Jason Edwards

Certified: The GIAC GCTI Audio Course

This course is designed to teach you how real-world threat intelligence actually works, from first signal to final decision. It focuses on turning raw technical data into clear, defensible intelligence that security teams and leaders can trust. Rather than memorizing isolated frameworks or chasing alerts, you learn how to think analytically, challenge assumptions, and build conclusions that hold up under pressure. The emphasis throughout is on clarity, rigor, and practical application in modern security environments. You will learn how to model intrusions, track adversary behavior over time, a...

Author

Jason Edwards

Category

Technology

Latest episode

Feb 8, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 18 — Deduplicate, cleanse, and harden your datasets 08.02.2026

A high-fidelity intelligence product depends on the quality of its underlying data, requiring a disciplined approach to deduplication and cleansing to ensure accuracy. This episode examines the methods for identifying and removing redundant indicators that often clutter threat feeds, ensuring that your analysts only spend time on unique and relevant signals. We explore data cleansing techniques to...

Episode 17 — Normalize incoming data so patterns pop out 08.02.2026

Data normalization is the essential process of converting disparate log formats and technical artifacts into a common schema so that patterns and correlations become visible to the analyst. This episode focuses on the technical challenges of reconciling different date-time formats, character encodings, and field naming conventions across a diverse security stack. We discuss how normalizing all tim...

Episode 16 — Exploit certificate transparency for stealthy infrastructure clues 08.02.2026

Certificate Transparency (CT) logs provide a goldmine of information for analysts looking to identify adversary infrastructure before it is even fully operational. This episode explores how to monitor public CT logs to discover newly issued Transport Layer Security (TLS) certificates that may be part of a domain-shadowing or typosquatting campaign. By examining the Common Name and Subject Alternat...

Episode 15 — Extract domain intelligence that drives confident pivots 08.02.2026

Domain names and their associated infrastructure are often the most visible and easily trackable components of an adversary's offensive operation. This episode focuses on extracting "domain intelligence" from DNS records, mail exchanger (MX) settings, and IP resolutions to uncover the broader scope of a threat actor's network. We explain how to use this data to drive "confident pivots," moving fro...

Episode 14 — Mine internal telemetry for durable intelligence wins 08.02.2026

While external data is important, your own internal telemetry often provides the most durable and high-fidelity intelligence "wins" for your specific organization. This episode explores how to mine your own history of incidents, failed login attempts, and blocked web traffic to identify patterns of adversary behavior that are unique to your network. We discuss building a "threat library" of intern...

Episode 13 — Make external threat feeds actually pay off 08.02.2026

External threat feeds are often a major investment for security teams, but they only provide value if they are correctly integrated and operationalized within the local environment. This episode teaches you how to "curate" commercial and open-source feeds, ensuring that the indicators of compromise (IOCs) you ingest are relevant to your specific industry, geography, and technology stack. We discus...

Episode 12 — Pull forensic artifacts that advance your hypothesis 08.02.2026

Forensic artifacts left behind on a compromised host provide the most detailed evidence of an adversary's presence and their specific technical actions. This episode focuses on identifying and extracting high-value artifacts—such as prefetch files, registry keys, shimcache entries, and amcache data—that can either prove or disprove your current investigative hypothesis. We explain how these artifa...

Episode 11 — Turn messy logs into decision-ready insights 08.02.2026

Raw system logs are often voluminous and chaotic, requiring a disciplined approach to processing to transform them into insights that a leader can use to make a decision. This episode covers the essential techniques of data parsing, filtering, and correlation, showing you how to find the "needle in the haystack" of millions of log entries. We discuss the importance of field mapping and timestamp n...

Episode 10 — Read network telemetry for signals that count 08.02.2026

Network telemetry serves as a primary source of ground truth during an investigation, providing a technical record of every interaction between the adversary and the targeted infrastructure. This episode focuses on identifying the specific signals that count, such as unusual outbound traffic patterns, non-standard protocol usage, and suspicious domain name system (DNS) queries. We dive into the an...

Episode 9 — Pick high-value sources and skip the noise 08.02.2026

In an era of information overload, the ability to identify and prioritize high-value sources while filtering out irrelevant "noise" is essential for analytical efficiency. This episode examines the diversity of intelligence sources, ranging from internal telemetry and dark web forums to open-source social media and paid commercial threat feeds. We discuss how to evaluate a source based on its reli...

Episode 8 — Write crisp intelligence requirements stakeholders love 08.02.2026

The success of an intelligence program is dictated by its ability to answer the specific questions posed by its stakeholders, making the creation of crisp intelligence requirements (IRs) a fundamental skill. This episode teaches you how to translate vague business concerns into technical, actionable requirements that guide the entire collection and analysis process. We distinguish between Priority...

Episode 7 — Profile threat actors, motives, and constraints that matter 08.02.2026

Successful intrusion analysis requires moving beyond technical artifacts to understand the human adversary, their underlying motivations, and the operational constraints that dictate their behavior. This episode explores the various categories of threat actors, including nation-states, cybercriminals, hacktivists, and insiders, emphasizing how their distinct motives—such as espionage, financial ga...

Episode 6 — Master the full intelligence cycle without busywork 08.02.2026

The intelligence cycle provides the structural backbone for any professional analytical mission, transforming fragmented data into a cohesive and actionable security product. This episode dives into each of the five core stages: planning and direction, collection, processing and exploitation, analysis and production, and dissemination and feedback. We focus on eliminating "busywork" by ensuring th...

Episode 5 — Separate strategic, operational, and tactical intelligence fast 08.02.2026

Effectively categorizing intelligence into strategic, operational, and tactical levels is a core requirement for both the GCTI exam and the successful operation of a threat intelligence team. This episode provides a rapid-fire framework for separating these layers: strategic intelligence informs high-level decision-makers about long-term trends and geopolitical risks; operational intelligence iden...

Episode 4 — Grasp threat intelligence essentials with real-world focus 08.02.2026

The foundation of a world-class security posture is built upon a deep understanding of threat intelligence essentials, moving beyond theoretical definitions to focus on the practical application of data in the heat of a breach. This episode defines threat intelligence as the collection, analysis, and dissemination of information about adversaries to inform defensive decision-making and reduce orga...

Episode 3 — Build a winning audio-only study routine 08.02.2026

Developing a highly effective, audio-driven study routine allows busy professionals to maximize their preparation time by integrating learning into their daily commutes, gym sessions, or household tasks. This episode explores the science of auditory learning and how to utilize audio-only episodes to reinforce core cybersecurity concepts, such as the various stages of the intelligence cycle or the...

Episode 2 — Decode scoring, timing, proctoring, and hidden pitfalls 08.02.2026

Navigating the administrative and logistical landscape of a high-stakes certification exam is just as critical as technical proficiency for achieving a passing score. This episode provides a detailed examination of the GCTI scoring algorithm, the strict four-hour time limit, and the nuances of the remote or in-person proctoring experience. Understanding the "CyberLive" hands-on virtual machine env...

Episode 1 — Conquer the GCTI blueprint 08.02.2026

Mastering the GIAC Cyber Threat Intelligence (GCTI) certification begins with a comprehensive understanding of the exam blueprint, which serves as the official roadmap for every technical domain you will encounter. This episode breaks down the weighted distribution of topics, from strategic intelligence planning and open-source intelligence (OSINT) gathering to complex intrusion analysis and the a...

Listen to the Certified: The GIAC GCTI Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.