined into adversary profiles or executed individually </strong>to validate specific detections and response procedures.</p>
<figure id="attachment_30234" aria-describedby="caption-attachment-30234" style="width: 968px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-30234" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/4-Examples-of-Included-Abilities.png" alt="Examples of Included Abilities" width="968" height="700" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/4-Examples-of-Included-Abilities.png 968w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/4-Examples-of-Included-Abilities-264x191.png 264w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/4-Examples-of-Included-Abilities-54x39.png 54w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/4-Examples-of-Included-Abilities-768x555.png 768w" sizes="auto, (max-width: 968px) 100vw, 968px" /><figcaption id="caption-attachment-30234" class="wp-caption-text">Examples of Included Abilities</figcaption></figure>
<p> </p>
<h3 style="text-align: left;">Mythic Caldera plugin: Caldera-Mythic Integration</h3>
<p style="text-align: justify;">At the core of the integration are two command-line interfaces (CLIs): <strong>apollo_exec.py</strong> and <strong>athena_exec.py</strong>. These CLIs interface with the <strong>Mythic API</strong> and are used by the <strong>Caldera agent Sandcat</strong> to <strong>programmatically task Apollo (Windows) and Athena (Linux) agents</strong> .</p>
<p style="text-align: justify;">For example, The <strong>Apollo CLI </strong>takes a <strong>Mythic callback ID</strong>, a <strong>command</strong>, and <strong>optional arguments</strong>, and supports additional options to extend execution behavior:</p>
<figure id="attachment_30236" aria-describedby="caption-attachment-30236" style="width: 1437px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-30236" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/5-Apollo-CLI.png" alt="Apollo CLI" width="1437" height="360" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/5-Apollo-CLI.png 1437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/5-Apollo-CLI-437x109.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/5-Apollo-CLI-71x18.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/5-Apollo-CLI-768x192.png 768w" sizes="auto, (max-width: 1437px) 100vw, 1437px" /><figcaption id="caption-attachment-30236" class="wp-caption-text">Apollo CLI</figcaption></figure>
<ul>
<li style="text-align: justify;"><strong>-uploads</strong>: upload files before execution</li>
<li style="text-align: justify;"><strong>-downloads</strong>: download files after execution</li>
<li style="text-align: justify;"><strong>-deletes</strong>: remove files after execution</li>
<li style="text-align: justify;"><strong>-ps</strong>: import a PowerShell script in-memory before execution</li>
<li style="text-align: justify;"><strong>-pid</strong>: specify a target process ID for process injection</li>
</ul>
<p style="text-align: justify;">To streamline the interaction between <strong>Caldera</strong> and <strong>Mythic</strong>, the plugin implements two core functionalities:</p>
<ul>
<li style="text-align: justify;"><strong>Connect C2</strong>: generates the <strong>apollo_exec.py</strong> and the <strong>athena_exec.py CLIs</strong> based on the provided Mythic C2 configuration parameters to enable communication with the <strong>Mythic API</strong>.</li>
<li style="text-align: justify;"><strong>Sync Payloads</strong>: automatically registers the payloads required by <strong>Caldera</strong> operations on <strong>Mythic</strong>, including .<strong>NET assemblies, DLLs, executables, and Beacon Object Files (BOFs)</strong>.</li>
</ul>
<p> </p>
<h3 style="text-align: left;">Mythic Caldera plugin: Execution Workflow</h3>
<p style="text-align: justify;">Within our workflow, <strong>MITRE Caldera</strong> is used as an <strong>orchestration platform</strong> rather than a traditional Command and Control (C2) server. <strong>The Caldera agent (Sandcat)</strong> is deployed on the same host as the Caldera server and is responsible for <strong>coordinating the execution of attack scenarios</strong>. Instead of executing abilities directly, it <strong>delegates their execution to the Mythic C2 infrastructure</strong>.</p>
<figure id="attachment_30238" aria-describedby="caption-attachment-30238" style="width: 1205px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-30238" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/6-Automated-execution-workflow.png" alt="Automated execution workflow" width="1205" height="389" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/6-Automated-execution-workflow.png 1205w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/6-Automated-execution-workflow-437x141.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/6-Automated-execution-workflow-71x23.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/6-Automated-execution-workflow-768x248.png 768w" sizes="auto, (max-width: 1205px) 100vw, 1205px" /><figcaption id="caption-attachment-30238" class="wp-caption-text">Automated execution workflow</figcaption></figure>
