Jason Edwards
Certified: The GIAC GCTI Audio Course
This course is designed to teach you how real-world threat intelligence actually works, from first signal to final decision. It focuses on turning raw technical data into clear, defensible intelligence that security teams and leaders can trust. Rather than memorizing isolated frameworks or chasing alerts, you learn how to think analytically, challenge assumptions, and build conclusions that hold up under pressure. The emphasis throughout is on clarity, rigor, and practical application in modern security environments. You will learn how to model intrusions, track adversary behavior over time, a...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 43 — Analyze intrusions through the kill chain lens 08.02.2026 15:28
The Cyber Kill Chain provides a powerful, linear lens for analyzing intrusions and identifying the specific stages where an adversary is most vulnerable to detection and disruption. This episode breaks down the seven stages of the Lockheed Martin model—from reconnaissance and weaponization to actions on objectives—and explains how to map your technical observations to each phase. We discuss the "d...
Episode 42 — Prioritize malware-driven tasks for maximum impact 08.02.2026 14:06
In the high-pressure environment of a breach, an analyst must be able to prioritize their malware-driven tasks to ensure they are providing the most impactful information to the defense team as quickly as possible. This episode focuses on the "triage" of malware analysis tasks—such as extracting C2 domains first, then analyzing persistence mechanisms, and finally performing full reverse engineerin...
Episode 41 — Connect malware families to credible campaigns 08.02.2026 14:21
Connecting individual malware samples to larger, credible campaigns is a vital step in moving from tactical detection to operational intelligence. This episode teaches you how to look for commonalities in delivery vectors, command-and-control (C2) infrastructure, and victimology that suggest a series of intrusions are part of a coordinated effort by a single threat actor. We discuss the "attributi...
Episode 40 — Pivot on malware metadata for campaign reach 08.02.2026 13:18
Malware metadata often contains "unintentional clues" left by the developers that allow an analyst to pivot and uncover the full scope of a global campaign. This episode explores how to use metadata such as compile timestamps, Rich Headers, PDB (Program Database) paths, and signing certificates to link disparate malware samples to a single production environment or actor. We discuss how these "dev...
Episode 39 — Extract static malware features that travel well 08.02.2026 13:10
Static malware analysis allows for the extraction of technical features that are "durable" and "portable," making them ideal for sharing across a global intelligence community. This episode focuses on identifying high-value static artifacts—such as imphash (import hash), fuzzy hashes (SSDEEP), unique strings, and embedded metadata—that can be used to identify malware families regardless of minor c...
Episode 38 — Read malware behavior to surface adversary goals 08.02.2026 13:40
Analyzing the dynamic behavior of malware within a controlled sandbox environment provides direct insights into the adversary's ultimate tactical and strategic goals. This episode explores how to interpret behavioral signals—such as file system modifications, network beaconing patterns, and credential-harvesting activities—to determine what the attacker intended to achieve once they gained access....
Episode 37 — Review boost: analysis and pivoting mastery 08.02.2026 12:19
This mid-course review boost is designed to solidify your mastery of advanced analytical frameworks and the technical art of multi-stage pivoting. This episode synthesizes the core lessons from the previous ten units, focusing on the practical application of Passive DNS, WHOIS history, and link analysis to map complex adversary ecosystems. We provide a series of "mental exercises" designed to test...
Episode 36 — Validate every pivot without chasing ghosts 08.02.2026 12:07
Analytical discipline requires that every technical pivot be rigorously validated to ensure that the investigation remains grounded in fact rather than descending into speculative "rabbit holes." This episode focuses on the "validation criteria" used to confirm that a newly discovered piece of infrastructure or a related file truly belongs to the adversary under investigation. We discuss the dange...
Episode 35 — Cluster weak signals into compelling hypotheses 08.02.2026 13:38
The ability to identify "weak signals"—subtle, seemingly unrelated anomalies—and cluster them into a compelling investigative hypothesis is what defines a master threat intelligence analyst. This episode teaches you how to look for low-fidelity indicators that, when combined, suggest a broader pattern of malicious activity that automated systems have missed. We discuss the "clustering" process, wh...
Episode 34 — Leverage WHOIS and registration breadcrumbs smartly 08.02.2026 12:41
WHOIS records and registration metadata provide vital "human breadcrumbs" that can link digital infrastructure to the actual individuals or organizations behind an attack. This episode explores how to leverage registrant names, email addresses, phone numbers, and physical addresses to uncover clusters of adversary activity, even when privacy services are used. We discuss the impact of GDPR (GDPR)...
Episode 33 — Exploit passive DNS for historical context 08.02.2026 13:53
Passive DNS (pDNS) is a critical forensic resource that provides a historical record of domain-to-IP resolutions, allowing an analyst to see how an adversary's infrastructure has changed over time. This episode focuses on exploiting pDNS to find "temporal patterns," such as when a domain was first registered, when it began resolving to a malicious IP, and if it has been used in previous campaigns....
Episode 32 — Run link analysis that reveals hidden clusters 08.02.2026 14:58
Link analysis is a powerful visualization technique used to uncover the "connective tissue" between seemingly unrelated technical artifacts and adversary campaigns. This episode teaches you how to build "relational graphs" that link entities such as email addresses, file hashes, and infrastructure nodes to reveal hidden clusters of activity. We explore the use of graph theory to identify "central"...
