Program Agenda

Agenda is subject to change. Times are reflected in UTC +1 (CET). Workshop sessions have limited seating and based on the registration admission purchased. Plenary sessions are open to all registered delegates.

Virtual Attendance: All TLP:CLEAR plenary presentations will be streamed live. Workshops will not be streamed. Virtual registration is available within the registration form. Streaming will be delivered over Zoom.

Registration Hours

Monday, November 6 - Registration Located on Level 2, Atrium
07:00-10:00 | Registration for Workshop Participants ONLY
11:00-18:00 | Registration for Plenary Participants

Tuesday, November 7 - Registration Located on Level 1, Near Stairway from 2 and Mall Entrance
08:00-16:00 | Registration

Wednesday, November 8 - Registration Located on Level 1, Near Stairway from 2 and Mall Entrance
08:00-15:00 | Registration

Monday, November 6th

Training: Track 1
Level 2 - MOA 16
Training: Track 2
Level 2 - MOA 14
Training: Track 3
Level 2 - MOA 15
08:30 – 09:00

Threat Quantification & Prioritization 101: A Practical Guide to Building (& Maintaining) Your Cyber Threat Profile (08:30-11:00)

Scott Small (Tidal Cyber, US); Simone Kraus (indevis GmbH , DE)

09:00 – 10:00

Intelligence Planning Workshop - How to Create and Employ an Intelligence Plan that Synchronizes with your Stakeholders Needs (09:00-13:00)

Michael DeBolt (Intel 471, US); Freddy Murstad (Nordic Financial CERT, NO)


Threat Quantification & Prioritization 101: A Practical Guide to Building (& Maintaining) Your Cyber Threat Profile (08:30-11:00)

Scott Small (Tidal Cyber, US); Simone Kraus (indevis GmbH , DE)


Hunting and Tracking Adversaries (09:00-13:00)

Bartek Jerzman (Standard Chartered, PL)

10:00 – 10:15

Coffee Break | Level 2 Atrium

10:15 – 11:00

Intelligence Planning Workshop - How to Create and Employ an Intelligence Plan that Synchronizes with your Stakeholders Needs (09:00-13:00)

Michael DeBolt (Intel 471, US); Freddy Murstad (Nordic Financial CERT, NO)


10:15 – 13:00


Threat Quantification & Prioritization 101: A Practical Guide to Building (& Maintaining) Your Cyber Threat Profile (08:30-11:00)

Scott Small (Tidal Cyber, US); Simone Kraus (indevis GmbH , DE)


Hunting and Tracking Adversaries (09:00-13:00)

Bartek Jerzman (Standard Chartered, PL)


10:15 – 13:00

11:00 – 13:00

How to Align CTI and Risk Management: Successfully Connecting Two Related Practices (11:00-15:45)

Grace Chi (Pulsedive, US); Jamie Collier, John Doyle (US)

13:00 – 14:00

Lunch Break | Level 2 Atrium

14:00 – 15:45

MISP CTI Analyst Threat Information Creator Workshop (14:00-18:00)

Alexandre Dulaunoy, Andras Iklody (CIRCL, LU)


How to Align CTI and Risk Management: Successfully Connecting Two Related Practices (11:00-15:45)

Grace Chi (Pulsedive, US); Jamie Collier, John Doyle (US)


‘Build Your Own Threat Landscape’ Workshop (14:00-18:00)

Brian Mohr (Reqfast, US); Roman Sannikov (Constellation Cyber LLC, US)

15:45 – 16:00

Coffee Break | Level 2 Atrium

16:00 – 18:00

MISP CTI Analyst Threat Information Creator Workshop (14:00-18:00)

Alexandre Dulaunoy, Andras Iklody (CIRCL, LU)


Priority Intelligence Requirements Workshop - How to Set the Directions of Your CTI Program

Ondra Rojcik, Vladimir Janout (Red Hat, CZ)


‘Build Your Own Threat Landscape’ Workshop (14:00-18:00)

Brian Mohr (Reqfast, US); Roman Sannikov (Constellation Cyber LLC, US)


Tuesday, November 7th

Plenary Sessions Day 1
Level 1, Rm MOA 6-9
09:00 – 09:15

Welcome Remarks

09:15 – 09:45

Helping Organizations Anticipate and Approach Emerging Technology Threats

Natalie Kilber (Harman International)

09:45 – 10:15

Solving CISO Headaches: How to Align CTI and Risk Management

Jamie Collier (US); John Doyle (Mandiant, US)

10:15 – 10:45

Networking Break with Exhibits | MOA 3-5

10:45 – 11:15

Will the Real Attribution Please Stand Up?