<p style="text-align: justify;">Depending on the nature of the technique being executed, TTPs are handled through one of <strong>two execution paths</strong>:</p>
<ul>
<li style="text-align: justify;"><strong>Network-based attacks</strong>: network-oriented TTPs, such as <strong>lateral movement or remote service interactions</strong>, are executed by the Caldera agent through a <strong>SOCKS5 proxy</strong> exposed by Mythic. <strong>Traffic is routed through the Apollo agent</strong> using tools such as <strong>proxychains</strong>.</li>
</ul>
<figure id="attachment_30240" aria-describedby="caption-attachment-30240" style="width: 987px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-30240" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/7-Network-based-ability-example.png" alt="Network-based ability example" width="987" height="638" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/7-Network-based-ability-example.png 987w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/7-Network-based-ability-example-295x191.png 295w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/7-Network-based-ability-example-60x39.png 60w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/7-Network-based-ability-example-768x496.png 768w" sizes="auto, (max-width: 987px) 100vw, 987px" /><figcaption id="caption-attachment-30240" class="wp-caption-text">Network-based ability example</figcaption></figure>
<ul>
<li style="text-align: justify;"><strong>System execution attacks</strong>: Host-based TTPs are <strong>executed directly on compromised systems through Mythic agents</strong>. In this scenario, the <strong>Caldera agent</strong> leverages the <strong>apollo_exec.py</strong> <strong>CLI</strong> to interact with the <strong>Mythic API</strong>, tasking the <strong>Apollo agent</strong> to perform the requested action.</li>
</ul>
<figure id="attachment_30242" aria-describedby="caption-attachment-30242" style="width: 764px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-30242" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/8-System-execution-ability-example.png" alt="System execution ability example" width="764" height="641" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/8-System-execution-ability-example.png 764w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/8-System-execution-ability-example-228x191.png 228w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/8-System-execution-ability-example-46x39.png 46w" sizes="auto, (max-width: 764px) 100vw, 764px" /><figcaption id="caption-attachment-30242" class="wp-caption-text">System execution ability example</figcaption></figure>
<p> </p>
<h2 style="text-align: left;">Objective Measurement: Assessing SOC Progress Using VECTR</h2>
<p style="text-align: justify;">A major limitation of tools such as <strong>Caldera</strong> is their <strong>Red-Team-centric design</strong>. While they excel at orchestrating and executing attacks, <strong>they</strong> <strong>do not provide a user-friendly interface for Blue Team analysts</strong> <strong>to review, enrich, and track assessment results</strong>. Consequently, <strong>accessing and interpreting the outcome of Purple Team exercises can become tedious</strong>, particularly when multiple operations are conducted over time.</p>
<p style="text-align: justify;">To address this challenge, we integrated <strong>VECTR</strong> into our workflow. <strong>VECTR</strong> <strong>is a Purple Team platform designed to</strong> <strong>centralize attack and detection data</strong>, providing a common operational picture <strong>for both Red and Blue Teams</strong>. By correlating adversary actions with defensive observations, it enables organizations to <strong>objectively measure detection capabilities and track their evolution over time</strong>.</p>
<p style="text-align: justify;">To streamline this process, <strong>we developed the</strong> <strong>VECTR plugin for Caldera</strong>. Once triggered by the operator, <strong>the plugin automatically exports completed operations to VECTR as campaigns</strong>, enabling the <strong>automatic</strong> <strong>generation of attack graphs and MITRE ATT&amp;CK heatmaps</strong> while eliminating hours of manual reporting effort.</p>
<p> </p>
<h3 style="text-align: left;">Vectr Caldera plugin: Campaign Creation</h3>
<p style="text-align: justify;">The plugin extends Caldera by <strong>exporting completed operations as VECTR campaigns</strong>. During the export process, the plugin transfers operation steps, execution status, executed commands, MITRE ATT&amp;CK technique mappings, timestamps, and command outputs (stdout/stderr).</p>
<figure id="attachment_30244" aria-describedby="caption-attachment-30244" style="width: 1901px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-30244" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/9-Vectr-CALDERA-plugin.png" alt="Vectr CALDERA plugin" width="1901" height="706" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/9-Vectr-CALDERA-plugin.png 1901w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/9-Vectr-CALDERA-plugin-437x162.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/9-Vectr-CALDERA-plugin-71x26.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/9-Vectr-CALDERA-plugin-768x285.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/9-Vectr-CALDERA-plugin-1536x570.png 1536w" sizes="auto, (max-width: 1901px) 100vw, 1901px" /><figcaption id="caption-attachment-30244" class="wp-caption-text">Vectr CALDERA plugin</figcaption></figure>
