
Loading summary
A
An analyst can log off at the end of the day and then, oh, if there's new data coming in overnight or whatever, like the agent can handle all of that intake, model it and then even just do initial pivots. So like for example, one of the earliest things we might do with a case is like, okay, we have a new indicator come in, we ingest it into our database, let's see if it's related to anything else that we already know. Like that's just a really quick check and that's something an AI can do. And then it would be awesome if we can log in the next day and we have our own little triage package of hey, hey. A thousand events have been ingested, modeled, found XYZ leads. Go look for these or go go dig on these a little bit more.
B
Welcome to another episode of Mandiant's Defenders Advantage podcast. I'm your host, Luke McNamara. Today I have the privilege of welcoming back Jake Nicastro who leads the Frontline Intelligence Operations Team's AI function. He's another member of gtig. So Jake, great to have you back here again talking about AI.
A
Yeah, thanks Luke. This is at least now my, my newest seat. I think last time I was on here I was still on the, the Frontline Intel Operations Team, but in a slightly different role. So, so excited to come of talk about this new little. I think it would be useful before
B
we get into the meat and potatoes of what we're going to talk about today to kind of set in context what your team within the Google Threat Intelligence Group, what it does, what it supports, and then also maybe some of your work on that. And then we'll dive into kind of specifically how you've been carving out this role in looking at how to apply AI to the work of cti.
A
Yeah, for sure. So the Frontline Intel Operations Team, it's actually kind of our new name. For a long time we were going by the name Advanced Practices. That name goes back into the FireEye days. But the mission has mostly changed or sorry, mostly stayed the same. The core mission at least, and that's our role is sitting right alongside Mandate Consulting, particularly the Incident Response Group. But I mean we help Strategic and Red Team where we can as well, but and then also the Mandiant Threat Defense, formerly the Managed Defense Team. And we sit alongside during their day to day operations, their engagements, their investigations and we kind of act as this two way street where we both take in the data they're identifying from alerts and their investigations and then like describing all of that in our intel database to help understand what threat actors are doing on endpoints, but then simultaneously taking the data we do have already and giving it back to them to drive their investigations to look, have like very targeted IOCs to look for and also just drive the response actions based on what group we suspect we have at hand. So it's a cool little bridge between the incident response and managed managed detection and response worlds and the intel world.
B
Yeah. And I think, you know, hopefully people get a sense from that. But your team is some of the most important connective tissue between what is now our Google Threat intelligence group and what is mainnet consulting, who are on the front lines. You're sort of the frontline piece of that from an intel perspective. The work that you guys do is very obviously operationally driven and focused. So you're very responsive to what is going on. I imagine at times that means you are dealing with incidents where you have a lot of data, you've got to comb through and analyze and process and triage. You have situations where obviously you are building, you're putting the puzzle pieces together when it comes to the threat activity, what happened, what went down in a specific breach. And so speed becomes very important. The ability to process a lot of data becomes very important in that sort of supporting role. And as you're building out that intel picture.
A
Yeah, for, for sure dealing with, I mean, for every investigation there's potentially thousands of artifacts to go through and yeah, we're taking a look at all of that and then just multiply that by the amount of investigations we do. And then on the managed managed detection and response side, it's a little, it's structured a little differently, but there's still thousands and thousands of alerts and events to go through on that side as well. So I think operating at a Google scale has never been or has always been familiar to us for that matter. But largely, yeah, some of it has been manual in the past. And I think this new world of AI and everything is super helpful for us to take advantage of and be able to go through this data at a, like you just said, faster speed and get to answers more quickly and things like that.
