Jason Edwards

Certified: The GIAC GCTI Audio Course

This course is designed to teach you how real-world threat intelligence actually works, from first signal to final decision. It focuses on turning raw technical data into clear, defensible intelligence that security teams and leaders can trust. Rather than memorizing isolated frameworks or chasing alerts, you learn how to think analytically, challenge assumptions, and build conclusions that hold up under pressure. The emphasis throughout is on clarity, rigor, and practical application in modern security environments. You will learn how to model intrusions, track adversary behavior over time, a...

Author

Jason Edwards

Category

Technology

Latest episode

Feb 8, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Welcome to the GIAC GCTI Audio Course 08.02.2026

This course is designed to teach you how real-world threat intelligence actually works, from first signal to final decision. It focuses on turning raw technical data into clear, defensible intelligence that security teams and leaders can trust. Rather than memorizing isolated frameworks or chasing alerts, you learn how to think analytically, challenge assumptions, and build conclusions that hold u...

Episode 67 — Exam-day tactics to maximize your score 08.02.2026

The transition from months of intense study to the actual day of the GCTI assessment requires a shift from learning mode to performance mode, where technical expertise must be demonstrated under the constraints of a high-stakes, timed evaluation. This episode provides practical advice for navigating the assessment, such as reading every question twice to identify specific qualifiers like "not" or...

Episode 66 — Deliver high-impact briefings under time pressure 08.02.2026

The ultimate test of a senior intelligence professional is the ability to distill weeks of technical forensic work into a few moments of high-stakes communication. In the professional world of cybersecurity, you will often find yourself in situations where a critical decision must be made, and you have only a brief window to influence the outcome. Typically, a seasoned cybersecurity educator will...

Episode 65 — Close stakeholder feedback loops for iteration 08.02.2026

The final stage of a mature intelligence lifecycle is the closing of the feedback loop, where stakeholder input is used to drive the continuous improvement and iteration of your analytical products. This episode focuses on the "service-oriented" nature of intelligence, emphasizing that your reports must evolve as the needs of your audience and the tactics of the adversary shift. We discuss how to...

Episode 64 — Handle sensitivities and caveats without friction 08.02.2026

Managing the sensitivity of intelligence data is a non-negotiable professional requirement, necessitating the use of the Traffic Light Protocol (TLP) to ensure that caveats and sharing restrictions are clearly understood by all parties. This episode breaks down the four TLP color codes—RED, AMBER, GREEN, and CLEAR—and provides specific scenarios for when to apply each label to your internal and ex...

Episode 63 — Exchange intelligence using standards that travel 08.02.2026

To achieve the speed and scale required for modern defense, intelligence must be exchanged using universal technical standards that allow disparate security tools to communicate without manual translation. This episode focuses on the implementation of the STIX (Structured Threat Information Expression) and TAXII (Trusted Automated Exchange of Intelligence Information) protocols, which serve as the...

Episode 62 — Share intelligence through trusted, auditable processes 08.02.2026

Collaborative defense depends on the secure and auditable exchange of threat data with trusted partners, requiring a strict adherence to protocols that protect both the information and the organization’s reputation. This episode examines the establishment of "circles of trust" within Information Sharing and Analysis Centers (ISACs) and the importance of having a clear understanding of how shared d...

Episode 61 — Measure intelligence impact with meaningful feedback 08.02.2026

Measuring the true value of a threat intelligence program requires moving beyond vanity metrics, like the volume of reports produced, and focusing on the tangible impact your work has on organizational risk. This episode explores the transition from quantitative counting to qualitative assessment, where success is measured by the number of "intel-led" detections or the strategic decisions influenc...

Episode 60 — Write decision-focused reports leaders actually read 08.02.2026

Writing effective intelligence reports requires a "decision-focused" approach, ensuring that busy executive leaders can immediately understand the threat and the specific actions they need to authorize. This episode explores the "Bottom Line Up Front" (BLUF) style of communication, where the most critical information—the threat, the business risk, and the recommendation—is placed in the very first...

Episode 59 — Enable proactive threat hunting that finds needles 08.02.2026

Proactive threat hunting uses intelligence to search for "hidden" threats that have successfully bypassed automated security controls, requiring a disciplined, human-led approach to data interrogation. This episode teaches you how to build a "hypothesis-driven" hunting plan based on the latest intelligence about an adversary's preferred techniques, such as "Credential Dumping" or "DLL Sideloading....

Episode 58 — Drive detection engineering with intel requirements 08.02.2026

Intelligence requirements should be the primary driver for the detection engineering process, ensuring that the organization’s monitoring rules are specifically tuned to the behaviors of the most relevant adversaries. This episode explores how to use observed TTPs from recent campaigns to define the logic for new security alerts, moving beyond static signatures to focus on attacker "habits." We di...

Episode 57 — Operationalize intelligence for frontline defenders 08.02.2026

The ultimate value of threat intelligence is measured by its ability to be "operationalized" into specific, technical actions that help frontline defenders detect and contain threats more effectively. This episode focuses on turning abstract analytical findings into "decision-ready" data for the Security Operations Center, such as high-fidelity indicator lists, custom detection rules, and incident...