<p style="text-align: justify;">The plugin displays <strong>available</strong> <strong>Caldera operations along with their execution status</strong>. Once an operation is completed, <strong>the operator can trigger the export with a single click</strong> after providing the VECTR connection parameters. <strong>The export process is performed asynchronously</strong> to avoid blocking the Caldera execution thread.</p>
<figure id="attachment_30246" aria-describedby="caption-attachment-30246" style="width: 1863px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-30246" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/10-Vectr-Campaign.png" alt="Vectr Campaign" width="1863" height="683" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/10-Vectr-Campaign.png 1863w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/10-Vectr-Campaign-437x160.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/10-Vectr-Campaign-71x26.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/10-Vectr-Campaign-768x282.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/10-Vectr-Campaign-1536x563.png 1536w" sizes="auto, (max-width: 1863px) 100vw, 1863px" /><figcaption id="caption-attachment-30246" class="wp-caption-text">Vectr Campaign</figcaption></figure>
<p style="text-align: justify;">Once exported, <strong>the operation appears as a campaign in VECTR</strong>. To maintain traceability between both platforms and ensure <strong>campaign uniqueness</strong>, the campaign name is composed of the Caldera operation name followed by <strong>the first 8 characters of the corresponding operation identifier</strong>.</p>
<p> </p>
<h3 style="text-align: left;">Vectr Caldera plugin: Campaign Enrichment</h3>
<p style="text-align: justify;">Each ability included in a Caldera operation is <strong>mapped to a corresponding test case within the VECTR campaign</strong>. As a result, <strong>every test case is automatically enriched with relevant Red Team information</strong>, including the associated ATT&amp;CK technique, execution status, timestamps, commands, and operational metadata:</p>
<figure id="attachment_30248" aria-describedby="caption-attachment-30248" style="width: 899px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-30248" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/11-Vectr-Test-Case.png" alt="Vectr Test Case" width="899" height="820" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/11-Vectr-Test-Case.png 899w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/11-Vectr-Test-Case-209x191.png 209w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/11-Vectr-Test-Case-43x39.png 43w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/11-Vectr-Test-Case-768x701.png 768w" sizes="auto, (max-width: 899px) 100vw, 899px" /><figcaption id="caption-attachment-30248" class="wp-caption-text">Vectr Test Case</figcaption></figure>
<p style="text-align: justify;">For abilities that were executed, <strong>command outputs (stdout/stderr)</strong> are exported to <strong>VECTR</strong> and attached as <strong>Red Team logs</strong>. These logs provide analysts with <strong>detailed visibility into the actions performed during the assessment </strong>and can be reviewed to <strong>better understand the execution flow</strong> and investigate detection opportunities.</p>
<figure id="attachment_30250" aria-describedby="caption-attachment-30250" style="width: 1191px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-30250" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/12-Vectr-Red-team-logs.png" alt="Vectr Red team logs" width="1191" height="708" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/12-Vectr-Red-team-logs.png 1191w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/12-Vectr-Red-team-logs-321x191.png 321w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/12-Vectr-Red-team-logs-66x39.png 66w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/12-Vectr-Red-team-logs-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/12-Vectr-Red-team-logs-768x457.png 768w" sizes="auto, (max-width: 1191px) 100vw, 1191px" /><figcaption id="caption-attachment-30250" class="wp-caption-text">Vectr Red team logs</figcaption></figure>
<p> </p>
<h2 style="text-align: left;">Bringing It All Together: End-to-End Demonstration</h2>
<p style="text-align: justify;">The following video brings together all components presented throughout this article, illustrating an <strong>end-to-end automated Purple Team assessment workflow</strong>, from automated adversary emulation with <strong>Caldera</strong> and <strong>Mythic</strong> to the visualization of adversary activities and operational results within <strong>VECTR</strong>.</p>
<p> </p>
<p><iframe loading="lazy" title="YouTube video player" src="https://www.youtube-nocookie.com/embed/NmTr0iQy27I?si=DsKIBxe10UlTSIqY" width="992" height="558" frameborder="0" allowfullscreen="allowfullscreen"></iframe></p>