B
So let's jump into some of the ways you've been approaching this because I think obviously there's been a long standing discussion now for the last several years of applying AI to the work of cyber defense and cybersecurity. And I think that sort of recognition that leaning into leveraging those tools is becoming more important as we see the Adoption on the adversary side and their ability to increase speed, especially kind of being a powerful forcing function. I know you've been thinking about this for a while because you had one of the presentations, one of the use cases when we did the hackathon, the AI hackathon a couple years ago. But I think it'd be useful to have some examples of how you've been thinking maybe broadly about this and then getting to specifics, because there's obviously so many different ways you can leverage AI in the general security context and then even into CTI as a specific sub discipline within that. There's a lot of different ways, everything from malware analysis to some of these other areas where you can leverage AI. So maybe to kind of start with your journey and like the things that you've been playing around with and experimenting and that you found to be useful in the application of AI to cti.
A
Yeah. So a little background. So I kind of started thinking about this sort of thing very. Just coincidentally, shortly before LLMs kind of took off. I was always interested in AI and then had started to just take some courses online and learning about the math behind it and just kind of pushing in that data science direction in general. And then LLMs happened. So that was kind of a wonderful coincidence. And as that happened immediately, we started to think about like, okay, what are the things we do and where could this possibly help us out? And the overall theme from the get go, and this is, I think rewind, like two years ago. this point, the overall theme for the team has been very much doubling down on like the human machine teaming element. We've never been going at it at the sense of like, oh, we can finally just offload all of these tasks and like, try to automate ourselves out of a job. We've really, really embraced. Recognizing that there are amazing strengths that the technology has, but then there's also still amazing strengths that the human brain has that a computer just can't replicate. But like I said, vice versa as well. So the two words I've kind of been pushing the team to rally around is like augmenting and empowering the team. So really, again, just embracing what we excel at, that analytical mindset, just that intuition and just context that a computer just won't have. But really leaning on the speed that computers and AI has when it comes to trudging through a lot of data, like super quickly or finding needles in haystacks potentially quicker than we could and surfacing those leads for us. So that's kind of resulted in A variety of different applications over the last couple of years. And of course kind of started out with, and I would say even still, still to this day, there's still value in it of just doing like little quick prompt engineering exercises of like, hey, can we have this decode this little script we found instead of having to wait for, wait for a reverse engineer if we're not capable of doing it ourselves, if it's like just super, super complicated and we don't have the time for it either, or just doing it ourselves. And then it's still going to take time, but now I can push a button and just have an answer immediately, which is pretty cool. So like those little things started to emerge very quickly and just getting those quick answers or even being able to provide data or be able to support requests for consulting and their clients that we just wouldn't have been able to before. For example, like there was an incident, this was a couple years ago at this point, they wanted to do just a really wide hunt for a bunch of IP addresses and gathering all of the IP addresses that we would have needed to search for. Or the different like net blocks that we would have had to search for would have been a very manual kind of painstaking task that we just didn't have the time for. But I was able to get AI to kind of do some research, put together a script and get me like the blocks that we could search for in a matter of minutes, which was pretty awesome. Like that just straight up would not have been a thing we would have been able to do purely for just time. And like there are some at that point we had to like prioritize, like, okay, is this a really important ask? Maybe in the moment, no, but now we can deliver on it, which is really cool. So. So we're able to deliver more just from little things like that. As the years have gone by. That's now turned into, especially with the advent of this agentic era, the embrace of like agent skills to streamline workflows, but then also engineering like agents to do some of these workflows. But we've especially focused on the chore work we got to do, and I use that term kind of ingest because it's the painstaking, meticulous labeling work of all of that data that we just talked about. So the thousands and thousands and thousands of events that add up to millions and millions of events, normally we would go through and manually label these things or we'd have some semi automated way to do it, but they're kind of Brittle because it's relying on regular expressions and logs and things change over time and we have to test and tune those. And that's a whole effort in and of itself. We've been focusing on that work because that ends up chewing up a lot of our time, but it's still valuable. But like, hey, if we can offload this task to a computer where it's like, this is, it's just, it's manual labor, it's painstaking, it's not like brain enriching. It doesn't really require a super analytical thought about it. It's just go find a label that applies to this thing. So like, that was a really early on task that we identified. Like, hey, this, this could potentially be done at scale by AI. So that was, that was that example that you mentioned about our early hackathon. And we've just kind of doubled down on those sorts of things. So identifying these, these little use cases that are like this is just an unenriching, from a mental perspective, activity we have to do that provides data enrichment. But now we can just have a machine do it and just check its work and it gets done significantly faster as well. So that's kind of the direction we're heading.