Alexis Dorais-Joncas; Joshua Miller (US)

11:15 – 11:45

What is a Threat Actor? Tracking Sandworm's Transformation

Lennart Maschmeyer (ETH Zürich, CH)

11:45 – 12:15

If You Want to Build Good Intelligence Requirements, You Do Not Start with Intelligence Requirements.

Brian Mohr (Reqfast, US)

12:15 – 13:30

Lunch Break with Exhibits | MOA 3-5

13:30 – 14:00

PXF-X - A Modular Python Framework to Hunt, Extract and Enrich Post-Exploitation Framework Artifacts

Joel Doenne (ATRUVIA AG, DE)

14:00 – 14:30

MISP 3 - Teaching an Old Dog New Tricks

Andras Iklody, Sami Mokaddem (CIRCL, LU)

14:30 – 15:00

How to Tango with MISP

Ingrid Grimstad (NO)

15:00 – 15:30

Networking Break with Exhibits | MOA 3-5

15:30 – 16:00

ThreatIntelGPT: STIX from Chaos

David Greenwood (EclecticIQ & Signals Corp, GB)

16:00 – 16:30

Automating the Junior Analyst: Cyber Security Report Generation with Classic AI

Sergey Polzunov (, NL)

16:30 – 17:00

Why AI Will Not Take Our CTI Analyst Jobs (But We Should Befriend the Machines, Anyway)

Stewart Bertram (Elemendar, GB)

17:00 – 17:10

Closing Remarks

17:30 – 18:30

Networking Reception with Exhibits - Sponsored by Silent Push | Level 1, Rm MOA 3-5

Wednesday, November 8th

Plenary Sessions Day 2
Level 1, Rm MOA 6-9
08:50 – 09:00

Opening Remarks

09:00 – 09:30

How Much Alert Fatigue Actually is Threat Intel Fatigue?

Markus Ludwig (ticura, DE)

09:30 – 10:00

Insights on the Spread and Use of Threat Intelligence Sharing Platforms

Clemens Sauerwein ( University of Innsbruck, Department of Computer Science, AT); Daniel Fischer (Technische Universität Ilmenau, DE)

10:00 – 10:30

The Blueprint for Enduring Actionable CTI

Ross Rustici (US)

10:30 – 11:00

Networking Break with Exhibits | MOA 3-5

11:00 – 11:30

OSINT The Hard Way: Navigating Hard Targets In Open-Source Intelligence

Kamil Bojarski (Standard Chartered Bank, PL)

11:30 – 12:00

VERIS Mappings to ATT&CK - Bridging Risk-based and Ops-focused Incident Classification (Virtual)

David Hylender, Philippe Langlois (US)

12:00 – 13:15

Lunch Break with Exhibits | MOA 3-5

13:15 – 13:45

How to Improve Your Threat Intelligence Process with AIL Project

Alexandre Dulaunoy (CIRCL, LU)

13:45 – 14:15

Foresight Analysis: The Magic Eight Ball of Intelligence Analysis

Freddy Murstad (Nordic Financial CERT, NO)

14:15 – 14:45

Networking Break with Exhibits | MOA 3-5

14:45 – 15:15

CTI, a Key Component into the M&A Process

Catalin Curelaru, Espen Johansen

15:15 – 15:45

Spin Your CTI Process Round

Andreas Sfakianakis (SAP, GR)

15:45 – 16:15

A Collective CTI Doctrine

David Bizeul, Fabien Gainier (FR)

16:15 – 16:30

Closing Remarks