<p> </p>
<h2 style="text-align: left;">What’s next?</h2>
<p style="text-align: justify;">While the workflow significantly reduces the effort required to conduct Purple Team assessments, one manual step remains: <strong>translating threat intelligence into executable Caldera abilities and adversary profiles</strong>.</p>
<p style="text-align: justify;">Today, this process requires analysts to review CTI reports, identify relevant TTPs, <strong>and manually implement the corresponding abilities within the adversary emulation library</strong>. Although this effort only <strong>needs to be performed once for each technique</strong>, it remains <strong>dependent on human expertise</strong> and can become <strong>time consuming</strong> when operationalizing large volumes of threat intelligence.</p>
<p style="text-align: justify;">Future work will focus on <strong>leveraging Artificial Intelligence</strong> to automate this process. By <strong>combining large language models with ATT&amp;CK knowledge and existing ability templates</strong>, CTI reports could be <strong>automatically transformed into executable Caldera abilities</strong>, significantly <strong>accelerating the operationalization of threat intelligence</strong> and further reducing the effort required to maintain an up-to-date adversary emulation library.</p>
<p style="text-align: justify;">This would <strong>complete the automation chain</strong>, enabling organizations to move <strong>from threat intelligence acquisition to automated adversary emulation and SOC assessment</strong> <strong>with</strong> <strong>minimal human intervention</strong>.</p>
<p> </p>


<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/06/automated-cti-powered-purple-teams/">Automated CTI-powered Purple Teams</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/06/automated-cti-powered-purple-teams/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Amplifying Cyber Threat Intelligence with AI: A Pragmatic, Maturity Driven Approach</title>
		<link>https://www.riskinsight-wavestone.com/en/2026/05/amplifying-cyber-threat-intelligence-with-ai-a-pragmatic-maturity-driven-approach/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/05/amplifying-cyber-threat-intelligence-with-ai-a-pragmatic-maturity-driven-approach/#respond</comments>
		
		<dc:creator><![CDATA[Pauline Hendi]]></dc:creator>
		<pubDate>Wed, 27 May 2026 08:07:40 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[AI in Cybersecurity]]></category>
		<category><![CDATA[AI4CTI]]></category>
		<category><![CDATA[Automatisation CTI]]></category>
		<category><![CDATA[CTI]]></category>
		<category><![CDATA[CTI automation]]></category>
		<category><![CDATA[Cyber Threat Intelligence]]></category>
		<category><![CDATA[cybersécurité]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[IA]]></category>
		<category><![CDATA[Natural Language Processing]]></category>
		<category><![CDATA[NLP]]></category>
		<category><![CDATA[offensive security]]></category>
		<category><![CDATA[RAG]]></category>
		<category><![CDATA[Threat Detection & Hunting]]></category>
		<category><![CDATA[vulnerability management]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=29986</guid>

					<description><![CDATA[<p>Against a backdrop of heightened geopolitical tensions, recent years have been marked by an upsurge in cyber threats, illustrated by the strengthening of attackers’ capabilities, the diversification of their tactics and even the enhancement of their operations thanks to artificial...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/05/amplifying-cyber-threat-intelligence-with-ai-a-pragmatic-maturity-driven-approach/">Amplifying Cyber Threat Intelligence with AI: A Pragmatic, Maturity Driven Approach</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">Against a backdrop of heightened geopolitical tensions, recent years have been marked by an upsurge in cyber threats, illustrated by the strengthening of attackers’ capabilities, the diversification of their tactics and even the enhancement of their operations thanks to artificial intelligence (ANSSI, Cyberthreat Landscape Overview 2025).</p>
<p style="text-align: justify;">In this context, integrating Cyber Threat Intelligence (CTI) into organizations’ cybersecurity strategy and overall posture has become a key asset to anticipating increasingly sophisticated and innovative attacks and their potential operational impacts. Indeed, CTI provides early insight into potential threats and supports proactive posture by strengthening detection, reinforcing defenses, and enhancing incident responses. More than just collecting raw indicators, it constitutes a decision-driven process, aimed at improving the understanding of adversaries by turning data into actionable intelligence capable of answering precise cybersecurity questions.</p>
<p style="text-align: justify;">In general, we distinguish three complementary forms of intelligence to reinforce an organization’s cybersecurity posture:</p>
<ul style="text-align: justify;">
<li>Strategic, guiding long‑term decisions and investment priorities,</li>