B
So today, how often are you finding that you are like the example you gave earlier of like, okay, let's see if we can use AI to attack this specific problem and then kind of approach it from. You're driving the investigation utilizing AI of a particular aspect of the larger investigation. How much of that is how you're using AI today versus wrangling agents, where you have agents that have been set up, that have been trained on specific tasks. The fact that we can have things like mitre, ATT and CK and the attack lifecycle does point to how systematic a lot of these intrusions are and how you can document these things. Which in turn means that we can have agents that can look for or hunt for, or identify or work different pieces of this process because they often follow certain patterns. So, you know, given that that kind of helps, you know, do you spend. Is this. The future seems to be moving more and more to the actual management of the agents that have some level of familiarity with these tasks that you've trained, you've developed skills for. Is that becoming more commonplace? Or are you also still saying, okay, I'm going to try to, you know, use an LLM interface to research some particular component or see if I can build this out real quick? I don't know if that makes sense, but this sort of way that you're approaching that now. Which of those sort of use cases are you finding more of?
A
Yeah, I'd say at the current point in time, it's still very much analytical. I would say going forward from at least our perspective, we want, we want to maintain that just to begin with, but the management of the agents will, I think, come more into play. At least where we're at right now. We have bits and pieces, but we still want to push to a much more like, streamlined, more orchestrated thing that's, if anything, ironically, more hands off for our analysts. Because we envision this world where like, hey, an analyst can log off at the end of the day and then, oh, if there's new data coming in overnight or whatever, like, the agent can handle all of that intake, model it, and then even just do initial pivots. So like, for example, one of the earliest things we might do with a case is like, okay, we have a new indicator come in. Let's just, we ingest it into our database. Let's see if it's related to anything else that we already know. Like, that's just a really quick check and that's something an AI can do. And then like, it would be awesome if we can log in the next day and we have our own little triage package of, hey, 1000 events have been ingested, modeled, found XYZ leads, go look for the. Or go, go dig on these a little bit more. And then it comes down to some manual stuff. But then also we've like enabled deeper or quicker manual analysis via other agents, if that makes sense. So like something that might have taken several database queries and thinking through the steps before in the past now can be reduced to like, hey, just here's a question, here's a thing I'm trying to research. Have the agent go off and go retrieve the data for you. And it can do multiple queries, correlate a couple of different things. And so you're able to kind of make more complex calls in a single, like, back and forth than you would with just a simple, like database query. So there is a little bit of a different approach to the analytical part, but I think in a better way where you can just execute these different steps in your analytical process a little faster and potentially do more complicated, like single steps, which is kind of cool, but then also in the background, yeah, like probably managing and wrangling the agents, doing all that ingest, et cetera, and making sure nothing breaks there. Perhaps we might like shift to more of like, okay, maybe we have dedicated functionality to that, while our analysts can stick with actually just using the results and using the analytical tools remains to be seen, but I think it'll be a little bit of both. We definitely don't want to lose the analysis part and don't want to shift entirely to just wrangling agents.
B
Yeah. And when you started to, now that you've been, you know, kind of building out the use cases and the actual infrastructure of how you're using it within your own team, you've been doing a lot more to kind of take those lessons learned to the larger Intel Org and you've been doing, you know, brown bag meetings and interacting with different teams. And there's a lot of different, obviously even just within cti, a lot of different use cases, whether it's for more attribution focused work or report writing or malware analysis. What have been some of the things that you've seen that other teams are doing here that you would put in there? Like this is, you know, much more transformative to what they're doing because they're now able to take people off of doing more repetitive tasks and focus on higher level analytic functions. What are some of the things you've seen that you think are pretty promising in the cti, the AI application to CTI space?