Episode 56 — Manage attribution bias and external pressure 08.02.2026

Maintaining analytical objectivity is a significant challenge when faced with high-stakes security incidents and intense external pressure from leadership or the media to provide quick answers. This episode examines the impact of cognitive biases—such as confirmation bias and the "sophistication trap"—on the attribution process, and provides strategies for mitigating their influence. We discuss ho...

Episode 55 — Reassess attribution as new signals emerge 08.02.2026

Attribution is a dynamic process that must be constantly reassessed as new technical signals and external reporting emerge to challenge old conclusions. This episode focuses on the "iterative" nature of intelligence, explaining how the discovery of a leaked malware builder or a new campaign can completely overturn a previous assessment. We discuss the importance of maintaining an "open-file" minds...

Episode 54 — Present attribution responsibly to decision makers 08.02.2026

Presenting attribution findings to executive leadership requires a strategic shift in communication, focusing on the business implications of the threat rather than just the technical name of the actor. This episode teaches you how to brief senior stakeholders on "who" is responsible in a way that manages their expectations and acknowledges the inherent uncertainty of the process. We discuss the i...

Episode 53 — Calibrate attribution confidence with sober language 08.02.2026

The language used to describe attribution must be carefully calibrated to reflect the true level of analytical certainty and to avoid the dangerous misunderstandings that come with absolute declarations. This episode focuses on the "words of estimative probability" and standardized confidence scales used to communicate how sure an analyst is about an actor's identity. We discuss the transition fro...

Episode 52 — Weigh attribution tradeoffs and avoid overreach 08.02.2026

Attribution is a high-stakes analytical exercise that requires a careful weighing of tradeoffs between the need for accountability and the risk of making an incorrect or premature claim. This episode explores the different levels of attribution—from the specific "keyboard operator" to the "sponsoring organization" or "nation-state"—and discusses the technical and geopolitical implications of each....

Episode 51 — Track adversary TTPs to anticipate moves 08.02.2026

Tracking an adversary's Tactics, Techniques, and Procedures (TTPs) is the most effective way to move from a reactive defensive posture to a proactive, anticipatory one. This episode focuses on the use of the MITRE ATT&CK framework to catalog the specific behaviors observed during an intrusion, such as "Process Injection" or "Account Discovery." We explain how these behavioral patterns are much...

Episode 50 — Build timelines that expose adversary cadence 08.02.2026

Constructing a detailed master timeline of an intrusion is one of the most powerful ways to expose an adversary’s "operational cadence" and identify patterns in their technical behavior. This episode focuses on the "normalization" of timestamps across multiple data sources to create a unified chronological record of every command, connection, and file modification performed by the attacker. We exp...

Episode 49 — Profile campaigns with evidence and restraint 08.02.2026

Campaign profiling is the disciplined act of grouping related incidents into a single, cohesive narrative while exercising the technical restraint needed to avoid over-generalization or premature attribution. This episode explores how to use commonalities in victimology, infrastructure reuse, and unique malware features to prove that a series of events are part of a coordinated mission. We discuss...

Episode 48 — Pressure-test conclusions before they reach leaders 08.02.2026

Before any intelligence product is disseminated to executive leadership, it must undergo a rigorous "pressure-test" to identify logical flaws, unverified assumptions, or potential biases that could compromise the accuracy of the report. This episode focuses on the "peer review" and "red teaming" processes where other analysts intentionally challenge your evidence, your pivots, and your final attri...

Episode 47 — Turn abstract models into defender guidance 08.02.2026

The true value of analytical frameworks lies in their ability to be translated from abstract concepts into concrete, actionable guidance for frontline defenders and incident responders. This episode teaches you how to take a completed Diamond Model or a Kill Chain mapping and turn it into a prioritized list of firewall blocks, endpoint detection rules, and proactive hunting queries. We discuss the...

Episode 46 — Blend multiple models to strengthen conclusions 08.02.2026

Relying on a single framework can create analytical blind spots, so the most effective investigators blend multiple models like the Cyber Kill Chain, the Diamond Model, and MITRE ATT&CK to create a more resilient and multi-dimensional conclusion. This episode explains how to use the linear progression of the Kill Chain to track an adversary's progress while simultaneously using the Diamond Mod...

Episode 45 — Select courses of action that change outcomes 08.02.2026

Choosing the right "course of action" (CoA) is the ultimate goal of the intelligence process, ensuring that technical insights lead to tangible changes in security outcomes. This episode explores the six defensive categories of CoA: discover, detect, disrupt, degrade, deceive, and destroy, providing a strategic framework for selecting the most effective response for a given threat. We discuss how...

Episode 44 — Model intrusions with the diamond for clarity 08.02.2026

The Diamond Model of Intrusion Analysis provides a non-linear framework that emphasizes the relationships between the four core facets of every security event: the adversary, the infrastructure, the capability, and the victim. This episode focuses on using the Diamond Model to organize complex data and identify "missing links" in your investigation, such as when you have the "malware" (capability)...

Listen to the Certified: The GIAC GCTI Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.