Episode 31 — Pivot from domains to infrastructure with intent 08.02.2026 13:14
Pivoting with intent is the art of using a single technical indicator to map out an adversary's broader offensive infrastructure with surgical precision. This episode explores the methodologies for moving from a malicious domain name to identifying the underlying command-and-control (C2) servers, name servers, and hosting providers used in a campaign. We discuss the use of passive DNS (pDNS) to fi...
Episode 30 — Triage indicators into true intelligence value 08.02.2026 15:30
Effective indicator triage is a vital skill for managing the flood of data that enters a modern security operations center, ensuring that analysts focus on signals with the highest intelligence value. This episode focuses on the "scoring" and "prioritization" of indicators based on their longevity, uniqueness, and direct relevance to the organization’s high-value assets. We discuss moving up the "...
Episode 29 — Avoid analytic pitfalls that sink good teams 08.02.2026 10:56
Even the most talented intelligence teams can be derailed by common analytic pitfalls that lead to flawed conclusions and wasted resources. This episode examines the dangers of "mirror imaging," where an analyst assumes an adversary will think or act like they do, and "satisficing," the tendency to accept the first plausible explanation instead of finding the best one. We explore how "groupthink"...
Episode 28 — Form testable hypotheses that survive scrutiny 08.02.2026 11:14
A hypothesis-driven approach is essential for focused investigations, allowing an analyst to move beyond aimless data browsing to a structured search for the truth. This episode teaches you how to form "testable" hypotheses—logical statements that can be proven or disproven by technical evidence—such as "The adversary is using valid credentials to move laterally through the R&D segment." We di...
Episode 27 — State confidence and uncertainty like a pro 08.02.2026 11:34
Communicating the level of certainty in your findings is a hallmark of professional intelligence, requiring the use of standardized "words of estimative probability" to avoid misleading stakeholders. This episode focuses on how to calibrate your confidence levels—high, moderate, or low—based on the quality, reliability, and quantity of your evidence. We explore the critical difference between a "f...
Episode 26 — Synthesize multi-source findings into one clear story 08.02.2026 12:27
Synthesis is the sophisticated analytical process of merging fragmented data from disparate sources into a singular, cohesive narrative that explains an adversary's actions. This episode teaches you how to correlate technical indicators from network logs with external threat reports and human intelligence to build a comprehensive view of an intrusion. We discuss the challenge of resolving conflict...
Episode 25 — Rate sources and evidence with discipline 08.02.2026 13:21
Rating the reliability of your sources and the credibility of your evidence with technical discipline is essential for producing intelligence that leaders can trust. This episode explores the standardized "grading scales" used within the intelligence community, such as the Admirality Code, to communicate the level of certainty in a finding. We discuss how to evaluate a source’s history of accuracy...
Episode 24 — Defeat cognitive bias before it misleads you 08.02.2026 12:15
Cognitive biases are the "silent threats" in any investigation, capable of misleading even the most experienced analysts into reaching incorrect and dangerous conclusions. This episode examines common biases such as confirmation bias, availability heuristic, and groupthink, explaining how they manifest in the day-to-day work of a threat intelligence team. We discuss practical "de-biasing" strategi...
Episode 23 — Use structured analytic techniques that sharpen judgment 08.02.2026 12:42
Structured Analytic Techniques (SATs) are the professional tools used to remove subjectivity and sharpen judgment during complex investigations where information is incomplete or ambiguous. This episode focuses on the application of techniques like the Analysis of Competing Hypotheses (ACH), Devil's Advocacy, and Red Teaming to pressure-test your conclusions. We explain how ACH helps an analyst ev...
Episode 22 — Review checkpoint: foundations locked and loaded 08.02.2026 12:58
Success in the GCTI exam and real-world investigations depends on a rock-solid grasp of foundational concepts, making this review checkpoint a critical moment in your preparation. This episode synthesizes the core themes covered in the first third of the course, including the intelligence cycle, actor profiling, and the technical requirements of data collection and processing. We provide a series...
Episode 21 — Systematize collection with repeatable, scalable workflows 08.02.2026 14:19
To move from a reactive posture to a professional intelligence operation, an analyst must systematize their collection efforts using repeatable and scalable workflows. This episode explores the design of automated collection pipelines that can ingest, tag, and route data from hundreds of sources simultaneously without manual intervention. We discuss how to use Application Programming Interfaces (A...
Episode 20 — Exam Acronyms: quick audio reference you’ll reuse 08.02.2026 13:38
The field of threat intelligence is saturated with complex acronyms that serve as a shorthand for critical technical concepts, frameworks, and protocols. This episode provides a rapid-fire audio reference for the most essential GCTI acronyms, from foundational models like the ACH (Analysis of Competing Hypotheses) and the TTPs (Tactics, Techniques, and Procedures) to technical standards like STIX,...
Episode 19 — Govern retention, access, and evidence integrity 08.02.2026 12:50
Effective intelligence governance requires strict controls over how long data is stored, who can access it, and how the technical integrity of the evidence is maintained over time. This episode focuses on the legal and operational requirements for data retention, balancing the need for historical context against the risks of storing outdated or sensitive information. We discuss implementing Role-B...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.