A
Yeah. So a large question, I think, just because like you said, there are so many facets of cti, like from report writing to more technical analysis across the board. I feel like there's different things off the top of my head. This is kind of more CTI adjacent, but I know it also overlaps with like what the Flare team is doing. So I know people on my team detections team that's on within GTIG and then Flare as well, have all kind of dabbled in a lot of the like malware analysis pieces. And whether that be just triaging stuff or just full on agentic reverse engineering, like using MCP servers to interact with like Ghidra or IDA Pro. A lot of that stuff I think is like, I haven't messed with it too in depth myself, but the demonstrations I've seen from Flare and my teammates, I think that's super cool. I think even for themselves. It's like, I think it was a quick reality check of like, oh wow, this actually can kind of do my job. But where the promise is is again, I think balancing the implementation. And so that's like, hey, we can use this automated stuff for like the routine commodity things that we see all the time instead of hammering reverse Engineers with tickets about the same old info stealer or something that we see all the time. And that's a like consistent workflow that they can go through and pull apart like toss that off to an agent and then for the really cool spicy espionage stuff we come across, let's get human eyes on that and then they can use their tools to assist themselves with going through it. And maybe it'll take significantly less time to go through it than it would have previously. But so I think similar to what we're trying to do within Frontline intel is just being able to free people up to focus more on the real juicy stuff. And the same goes for I think for like on the reporting side it's like hey these little any like roll ups of OSINT or news analysis or like these regular reports for industry trends, things like that that I feel like can probably be a little more pawned off to AI. But these maybe larger custom pieces or these really in depth looks into a particular threat actor are really where the humans can come into play and craft that analysis that an AI just wouldn't be able to deliver the same effect for. But again they could use the same analytical tools to support all that. So, so it's really that again that human machine teaming I think is where the success lies and then to bring it back even to frontline Intel. A great example of similar to the flare thing is we on the managed defense side envision a world where like hey similarly like we're seeing all these, these threat actors that are deploying like click fix and all these, especially all these malvertising related actors. The initial flow is relatively the same so it like just doesn't make sense. And it's not like again super enriching for our analysts to go investigate the same alert over and over and over again. It's still valuable for us to track that to hey see if anything changes over time or track who they're targeting etc. But where it's that initial flow is relatively the same. Like hey maybe we can hit a certain threshold. Have we seen this actor do XYZ the same thing so many times? Let's make this a workflow for an agent. Upon that off and now our analysts can focus on like net new novel things just focus their time better. So I think across the board it's a lot of those. Anything that's like repeatable and small I feel like can be start to be pawned off to agents while the humans can focus on these more technical deep dive stuff.
B
Well I think Also something you touched on earlier, too, that's a powerful force multiplier in the utilization of agents is the fact that they don't sleep and that they can be running around the clock. And, you know, we're a big organization. You know, the people listening to this, you know, might be part of organizations that have round the sun socks and security teams. But even still, I mean, there's a limit on the resources that you have, how many people are able to work something. And, you know, even, like, in any individual investigation, I imagine there's only so much time you can kind of spend chasing down multiple, like, loose ends. And I think we've all had that experience of, like, working something where, like, you. You pivot out your Maltego chart is like. Until you're just mapping the Internet at this point or, you know, you're like, spidering a lot, in a way. But some of those, you know, sometimes you. You make a breakthrough and those following those threads become very, very useful, but you don't always have the time to do that. And I think having an agent that can perform some of those functions, especially kind of early on in the. Kind of mapping out the scope of something and chasing down some of those leads, I think that's an incredibly powerful capability that I think we're starting to see unleashed in the CTI world.
