[Speakers]
Adversary Village at
DEF CON 34

William Thomas

Senior Threat Intelligence Advisor

Will Thomas is a Senior Threat Intelligence Advisor at Team Cymru with over 9 years experience in cybersecurity. He previously worked as the Head of Threat Hunting at Equinix, the world’s largest data center company, and is the co-author of the SANS FOR589 Cybercrime course and SANS Instructor. Before this, he worked for Cyjax, a CTI vendor that works with UK banks and police. He is well-known for the research on his personal blog (bushidotoken.net) and his work as the co-founder of the Curated Intel trust group. He has presented his research at various conferences including Underground Economy, DEFCON, Sleuthcon, and CyberThreatUK.

The APT OSINT Challenge

11:00-12:55 PDT | Friday, Aug 7th 2026 | Adversary Village Workshop Stage, Las Vegas Convention Center
Hands-on Workshop

Abstract

This hands-on workshop places participants in the role of a threat intelligence analyst, tasked with attributing real-world cyber intrusions to Advanced Persistent Threat (APT) groups using only open-source intelligence. Working from publicly available breach reports drawn from my own Breach-Report-Collection repository, attendees will practise pivoting through OSINT sources, from MITRE ATT&CK and vendor threat blogs to DOJ indictments and IoC databases, to answer the fundamental questions of threat attribution: Who did this? Who sent them? And are they still out there? No prior threat intelligence experience is required; curiosity is the only entry ticket.

Workshop outline

Part 1 - Orientation & Mission Brief


Participants are introduced to the workshop's core objective: to take a real public breach report, apply OSINT tradecraft, and attribute the intrusion to a named APT actor with as much specificity as possible. The facilitator explains the challenge structure and the worksheet each team will use throughout the session.


Part 2 - The 10 Targeting Questions
Every breach report is analysed against a standardised set of ten questions that drive the investigation:


Can you identify the APT group responsible?
Can you identify the country behind the APT?
Can you identify the government agency sponsoring the APT?
Can you identify any front companies linked to the APT?
Can you find names of specific individuals associated with the group?
Can you build a Diamond Model of the intrusion? (Adversary / Victim / Capability / Infrastructure)
Is the group still active, and when was their last reported activity?
(Plus additional source and pivot questions)


Part 3 - Rules of Engagement
The facilitator walks through the workshop format:
- Each round opens with a QR code linking to a real breach report
Participants skim the report for IoCs, victim profile, dates, TTPs, and vendor naming conventions
- Teams pivot through OSINT sources to answer the 10 questions, citing every source
- The group reconvenes to compare findings and discuss attribution reasoning before the next report is introduced

Agency.


Join Adversary Village Discord Server.

Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!