Skip to content
Artwork for Signals & Stories

Signals & Stories

The Vertex Project

A limited podcast series from The Vertex Project exploring how cyber threat intelligence has evolved over the past decade and what it takes to build intelligence teams can trust.

Play
  • 10 episodes
  • fortnightly
  • Avg 40 min
  • English
  • S1 · E9
    Tuesday · 54 min

    Episode 9: The Analyst and the Developer: Building Intelligence Together

    What happens when the people building intelligence software work side-by-side with the analysts actually using it? In the penultimate episode of our Signals & Stories 10-Year Anniversary series, Kali Fencl brings together both sides of the equation: Vertex analysts Jennifer Kolde (thesilence) and Mary Beth Lee (savage), alongside engineers William Gibb (epiphyte) and Mike Moritz (redox). Together, they dig into the relationship between analysts and developers including where their perspectives differ, what they've learned from each other, and how ten years of collaboration has helped shape Synapse. In this episode: 🔹 Why analyst "edge cases" aren't always edge cases 🔹 How better tooling gives analysts more time to actually analyze 🔹 Why messy real-world data complicates software development 🔹 How rapid feedback and frequent releases improve the platform 🔹 Why good software design often goes unnoticed 🔹 How Synapse power users increasingly bridge the gap between analyst and engineer 🔹 The tradeoffs behind deciding what features actually get built 🔹 How Synapse evolved from an early research project into the platform it is today 🎧 Watch the full episode and explore the rest of the Signals & Stories series celebrating 10 years of The Vertex Project. Learn more: https://vertex.link/10-year-anniversary/ #CyberThreatIntelligence #ThreatIntelligence #CyberSecurity #IntelligenceAnalysis #SoftwareEngineering #Synapse #VertexProject

    • Transcript
  • S1 · E8
    August 11 · 59 min

    Episode 8: What Makes Intelligence Trustworthy?

    How do you know when intelligence is actually trustworthy? In this episode of Signals & Stories, Kali is joined by Vertex co-founder visi stark and Vertex analysts, Jen Kolde (thesilence), Mary Beth Lee (savage), and Ryann Hallback (reign) to explore one of the most fundamental questions in cyber threat intelligence: What makes reporting trustworthy? The conversation starts with a seemingly simple distinction between accuracy and precision, but quickly expands into a broader discussion about analytical transparency, confidence, trust, public reporting, threat actor naming, AI-generated intelligence, and why good intelligence should help people make better decisions—not just present conclusions. Some of the topics we cover include: - Why accurate intelligence isn't always actionable - The difference between accuracy, precision, and trust - Why showing your methodology builds credibility - Confidence language and communicating uncertainty - The ongoing debate around threat actor naming conventions - Balancing timeliness with analytical rigor - Writing intelligence for different audiences - The impact of AI and LLM-generated reporting on trust Whether you're a threat intelligence analyst, SOC analyst, security leader, or simply interested in how cybersecurity reporting is produced and consumed, this episode offers practical insights into evaluating intelligence and producing reporting others can trust. Listen to the full 10-Year Anniversary Podcast Series: https://vertex.link/10-year-anniversary/ Learn more about Vertex: https://vertex.link Follow Vertex for more cyber threat intelligence research, podcasts, and educational content.

    • Transcript
  • S1 · E7
    July 28 · 35 min

    Episode 7: Hard Cyber Threat Intel Pills to Swallow with Special Guest Nicole Hoffman

    Every cyber threat intelligence analyst eventually encounters a few uncomfortable truths. In this episode of Signals & Stories, Kali sits down with Nicole Hoffman, Senior Threat Intelligence Analyst, creator of the Cognitive Stairways of Analysis framework, and author of the Threat Hunter Girl children's cybersecurity series, to discuss the ideas behind her viral "Hard Cyber Threat Intel Pills to Swallow" graphic. Together, they explore why the graphic resonated so deeply with the CTI community and unpack some of the profession's most enduring challenges: balancing threat research with enterprise intelligence, avoiding panic cycles, writing reports that actually influence decisions, and recognizing that more data doesn't always lead to better intelligence. Nicole also shares how her perspective has evolved over a decade in threat intelligence—from caring deeply about attribution to focusing on what truly matters for helping organizations assess and reduce risk. Along the way, she offers practical advice for new analysts, explains why tools can't replace analytical judgment, and discusses the communication skills that separate good intelligence from great intelligence. Topics covered: - The story behind the viral Hard Cyber Threat Intel Pills to Swallow graphic - Threat research vs. enterprise cyber threat intelligence - Why prioritization is one of the most important analyst skills - Escaping "panic cycles" during major cyber events - Why tools don't make better analysts - The role of attribution in intelligence reporting - Writing concise, actionable intelligence for decision-makers - Advice for analysts entering the CTI field 🔗 Learn more about Nicole and her work: https://threathuntergirl.com 🔗 Explore the full Signals & Stories limited series celebrating 10 years of The Vertex Project: https://vertex.link/10-year-anniversary/ Learn more about The Vertex Project and Synapse: vertex.link #CyberThreatIntelligence #CTI #ThreatIntelligence #OSINT #Attribution #CyberSecurity #ThreatResearch #SignalsAndStories #TheVertexProject #Synapse Join our community: Slack LinkedIn Twitter/X Bluesky