A
Yeah, for sure. I think just as an example of that, there was months ago in. In one of our. Our agents that we have to interact with our. Our database. I just stumbled upon this. I was looking at. I'm gonna be honest. I don't remember what group it was, but it was something to do with Cobalt Strike Beacon, if I recall. Pivoting around different indicators, the agent found a, like, an overlap with an investigation from the ManU threat defense from two or three years ago that there wasn't an actual, like, technical indicator overlap. We're like, hey, this IOC was seen at this victim within the same week as these other reports that we saw at this victim. And these reports were attributed to. So to whatever group it was. So, like, this IOC might also be related to this group. And it's like, that's just something. Again, like that. Because of prioritization at the time, obviously we're focused on like, hey, where are the actual back doors then? Rather than this IP address that just made a connection and just in the pile of everything else that just didn't get prioritized, looked at. But the AI made that, like, temporal overlap conclusion and raise that to the surface to be like, okay, cool, like that's something that, like an example of we're expanding the threat picture and it's. And we didn't have that information before just because, again, just due to time, resources and not being able to pull every single thread all the way, but now we can maybe start to pull some of those other threads and paint a bigger threat picture.
B
Have you found certain use cases or seen different intel teams struggle with certain use cases where maybe the AI tooling is not quite there to do certain things or even certain. I mean, I know, I think everyone's had this experience here where, you know, you use a certain AI tool or model and it like works for something or gets you to like the 80% solution, but then like, you can't create slides easily. Right. And so you gotta like figure out a workaround for that. Have you seen things like that where, you know, maybe the implementation or the models are not quite there to do certain parts of the CTI workflow?
A
Yeah, that's. That's a tough one. Right. And I don't want to pretend I have the golden answer. A lot of those sorts of issues kind of come down to what's known as the harness. And just in case anyone listening isn't aware of what that term means, it's kind of a new hot term, but it's effectively, there's the LLM, but then you have the skills, the prompts, the MCP servers, whatever else, everything that's built around the LLM, and that really gives it its way of operating and the skills or the abilities rather it has, etc. All the knowledge and out of the box. A lot of the time is where I think these things fall short. But if you build the right harness, you can really kind of start to achieve things that maybe you didn't think was possible. Understanding that resources and time are a thing, as we just talked about, a lot of it comes down to experimentation and really just trying to give it the ability to do a certain thing. But the other piece too, on the flip side is, is it a task that is even appropriate for an LLM? Because I think that's the other piece to be aware of. And that's another thing we've tried to maintain through all this time, is still asking the question, is this a problem that an LLM can or should even solve? There's still plenty of cases where there probably is a simpler solution, in which case maybe you could have an LLM, help you build that solution. For example, if it's an automation thing, like you could have the LLM build that script for you or at least help iterate over it and improve on it and things like that. So I think sometimes it's perspective, sometimes it is. I think a lot of times rather it is the harness. But also just things are changing so fast, like rewind a year. And the things we're doing with LLMs now either wanted or could sort of do a year ago, let alone two years ago, that we totally can do now with just model improvements, harness improvements and things like that. So it's definitely out there. People are struggling for sure, I think especially with time or the lack thereof to be able to iterate and experiment on these things. But I feel like a lot is possible, maybe more so than some people might think, but it just requires a lot of extra touch. And that's kind of the unfortunate thing.
B
And that is something I would definitely encourage people if they've, you know, tried to implement something at one point and it wasn't quite there yet, either from a model standpoint or even setting up the harness, they're kind of skill set or know how on that things are improving at such a rate where I think I really would encourage people to kind of revisit those components of like, well, maybe that project could be done now that 6 months ago kind of stalled out in this particular way. So I guess to that point, one thing I'm also curious about is you obviously have no shortage of examples of threat activity that you guys are looking at where you can think through, all right, how would we throw AI at this problem? But are there areas where kind of outside, even security work that you see that you get ideas from of like, oh, we could apply this to what we're doing here because it seems like there's certain things that you start to see as like a best part practice in one area. I think we were talking about this earlier, but just even like the concept of like a judge agent or mediator or evaluator agent that you have maybe agent one or agent two doing some sort of task and then you have another agent that's evaluating that work before it's going to the human, you could obviously use that in a number of different contexts, but I can imagine that would be useful in security. Yeah. So just kind of curious, like where, where do you get some of the ideas around like, oh, we should implement that or we should look at how this could apply to the security use case.
