Director of Threat Analysis at Fable Security
Stryker has spent over ten years translating technical research and qualitative intelligence into the "so what?" and "what now?" materials that keep more people safe and secure. She previously produced threat intelligence across financial services, cybersecurity vendors, and now early-stage startups - including work at Ivanti, Blackpoint Cyber, and GEICO - and currently leads threat analysis at Fable Security. You can often find her playing tabletop card games after her talks at SecTor, DEF CON, and Bsides conferences around the United States. Stryker lives in Maryland, growing parsley for butterflies and algae for shrimp.
13:00-14:55 PDT | Friday, Aug 7th 2026 | Adversary Village Hands-on Activity Area, Las Vegas Convention Center Hands-on Activity
Several years ago, before I even knew what a "threat intelligence platform" was, I accidentally cobbled a TIP together with nothing but ChatGPT, Feedly, Airtable, Zapier, and duct tape vibes.
That original setup was robust enough that I still use parts of it today!
In this interactive, hands-on session, I'll walk you through how to hack together your first minimum viable TIP using whatever no- or low-cost tools you've got on hand.
Bring an Internet-capable laptop, and we'll:
* Pin down why you need a TIP: are you drowning in docs and articles, still cutting and pasting indicators, or just trying to appease the corporate gods who think it's a good idea?
* Seed your intel feeds with customized primary sources while discovering hidden RSS feeds together.
* Perfect your OSINT summary prompt engineering for the Gen AI bot of your choice, with a few experiments showing common failure points.
You’ll walk away with war stories, a functional schematic to assemble your own TIP, and a community ready to help you iterate... no six-figure surcharge required.
# INTRO / “WHAT IS A TIP”? (15 min)
* Intro of agenda and who everyone is, what they do, why they want to try to make a TIP (so we know who to go to for help / ideas + I know where to focus)
* Defining a threat intelligence platform
* Lists can be nested each element of TIP (= what is Threat / Intelligence / Platform in our context?)
* Process = Source -> Feed -> Dashboard Triage -> Automation / Metadata -> Database -> Distribution
* If remember nothing else:
* 1. Information != Intelligence
* 2. TIP != Information Hoard
* 3. Tools you already have and know > Niche “just for CTI” tools
## EXERCISE No1: CHOOSE YOUR TIP (15 min)
* Establishing minimum viable product parameters by asking who needs this and why?
* Story: my first TIP “failed” because I focused on what *I* thought was interesting, not what my *recipients* actually cared about.
* Exercise: Fill in the blank TIP objective / share goals, focus together, get specific
## SELECT YOUR SOURCES (10 min)
* Differentiating between secondary & primary sources
* How to use secondary sources to find relevant primary sources / research over time for faster time to notice
* Bias examples of sources (vendor, researcher, journalist, dark web) + importance of triangulation / corroboration, confidence levels)
* Discussion of whether dark web feeds are required for APT / direct threat research and for what purpose
* Seed source list
## EXERCISE No2: FIND YOUR FEEDS + bio break (20 min)
* Creating / finding hidden RSS feeds by:
* Google Alerts
* View Page Source + Line Wrap + Ctrl-F [Keywords]
* Main Blog or Site + [Standard Extensions]
* Robots.txt or sitemap.xml
* I shut up and literally let people try to find RSS feeds, periodically showing where there’s a good example or trouble spot someone has.
* Possible feed discovery / creation tools & browser extensions
## READ YOUR NEWS (5 min)
* Walkthrough of my feed dashboard and how I process information
* Feed collection types to “boards” for automation hook integration
* Possible feed collection / dashboard tools
## AUTOMATE YOUR INFORMATION (5 min)
* Basic information metadata to scrape
* Title, date, source, description, URL, data sensitivity labels, etc.
* HTML metadata / schema.org intro
* Walkthrough of my automations (basic & advanced)
* Making a database record
* What automation can do (pretty quickly) and what it could do (over time)
* Possible automation tools
## STORE YOUR DATA (5 min)
* Walkthrough of my database
* Example record w/Gen AI summary
* Possible database options
* Write three possible custom metadata fields, based on schema.org and / or own TIP purpose, that can be used for automation
## SHARE YOUR FINDINGS (10 min)
* Walkthrough of my distribution methods (Medium + Mastodon + Email)
* Possible distribution channels
* Write down two possible distribution channels with template message / info formats, using identified previous metadata fields
## EXERCISE No3: GENERATE YOUR AI (20 min)
* What Gen AI CANNOT and often can do automatically
* Example of error
* NEVER PUT INTERNAL DATA INTO CHATBOTS. EVER.
* Walkthrough of my Gen AI bot “Bethany” / Extreme TLDR prompt
* Exercise: Hallucination Station
* “List 20 aliases for threat group Scattered Spider” to see it come up with realistic alternative labels mixed with real ones (or refuses to find any!)
* Optional variants
* Lower chatbot's “temperature” to 0.1 for the fewest standard deviations, rerun prompt, & compare outputs.
* Raise chatbot’s “temperature” to 0.9 for highest standard deviations, rerun prompt, & compare
* Exercise: Summarization & the “Xerox Problem”
* Repeat the same summarization prompt / input five times with new URLs, and see how the output has deviated from Source 1 to Source 5.
* Demonstrates how automated AI agent issues turn into huge problems later in the process without a human in the loop (HitL)
## RESOURCES AND QUESTIONS + slip (remaining time)
Agency.
Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!