<li>Tactical, analyzing attackers’ tools and Tactics, Technics and Procedures (TTPs) to shape defensive posture,</li>
<li>Operational and technical, providing actionable details such as Indicators of Compromise (IoCs) and Indicators of Attack (IoAs) to counter specific, recent threats.</li>
</ul>
<p style="text-align: justify;">As CTI spans multiple levels of decision‑making, its effectiveness depends on an organization’s ability to process growing volumes of heterogeneous data, detect weak signals, and produce actionable intelligence across all layers. These capabilities remain highly challenging for traditional CTI tools given data volume and heterogeneity. Throughout this article, we will present several use cases in which the use of enterprise-internal AI acts as a powerful lever to truly enhance CTI. To do so, our analysis is grounded in the CTI‑CMM model, which provides stakeholders with a structured framework for strengthening their CTI maturity. Designed to assess a program’s maturity and capability growth, the CTI‑CMM proposes a comprehensive mapping of CTI use cases across eleven domains, providing a clear and systematic foundation for evaluating where AI can most effectively enhance CTI activities.</p>
<p style="text-align: justify;">Not all AI use cases in CTI deliver the same value or should be approached in the same way. Building on its experience across CTI engagements, Wavestone has developed a three-tier model – Safe Wins, Accelerators, and Frontier Bets – designed to structure use cases based on their AI maturity, impact on decision-making, and alignment with an organization’s CTI maturity.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-29964" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/A-Maturity-Based-3-Tier-Model-for-AI-Enhanced-CTI-Use-Cases.png" alt="A Maturity-Based 3-Tier Model for AI-Enhanced CTI Use Cases" width="1088" height="658" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/A-Maturity-Based-3-Tier-Model-for-AI-Enhanced-CTI-Use-Cases.png 1088w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/A-Maturity-Based-3-Tier-Model-for-AI-Enhanced-CTI-Use-Cases-316x191.png 316w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/A-Maturity-Based-3-Tier-Model-for-AI-Enhanced-CTI-Use-Cases-64x39.png 64w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/A-Maturity-Based-3-Tier-Model-for-AI-Enhanced-CTI-Use-Cases-768x464.png 768w" sizes="auto, (max-width: 1088px) 100vw, 1088px" /></p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">Safe Wins</h2>
<p style="text-align: justify;"><strong>“Safe Wins” are use cases where AI can already improve CTI performance with minor changes to a “traditional” CTI governance model</strong> (i.e., analyst accountability, validation and dissemination workflows, and control over what is automated versus what remains expert judgment). They are low-regret and easy to implement, delivering fast ROI by automating high-volume tasks such as filtering, enrichment, and correlation. Outputs are reversible, errors are easy to detect, and AI is typically used for triage or processing, making them ideal entry points.</p>
<p> </p>
<h3 style="text-align: justify;">AI to enhance threat detection and preparedness (1a.)</h3>
<p style="text-align: justify;">AI has become a powerful ally in processing and correlating unstructured data collected through Threat Intelligence Platforms (TIP) to be transformed into actionable intelligence. While organizations should rely on TIP for data collection on IOCs and IOAs from human-selected qualitative feeds and OSINT sources, the true added value of enterprise-controlled AI for attack prevention and preparedness lies in its capacity to improve the quality of incoming data through confidence scoring. Given its capacity to process vast amount of data quickly (IP, domain, hash, behavior, etc.), AI can be used to correlate features (e.g., similarities to past malware, links to threat actors, unusual behavior) and verify false positives in incoming IOCs to assign a confidence score and avoid blocking relevant information on the Blue Team side.</p>
<p> </p>
<h3 style="text-align: justify;">AI to structure and standardize CTI data analysis and report (1b.)</h3>
<p style="text-align: justify;">AI can support CTI teams by assisting in the analysis of raw intelligence data from multiple sources using large language models. It helps restructure reports according to standardized models such as STIX, ensuring that the right information is placed in the appropriate fields. Attacker procedures, techniques, and contextual elements can be extracted and transformed into structured data in a consistent manner. This improves overall data quality, readability, and interoperability with TIPs and downstream security tools. As a relatively simple and low risk use case, it primarily acts as an analyst productivity booster for structuring reports in a standardized format.</p>
<p> </p>
<h3 style="text-align: justify;">AI to operationalize CTI for offensive security operations (1c.)</h3>
