Know Your Adversary: Turning Threat Research into Defensive Action
Download resourcesAbout this session
Marcelle Lee, founder of Fractal Security Group and an adjunct cybersecurity professor, argues that raw threat intelligence is useless without a process to turn it into action. She walks through planning and prioritization (matching intel to an organization's industry, tech stack and regulatory footprint), the difference between strategic, tactical and operational intelligence, and who actually consumes it: executives, SOC, red and purple teams, PR, HR and even customers, most of whom do not yet know they need it. She covers extracting and handling intelligence responsibly, including source reliability, defanging indicators, the Traffic Light Protocol for sensitive sharing, and setting expiration dates so indicators age out of firewalls. Using the Pyramid of Pain, she explains why indicators of compromise are trivial for attackers to change while tactics, techniques and procedures are not, and why MITRE ATT&CK gives teams a shared language for detection, hunting and architecture decisions. She closes with a real attack-chain walkthrough of a Scattered Spider intrusion and a warning that current AI research tools still fabricate sources and cannot be trusted unverified.
Effective defense begins with understanding the adversary. Yet many organizations struggle to translate threat research into meaningful improvements to their security posture. Threat reports are collected, indicators are ingested, and intelligence feeds are monitored, but security teams are often left with a critical question: what should we do differently because of what we've learned?
This session explores how defenders can transform threat actor research into actionable security outcomes across the entire security lifecycle. Drawing on real-world experience building and supporting threat intelligence programs, Marcelle will demonstrate how organizations can leverage adversary tactics, techniques, and procedures (TTPs) to drive threat hunting, detection engineering, incident response, security control validation, and risk-informed decision making.
Using the MITRE ATT&CK® framework as a common language, attendees will learn practical methods for analyzing adversary behavior, identifying defensive gaps, and prioritizing efforts based on threats that matter most to their organization. The presentation focuses on moving beyond indicators of compromise and toward a deeper understanding of how threat actors operate, enabling defenders to build more resilient and proactive security programs.
Whether you're a threat hunter, SOC analyst, security leader, incident responder, or threat intelligence practitioner, you'll leave with practical strategies for turning adversary knowledge into measurable defensive action.
Key Takeaways
Learn how to identify and prioritize threat actor activity relevant to your organization
Understand how adversary TTPs can be used to drive threat hunting and detection engineering efforts
Apply the MITRE ATT&CK framework to map threats to defensive capabilities
Identify and address security control gaps through threat-informed analysis
Transform threat research into actionable outputs that improve security operations and decision-making
Key takeaways
- Before consuming any threat report, check whether your organization actually runs the affected software or hardware; irrelevant intelligence is not worth processing.
- Track tactics, techniques and procedures rather than only indicators of compromise; per the Pyramid of Pain, IPs and hashes are trivial for attackers to change but learned TTPs are not.
- Set expiration windows on ingested indicators (roughly three months for an IP, six for a domain, a year for a hash) so firewalls are not carrying an ever-growing, stale block list.
- Map every internal report and detection rule to MITRE ATT&CK so different teams share one vocabulary for what happened and what still needs coverage.
- Do not trust AI research tools to summarize threat news unverified; they have fabricated entire articles with dead-link sources, so confirm every claim against the original reporting.
Speakers

Founder and Principal Advisor at Fractal Security Group where I help organizations translate complex threat intelligence into clear, business-aligned strategy. Over a career spanning threat intelligence, emerging threat research, and program… Read moreRead less
Founder and Principal Advisor at Fractal Security Group where I help organizations translate complex threat intelligence into clear, business-aligned strategy. Over a career spanning threat intelligence, emerging threat research, and program development, I’ve built a reputation for turning technical depth into insight that strengthens client trust and guides executive decision-making.
I lead cross-functional research initiatives and deliver briefings, tabletop exercises, and advisory services to clients, partners, and stakeholders across government and industry. A core part of my work is building and expanding strategic partnerships that improve intelligence sharing and organizational resilience.
Beyond client work, I’m a frequent public speaker and technical writer, publishing weekly threat research through my Cyber Threat Bulletin, and presenting at industry conferences, webinars, and training events. I also serve on the board of the Cyberjutsu, supporting the next generation of women in cybersecurity.