A
Touching on, on like the, the judge example. I think that's a good one because so a lot of these use cases regarding LLMs are very, very centered around software engineering.
B
Right?
A
Of course, when it comes to like software engineering, like project management and everything, like you want, you want to be able to poke holes in a plan and make sure like it's a robust plan and you're not overlooking anything. And that's where we've seen examples of those judges come in. Like it's an LLM reviewing an LLM generated plan and that LLM's job is to just be adversarial and poke holes in it. We've seen, I mean colleagues of ours have built systems where they're basically implementing like structured analytic techniques to call back to what's it Richard is that.
B
And you said it correctly too. Everyone forgets that it's Richard's plural. Hoyer. Yes.
A
I will never forget that. I remember seeing that asset. I'm like, yep, okay, Richard Sawyer, call back to that. People have implemented like that sort of system with several agents kind of coming up with a hypothesis, poking holes in your hypothesis and things like that. So I think that's, I think like textbook exhibit A of that example being applied to Threat intel as far as other like, other examples. So personally a lot of my mindset I don't often necessarily even look for like transferable things. It's more like my, I kind of reflect on my background because so before joining Frontline Intel I was an incident response consultant. So like digital forensics and stuff has been my, my bread and butter since college. So I kind of have always looked at every step of that workflow and thought like, okay, genuinely I just look at it from like, what part of this is annoying to do or what part of this. I mean especially in pre LLM like by a machine learning algorithm potentially. So I've looked at like other early examples of that and the, the event labeling application that we talked about earlier. That thought for me predates LLMs. When I was a consultant, I was dreaming of man. I see all these classification tasks as they're known in the machine learning world being done on all sorts of other data and I'm like, why can't we do that on the forensic data we're collecting now we're able to do that, which is really cool. And ironically actually that system is a great example of. It's not entirely LLM based, but there are a couple key steps in there that LLMs have made it like super, super effective that before with just a machine learning model probably wouldn't have worked as well. But so I kind of just pull on other examples that I know of just from being in and around data science and try to think about the data we have and be like, okay, is this technique something we could apply to our data? And then also. But then aligning it with the things we do that I'm like, okay, we, for example, our job and the word we've used for years has been clustering threat data. Like clustering is an action that machines have been very good at from a mathematical standpoint. So in the age of LLMs now, like a big challenge for us previously has been a lot of the data we deal with is very unstructured. It's totally like the formats vary, it's not very consistent. And so like going through and cleaning all of that is just not a feasible task. But now we can do all this like semantic understanding with LLMs and embeddings and that enables us to do these classification tasks that we just couldn't do before. So I think just looking at also just historical applications and not forgetting about those simple routes and seeing like, hey, is there something with that that we can do that we couldn't do before that LLMs now can augment? So like even just, I think to bring that all back to like an overall point is picking apart problems and being like, okay, what parts of these were difficult to do before with traditional programming or traditional methods that an LLM can now enable us to do? So just getting in the weeds of our processes and everything. I know that doesn't directly answer the like, outside influences, but honestly I think reflecting on it, most of my influences just come from, hey, what are general data science things that I think we could do that we couldn't do before? And just trying to apply those.