<p style="text-align: justify;">When it comes to red and purple team activities, AI acts as a strong enabler by helping CTI teams identify recurring TTPs across reports, cluster similar procedures, and consolidate duplicates into exploitable building blocks. AI can support analysts in extracting the most relevant information from threat reports and OSINT to maintain a consistent and actionable threat-driven knowledge base. AI can also help generate macro scenarios based on threat reports and publicly available intelligence, including actor selection and attack patterns. However, to be considered a safe win it must remain a decision-support tool, as end-to-end technical scenario generation would require sensitive data, the adequate responsibility model, and data confidentiality safeguards to avoid improper exposition and misuse.</p>
<p> </p>
<h3 style="text-align: justify;">AI to support strategic alignment of intelligence requirements (1d.)</h3>
<p style="text-align: justify;">AI can also support the definition and refinement of priorities and objectives within the threat intelligence function. More specifically, AI participates in accelerating analytical processes by assisting in the drafting and continuous refinement of priority intelligence requirements (PIRs) and proposing stakeholder-tailored reporting frameworks. It also helps distill complex program signals into intermediate insights, enabling analysts to focus on interpretation and decision‑making. Human validation remains essential to ensure alignment with the organization’s broader cyber strategy and performance frameworks. However, failing to account for AI’s inherent limitations, particularly in terms of accuracy, reliability, and explainability, may introduce significant risks, including the generation of misleading insights that could misalign intelligence outputs with enterprise cybersecurity objectives.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">These &#8220;Safe Wins&#8221; illustrate how AI can already strengthen CTI across several operational dimensions: improving the quality and exploitation of intelligence data for defensive activities (a), accelerating the structuring and usability of CTI reporting (b), supporting threat-informed offensive security operations through better TTP extraction and scenario preparation (c), and assisting in the drafting of intelligence requirements and designing of reporting. By enhancing efficiency, consistency, and scalability across these activities, these use cases establish a strong foundation for the next tier of applications, where AI supports more analytical and decision-driven processes requiring greater maturity and governance.</p>
<p style="text-align: justify;"> </p>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-29970" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Safe-Wins-Use-Cases-Across-the-CTI-Lifecycle.png" alt="Safe Wins Use Cases Across the CTI Lifecycle" width="1200" height="482" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Safe-Wins-Use-Cases-Across-the-CTI-Lifecycle.png 1200w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Safe-Wins-Use-Cases-Across-the-CTI-Lifecycle-437x176.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Safe-Wins-Use-Cases-Across-the-CTI-Lifecycle-71x29.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Safe-Wins-Use-Cases-Across-the-CTI-Lifecycle-768x308.png 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>
<p> </p>
<h2 style="text-align: justify;">High-Potential Accelerators</h2>
<p style="text-align: justify;"><strong>“High-potential Accelerators” target more mature CTI teams, where AI acts as a force multiplier rather than a substitute for expertise. </strong>They significantly amplify analyst productivity by scaling detection, supporting hypothesis generation, and translating intelligence into actionable outputs. However, these use cases require high-quality contextual data, structured processes, and robust governance (e.g., human-in-the-loop, explainability, feedback loops) to ensure reliable and controlled outcomes.</p>
<p> </p>
<h3 style="text-align: justify;">AI to scale financial fraud and brand impersonation detection (2a.)</h3>
<p style="text-align: justify;">AI can enhance CTI by scaling the identification of fraud and brand impersonation assets across large data streams and monitored perimeters. It enables the detection of newly created lookalike domains and cloned websites/logos across domains using NLP<sup>[1]</sup>, computer vision, and behavioral analytics. These assets can be enriched with technical indicators (DNS, hosting infrastructure, registration patterns) and contextual signals (content similarity, redirection flows), then correlated into coherent attack campaigns and ingested into TIPs. The resulting intelligence can be disseminated to blue teams to support detection, blocking, and take-down actions. While the automation of large-scale discovery and triage allows CTI teams to focus on validation, prioritization, and business impact, it requires strong governance and coordination between CTI, fraud/brand protection, legal, and security operations teams to minimize false positives and ensure effective response.</p>
<p> </p>
<h3 style="text-align: justify;">AI to prioritize vulnerability patching (2b.)</h3>