    • Transcript
  • S1 · E6
    July 14 · 45 min

    Episode 6: Avoiding Common Cyber Threat Intelligence Analyst Pitfalls

    Even the most experienced cyber threat intelligence (CTI) analysts aren't immune to cognitive bias. In this episode of Signals & Stories, the team explores some of the most common analytical pitfalls that can quietly influence investigations and how strong analytical tradecraft helps avoid them. The conversation covers confirmation bias, premature threat attribution, and the dangers of forcing new activity to fit existing narratives. The team also examines today's intelligence "echo chamber," where repeated reporting can amplify assumptions without adding new evidence, making validation more important than ever. Along the way, the panel discusses why healthy analytical cultures encourage constructive disagreement, how mentorship and professional communities accelerate growth, and why curiosity remains one of the most valuable skills an analyst can develop. Whether you're new to cyber threat intelligence or have spent years in the field, this episode offers practical insights for improving analytical rigor, challenging assumptions, and producing intelligence that prioritizes evidence over ego. In this episode: • Recognizing and overcoming confirmation bias • Avoiding common threat attribution mistakes • Evaluating evidence without forcing connections • Building teams that embrace constructive debate • Why mentorship and continuous learning matter in CTI Tune in for a thoughtful discussion on what separates good intelligence from great intelligence and how better analytical habits lead to better decisions. Learn more about The Vertex Project and Synapse: vertex.link #CyberThreatIntelligence #CTI #ThreatIntelligence #OSINT #Attribution #CyberSecurity #ThreatResearch #SignalsAndStories #TheVertexProject #Synapse Join our community: Slack LinkedIn Twitter/X Bluesky

    • Transcript
  • S1 · E5
    June 30 · 51 min

    Episode 5: The Evolution of Attribution in Cyber Threat Intelligence with Kamil Bojarski

    In this episode of Signals & Stories, Kali Fencl sits down with Jennifer Kolde (thesilence), Principal Intelligence Analyst at The Vertex Project, and cyber threat intelligence expert, Kamil Bojarski, to explore how attribution has evolved over the last decade. Drawing from Kamil's recent workshop at CyCon, the conversation examines how modern cyber operations increasingly rely on complex ecosystems of contractors, infrastructure providers, malware developers, and operational teams. Together, they discuss why traditional attribution models are under pressure, how regional expertise can strengthen investigations, and why collaboration across technical CTI, OSINT, and geopolitical disciplines is essential for understanding today's threat landscape. Whether you're a threat intelligence analyst, security researcher, or simply interested in how cyber operations are changing, this episode offers valuable insights into the challenges and opportunities shaping the future of intelligence analysis. In this episode: 🔹 How cyber threat intelligence has evolved over the last 10 years 🔹 Why attribution is becoming more complex 🔹 The growing role of public-private cyber ecosystems 🔹 Why language and regional expertise matter in CTI 🔹 Common pitfalls analysts face when making assumptions 🔹 Lessons learned from building hands-on intelligence workshops 🔹 The future of attribution, collaboration, and intelligence tradecraft Learn more about The Vertex Project and Synapse: vertex.link #CyberThreatIntelligence #CTI #ThreatIntelligence #OSINT #Attribution #CyberSecurity #ThreatResearch #SignalsAndStories #TheVertexProject #Synapse Join our community: Slack LinkedIn Twitter/X Bluesky

    • Transcript
  • S1 · E4
    June 16 · 34 min

    Episode 4: How Analysts Think During an Investigation

    In this episode of Signals & Stories, host Kali Fencl sits down with Vertex Project analysts Ryann "Reign" Hallback, Jen "The Silence" Kolde, and Mary Beth "Savage" Lee to explore the investigative mindset behind threat intelligence work. The conversation goes beyond indicators and malware to examine how experienced analysts approach uncertainty, evaluate evidence, and determine whether a lead is worth pursuing. The team discusses the importance of context, how to separate signal from noise, why confidence should be backed by evidence, and the cognitive biases that can derail an investigation. They also share lessons learned from years of intelligence work, including common mistakes analysts make, the challenges of proving attribution, the role of malware in investigations, and why skepticism is one of the most valuable skills an analyst can develop. Whether you're a seasoned intelligence professional or just starting your cybersecurity journey, this episode offers a candid look at the thought processes that drive effective investigations. In this episode: Where investigations really begin How analysts decide what is worth pursuing The difference between signal and noise Why context matters more than a single indicator The risks of over-relying on malware families Common mistakes analysts make How Synapse helps analysts connect disparate data sources The importance of showing your work and validating conclusions https://vertex.link/10-year-anniversary #CyberSecurity #ThreatIntelligence #CTI #CyberThreatIntel #APT1 #InformationSecurity #ThreatAnalysis #CyberPodcast #TheVertexProject Join our community: Slack LinkedIn Twitter/X Bluesky