B
Well, you know, I'll build off of that, I guess into my last question here. You know, as we look towards the future, obviously there's a lot of discussion right now about how AI will change the work of intel analysis generally, but then also the discipline of cti. And it is interesting, I think, you know, again, you've highlighted a number of different times that the work of employing and bringing in an AI agent to do a certain task is not replacing the human, but it's allowing human analysts to focus on some of those more high level components and things that are frankly more interesting. But it is interesting to think about how this is going to change, for example, for people entering the field. I remember as an early threat analyst I got to work in the same room as malware analysts and so I was constantly bothering them and pestering them with questions all the time of like, why does this do this? Why does this show up in this particular piece of malware? A lot of that sort of querying now could be easily done with an AI agent that has a corpus or body of knowledge of historical events and malware and things like that. And so having something you can kind of query in real time that's an expert in some of these specific domains is going to make, I think some of the early kind of getting up to speed on problems much easier. Or you have an analyst that wants to transition. Maybe they're covering information operations and now they're focused on Russian cybercrime. Right. Being able to get up to speed much, much quicker obviously is important. So I think again, it's a very open ended question, but I'm curious your thoughts on sort of how this will change what it is that we do and how we approach what we do.
A
Yeah, so before I dive in on that, I do want to hit just what you just talked about before the question, and that's regarding, like getting spun up on, on things. I think our team is a prime example of a place where, I mean, sure, we're already in this world, et cetera, but whereas many intel analysts might be on a team dedicated to North Korea or a particular crime threat or what have you, because of our nature of just supporting incident response, we don't get a choice of what threat actors we're dealing with. It's whatever lands on our desk that day. So we kind of have to be a jack of all trades or at least flexible to understand various threat actors.
B
And I think that's also true of a lot of our customers as well. Right. They're not. You don't get to choose who's targeting you, so you're going to have to investigate and chase those leads down, whatever they appear as.
A
Exactly. So I think having the ability to what used to be like, hey, let me go from our perspective, run a bunch of queries in our database, go read a bunch, dig up a bunch of reports that people have written and try to manually digest all of this information to very quickly get spun up on a threat. I can now talk to our agent that talks to all of our database and get a nice synthesis of this threat and at least at a high level, who they are, what they're doing, how they're doing it, and then I can maybe dive in from there, even from not even a transition standpoint, but like, hey, we're just living this every day, like having that ability to at least quickly get Spun up on something is huge. But side note, I also believe that yeah, if you use it right, get using these tools as like an educational piece I think is massive. I've been working on my master's degree and straight up I've been using Cloud because I get a premium subscription through school, through the school for it and it's like integrated with our courses and whatnot. So I've been using it in its learning mode and like genuinely it's like the tutor I wish I always had. It's like it's able to explain things and answer questions I have that are very specific and follow up questions especially in, in an online classroom maybe the professor's not always available and so but I have an answer at my fingertips or at least can have something that asks me questions that get me to the answer very effectively. And I think as a learning tool it's just yeah, super incredible. To answer your question, where we're going with this, I think, I think this actually beautifully kind of brings it back to my first point of I think focusing on again that that human machine teaming piece is really the direction we're going. And I, I pulled this excerpt from a white paper that Google actually just recently published this with this 5 day intensive vibe coding course that they put on Kaggle which is like data science community development platform thing. This particular one is the new software development, like software development life cycle with Vibe coding. And at the very last paragraph I took this quote out but I'm going to replace software engineering with intel and it still stands true. The teams that thrive will be those that embrace AI as a powerful tool while maintaining the analytical discipline that has always been the foundation of threat intelligence. They'll be the ones who understand the future of threat intelligence isn't about choosing between human expertise and AI capability. It's about designing systems where both contribute their unique strengths. So that's the direction for again the original quote was software engineering. That's the direction for software engineering. I think that's the same direction for threat intelligence. I think it's really, really leaning on again human expertise, human intuition, the context that we all have, the experiences that we have as individuals, but using the machines to really go through data in a way we haven't been able to before and get to answers at a speed we haven't been able to do before. But also making sure we're I guess checking each other's work because there's plenty of times I've had the AI show that I was wrong for something but then also vice versa, because nobody or nothing is infallible. But having this complimentary world, I think, is the world we're going to.