<p style="text-align: justify;">AI can support vulnerability management by dynamically prioritizing patching efforts based on threat intelligence, underlying technologies, and the exposure and criticality of business applications. By combining threat context, exploit activity, asset environment, and enterprise-specific constraints, AI can estimate a risk score for each vulnerability. This score is used to raise targeted alerts and guide patching teams toward the most critical remediation actions. The approach embeds all threat-related elements within the organization’s context, allowing AI to act as an intelligent decision-support layer rather than a generic scoring mechanism. This use case complexity arises from the need for AI to access and correlate large volumes of sensitive and critical data across security, IT, and asset management systems.</p>
<p> </p>
<h3 style="text-align: justify;">AI to support threat hunting and penetration testing (2c.)</h3>
<p style="text-align: justify;">When it comes to guiding proactive hunt hypotheses and prioritizing them using threat‑actor TTPs, campaigns, and priority intelligence requirements, AI adds real momentum. It can help generating hunting hypotheses from observed TTPs, turning them into queries or playbooks, highlighting which hunts should come first based on PIRs, vulnerabilities, or asset signals, and summarizing the results of ongoing investigations. Paired with an internal knowledge base or RAG<sup>[2]</sup>‑enhanced context, AI supports hunters move through their environment with greater clarity and focus. Additionally, AI can assist the teams in the execution of penetration testing and adversary simulation activities. By automating offensive workflows and simulating complex, real-world attack scenarios, it enables more scalable, efficient, and realistic testing, helping teams better keep pace with increasingly AI-enabled threats. However, this does not imply that AI can replace CTI and offensive security teams. Success in AI-supported penetration testing relies on expert control, business awareness, and rigorous risk management. Human expertise remains essential for interpreting results and making informed decisions.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Taken together, these High-potential Accelerator cases show how AI amplifies CTI across three core functions: detecting financial fraud and brand impersonation threats (a), prioritizing vulnerability patching (b), and enhancing proactive threat hunting and validation of adversary behaviors (c). Acting as a force multiplier rather than a substitute, AI accelerates intelligence exploitation, improves prioritization, and strengthens decision-making.</p>
<p> </p>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-29968" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/High-Potential-Accelerators-Use-Cases-Across-the-CTI-Lifecycle.png" alt="" width="1177" height="473" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/High-Potential-Accelerators-Use-Cases-Across-the-CTI-Lifecycle.png 1177w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/High-Potential-Accelerators-Use-Cases-Across-the-CTI-Lifecycle-437x176.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/High-Potential-Accelerators-Use-Cases-Across-the-CTI-Lifecycle-71x29.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/High-Potential-Accelerators-Use-Cases-Across-the-CTI-Lifecycle-768x309.png 768w" sizes="auto, (max-width: 1177px) 100vw, 1177px" /></p>
<p> </p>
<h2 style="text-align: justify;">Frontiers Bets</h2>
<p style="text-align: justify;"><strong>“Frontier Bets” represent more complex and experimental AI applications in CTI, requiring significant transformation of operating models and strong governance frameworks. </strong>Compared to the two other tiers, they involve higher uncertainty, stronger dependency on data quality, and risks that are harder to detect or control (e.g., bias, hallucination, strategic misalignment). As such, they should be approached through controlled experimentation, with strict guardrails, human oversight, and iterative validation before scaling.</p>
<p> </p>
<h3 style="text-align: justify;">AI to improve situational awareness of the cyber threat landscape (3a.)</h3>
<p style="text-align: justify;">AI could help maintain a comprehensive understanding of the cyber threat landscape by serving as a preliminary layer of analysis before CTI experts validate and expand it. More broadly, it could enable the continuous synthesis of the threat landscape from OSINT sources, partners, and vendors, and the detection of emerging trends and correlations for informed strategic decision-making. While the autonomous drafting of CTI reports by large language models raises the risk of biased outputs and AI hallucinations, AI should initially be used to support analysts in drafting activities to help them gain time in the analysis of cyber threats, serving as a pragmatic first step toward broader AI integration in this use case.  The market maturity for use cases supporting the full intelligence lifecycle remains limited, with few industrialized and proven solutions available.</p>
<p> </p>