    • Transcript
  • S1 · E3
    June 2 · 38 min

    Episode 3: On the Frontlines: A Decade of CTI with Tom Hegel

    In this episode of the Signals & Stories limited series, host Kali Fencl sits down with Tom Hegel, Distinguished Threat Researcher and Research Lead at SentinelOne, alongside Visi Stark, co-founder of The Vertex Project, for a deep dive into how cyber threat intelligence has evolved over the past decade. The conversation explores the increasing professionalization of nation-state and criminal threat actors, the blurred lines between cybercrime, espionage, and hacktivism, and the growing complexity of attribution in modern CTI. Tom shares insights from SentinelOne’s research into DPRK IT workers posing as job applicants, explaining how North Korean operators infiltrate organizations through automated hiring campaigns and why cybersecurity companies themselves have become top-tier targets. The episode also examines why cross-functional intelligence sharing matters more than ever — from recruiting and HR to sales and security operations — and how organizations can use intelligence platforms to connect signals across teams. Along the way, the discussion touches on AI’s role in threat intelligence, the challenges of scaling analysis, and why analyst creativity and iterative exploration still matter in an increasingly automated world. Topics covered include: - The evolution of cyber threat actors over the last decade - DPRK IT worker operations and fake job applicants - Threat intelligence beyond the SOC - Cross-functional collaboration in cybersecurity - Intelligence platforms and analytical workflows - AI, automation, and the future of CTI research Subscribe for more episodes from Signals & Stories as we continue exploring the past, present, and future of cyber threat intelligence. https://vertex.link/10-year-anniversary #CyberSecurity #ThreatIntelligence #CTI #CyberThreatIntel #APT1 #InformationSecurity #ThreatAnalysis #CyberPodcast #TheVertexProject Join our community: Slack LinkedIn Twitter/X Bluesky

    • Transcript
  • S1 · E2
    May 19 · 42 min

    Episode 2: “It Depends”: Attribution, Analysis, and the Evolution of Cyber Reporting

    As part of The Vertex Project’s 10-year anniversary podcast series, Kali Fencl sits down with Vertex analysts Ryann “reign” Hallback, Jennifer “thesilence” Kolde, and Mary Beth “savage” Lee for a conversation about how cyber threat intelligence has evolved over the last decade and where it’s headed next. From the lasting impact of the APT1 report to the realities of attribution, intelligence sharing, media pressure, and modern threat reporting, this episode explores how analysts balance technical rigor, operational context, and public narratives in today’s cybersecurity landscape. The discussion also dives into mentorship, representation, and the qualities that truly make a great analyst: critical thinking, curiosity, adaptability, and intellectual humility. In this episode: • How cyber reporting evolved beyond malware analysis • Why attribution is more complicated than most people realize • The tension between intelligence sharing and publicity • How geopolitics now shapes cyber operations • Why diverse perspectives improve intelligence analysis • The traits that separate strong analysts from the rest Whether you work in cyber threat intelligence, SOC operations, incident response, or are simply interested in how the industry has changed over the past decade, this conversation offers an inside look at the people and thinking behind modern cyber investigations. #CyberSecurity #ThreatIntelligence #CTI #CyberThreatIntel #APT1 #InformationSecurity #ThreatAnalysis #WomenInCyber #CyberPodcast #TheVertexProject https://vertex.link/10-year-anniversary Join our community: Slack LinkedIn Twitter/X Bluesky

    • Transcript
  • S1 · E1
    May 5 · 43 min

    Episode 1: There’s CTI and There’s Intelligence

    Cyber Threat Intelligence (CTI) has come a long way—but has its definition kept pace with its potential? In this episode, Vertex co-founders Visi Stark and John “Whippit” Rodgers reflect on a decade of CTI evolution, from manual workflows to automation-driven analysis. They explore the risks of narrowing intelligence into rigid outputs, the hidden dangers of ambiguity in modern data processing, and why precision, timing, and intentional automation are critical to delivering real impact. This conversation challenges listeners to rethink CTI not as a function, but as a discipline that drives better decisions across the business. Learn more about The Vertex Project. Celebrate our 10 Year Anniversary with us! Join our community: Slack LinkedIn Twitter/X Bluesky

    • Transcript
  • April 15 · 50 sec

    Signals & Stories: Trailer

    A lot has changed in the past 10 years, including how we collect and analyze intelligence. This is Signals and Stories, 10 years with The Vertex Project, a limited series breaking down how analysts actually investigate threats. From infrastructure pivots and identity modeling, to the hidden impact of bad data and broken assumptions, to the biases and shortcuts that quietly derail analysis. We're unpacking what it really takes to build intelligence you can trust. Featuring conversations with Vertex analysts and industry experts, this series goes beyond indicators and into the reality of modern cyber threat intelligence. 10 episodes, 10 years of lessons, 10 years with the Vertex project. vertex.link

    • Transcript
Showing 1–10 of 10 episodes