B
A great point to end it on. Jake Castro, thank you again, as always, for your time and I think your insights into this. And it'll be good to have you back on at some point in the future, because I'm sure, as always, this is going to progress so quickly. And so the use cases and how we're adopting and leveraging this and our intel work is also going to be accelerating. So thank you, though. I think this is a powerful kind of window into what's going on and specifically your team and what you've been building in this space. So thank you for your time today.
A
Yeah. Just the tip of the iceberg. Thanks for having me, Luke.
B
Take care.
The Defender's Advantage Podcast
Episode: Human-Machine Teaming: Applying AI to Frontline Threat Intelligence Workflows
Host: Luke McNamara (Google Threat Intelligence Group)
Guest: Jake Nicastro (Frontline Intelligence Operations Team, AI Lead)
Date: July 13, 2026
In this episode, host Luke McNamara engages with Jake Nicastro—the AI lead for Google Threat Intelligence Group's (GTIG) Frontline Intelligence Operations Team—to delve into the practical application of AI and human-machine teaming in cybersecurity threat intelligence (CTI). The duo explores the evolution of workflows, how AI augments rather than replaces analysts, and real examples from the frontlines of large-scale incident response.
“Our role is sitting right alongside Mandiant Consulting, particularly the Incident Response group...while also taking the data we do have already and giving it back to them to drive their investigations.” — Jake Nicastro [01:50]
"We've really, really embraced...the human brain has that a computer just can't replicate. But the technology, vice versa as well. The words I've pushed the team to rally around is like augmenting and empowering the team." — Jake Nicastro [06:54]
“Gathering all of the IP addresses…would have been a very manual, painstaking task...But I was able to get AI to kind of do some research, put together a script and get me...blocks that we could search for in a matter of minutes.” — Jake Nicastro [09:07]
“...An analyst can log off at the end of the day and then...the agent can handle all of that intake, model it, and even do initial pivots.” — Jake Nicastro [13:19]
"Anything that’s repeatable and small…can start to be pawned off to agents while the humans can focus on these more technical, deep dive stuff." — Jake Nicastro [19:43]
“The AI made that, like, temporal overlap conclusion and raised that to the surface...expanding the threat picture…and we didn’t have that information before just because, again, just due to time, resources and not being able to pull every single thread.” — Jake Nicastro [22:13]
“Is it a task that is even appropriate for an LLM?...There are plenty of cases where there probably is a simpler solution, in which case maybe you could have an LLM help you build that solution.” — Jake Nicastro [24:25]
“Having that ability to…quickly get spun up on something is huge. If you use it right, these tools as an educational piece…is massive.” — Jake Nicastro [34:29]
“The teams that thrive will be those that embrace AI as a powerful tool while maintaining the analytical discipline…The future of threat intelligence isn’t about choosing between human expertise and AI capability. It’s about designing systems where both contribute their unique strengths.” — Jake Nicastro [36:05]
On Human-Machine Teaming:
“We've really, really embraced...the human brain has that a computer just can't replicate. But the technology, vice versa as well.” — Jake Nicastro [06:54]
On Speed and Coverage:
“An analyst can log off at the end of the day and then...the agent can handle all of that intake, model it, and even just do initial pivots.” — Jake Nicastro [13:19]
On Transforming Workflows:
“Free people up to focus more on the real juicy stuff…Anything that's repeatable and small I feel like can be start to be pawned off to agents while the humans can focus on these more technical, deep dive stuff.” — Jake Nicastro [19:34 & 19:43]
On the Power of AI as a Tutor:
“Using these tools as like an educational piece I think is massive...It’s like the tutor I wish I always had.” — Jake Nicastro [34:56]
Summing Up the Future:
“It’s about designing systems where both contribute their unique strengths. So that's the direction…for threat intelligence.” — Jake Nicastro [36:08]