<h3 style="text-align: justify;">AI to enhance identity-based threat detection and response (3b.)</h3>
<p style="text-align: justify;">AI could strengthen CTI for identity‑driven use cases by enabling earlier detection of attacker behaviors and supporting deception techniques such as honey accounts<sup>[3]</sup> or canary tokens<sup>[4]</sup> to expose and divert adversaries. By treating identities as active sensors, organizations can surface stealthy attacker activity before full compromise. AI could help scale these mechanisms by automating deployment, continuously tuning detection signals, and correlating weak indicators. It could also reduce analyst workload through intelligent alert triage, prioritizing high‑confidence identity‑related threats over noise. Despite its high potential for CTI and IAM teams, this use case remains at an experimental stage due to the limited maturity of identity‑centric deception techniques, integration complexity with IAM and SOC processes, and the need for strong governance to avoid false positives, operational overhead, or unintended exposure of deception assets.</p>
<p> </p>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-29966" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Frontier-Bets-Use-Cases-Across-the-CTI-Lifecycle.png" alt="" width="1199" height="475" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Frontier-Bets-Use-Cases-Across-the-CTI-Lifecycle.png 1199w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Frontier-Bets-Use-Cases-Across-the-CTI-Lifecycle-437x173.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Frontier-Bets-Use-Cases-Across-the-CTI-Lifecycle-71x28.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/05/Frontier-Bets-Use-Cases-Across-the-CTI-Lifecycle-768x304.png 768w" sizes="auto, (max-width: 1199px) 100vw, 1199px" /></p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">AI is already transforming how organizations produce and use cyber threat intelligence, not by replacing analysts, but by amplifying their ability to process information and enhance decision-making at scale. This article highlights where enterprise-internal AI can deliver value to CTI by focusing on the use cases most relevant in practice. To structure this approach, we introduced a pragmatic three-tier model to help prioritize efforts and adopt AI progressively based on the organization’s maturity, from low-risk &#8220;Safe Wins&#8221; to more advanced use cases dependent on high-quality data, robust governance as well as human oversight and AI model explainability.</p>
<p style="text-align: justify;">Organizations should therefore focus on applying AI where it creates measurable value and aligns with their level of maturity, reinforcing a key reality: AI does not create CTI maturity, it amplifies it. Recent developments such as Anthropic’s Mythos also illustrate a broader shift in the cyber landscape: AI is beginning to compress the gap between vulnerability discovery and operational exploitation, while significantly reducing the cost and complexity of large-scale offensive operations. While the exact pace and scale of this evolution remain uncertain, it highlights the need for organizations to become “Mythos-ready” by enabling teams to leverage AI for defense while ensuring robust cybersecurity fundamentals.</p>
<p style="text-align: justify;">At Wavestone, we support organizations in navigating this transformation, from identifying high-potential use cases to implementing AI in a controlled, scalable, and value-driven manner across their CTI capabilities.</p>
<p> </p>
<hr />
<p style="text-align: justify;"><sup>[1]</sup><span style="text-decoration: underline;"><strong>NLP (Natural Language Processing) :</strong></span> AI techniques used to analyze and understand human language in text or speech</p>
<p style="text-align: justify;"><sup>[2]</sup><span style="text-decoration: underline;"><strong>RAG (Retrieval‑Augmented Generation) :</strong></span> AI approach in which a generative model is systematically enriched with relevant contextual information retrieved from curated knowledge sources at query time, allowing it to produce outputs that are better aligned with a given operational or analytical context</p>
<p style="text-align: justify;"><sup>[3]</sup><strong><span style="text-decoration: underline;">Honey account :</span></strong> A decoy user account created to mimic a legitimate identity, used to detect unauthorized access when an attacker attempts to use it</p>
<p style="text-align: justify;"><sup>[4]</sup><span style="text-decoration: underline;"><strong>Canary token :</strong></span> A planted digital artifact (e.g., credential, file, or link) that triggers an alert when accessed or used, revealing potential malicious activity</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/05/amplifying-cyber-threat-intelligence-with-ai-a-pragmatic-maturity-driven-approach/">Amplifying Cyber Threat Intelligence with AI: A Pragmatic, Maturity Driven Approach</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/05/amplifying-cyber-threat-intelligence-with-ai-a-pragmatic-maturity-driven-approach/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
