From Ransomware Matrices To Actionable Threat Actor Profiles (Will Thomas & Pedro Kertzman) episode artwork

EPISODE · May 12, 2026 · 29 MIN

From Ransomware Matrices To Actionable Threat Actor Profiles (Will Thomas & Pedro Kertzman)

from Cyber Threat Intelligence Podcast · host Pedro Kertzman

The fastest way to fall behind in cybersecurity is to stay reactive while attackers iterate in real time. We sit down with Will Thomas, known across the CTI community as “BushidoToken” to get practical about what actually helps defenders: threat actor profiling that is repeatable, actionable, and built for change.We start with how Will builds community-ready resources like the ransomware tool matrix and his threat actor profiling guide, then zoom into the Conti leaks and what hundreds of thousands of internal ransomware messages can teach us. From “salary day” breakdowns to operator behavior during major incidents, we talk about why these datasets are a gold mine and how to avoid getting lost in the volume. Will shares a concrete workflow for large-scale analysis using JSON exports, regex searches, CyberChef, and Elasticsearch so you can extract IOCs, wallets, infrastructure clues, and the higher-level “so what” that drives detections and threat hunting.From there, we shift into emerging threats and modern intrusion tradecraft: hacktivism that ranges from empty noise to destructive campaigns, EDR bypass techniques like bring-your-own vulnerable drivers and “EDR-on-EDR” tactics, and the steady rise of legitimate tools abused for access. We also dig into identity-led attacks where stolen credentials, social engineering, and SSO platforms like Okta can make endpoint controls less decisive. Finally, we unpack threat intelligence exchange beyond IOC feeds, including why STIX/TAXII still matters, how data quality and freshness drive results, and why a bidirectional TIP and SIEM relationship enables better correlation and “sightings.”Subscribe, share the episode with your team, and leave a review, then tell us: what part of your threat intelligence program needs the biggest upgrade right now?Send us Fan MailSupport the showThanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

Episode metadata supplied by the publisher feed · Published May 12, 2026

Embed this episode

The fastest way to fall behind in cybersecurity is to stay reactive while attackers iterate in real time. We sit down with Will Thomas, known across the CTI community as “BushidoToken” to get practical about what actually helps defenders: threat actor profiling that is repeatable, actionable, and built for change. We start with how Will builds community-ready resources like the ransomware tool matrix and his threat actor profiling guide, then zoom into the Conti leaks and what hundreds of th...

Distinct summary based on available episode metadata or transcript content.

Ready to play

From Ransomware Matrices To Actionable Threat Actor Profiles (Will Thomas & Pedro Kertzman)

0:00 29:59

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Cyber Threat Intelligence Podcast?

This episode is 29 minutes long.

When was this Cyber Threat Intelligence Podcast episode published?

This episode was published on May 12, 2026.

Can I download this Cyber Threat Intelligence Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!