AI is fundamentally transforming the field of Cyber Threat Intelligence (CTI), as highlighted by recent expert discussions and case studies. Analytical tradecraft, once rooted in manual processes and shared human standards, is now being reshaped by the integration of AI assistants and agentic systems. Researchers and analysts are increasingly relying on AI to handle data preparation, analysis, and even entire investigative workflows, which has led to significant productivity gains. However, this shift introduces new challenges regarding the reliability and transparency of AI-driven processes, especially when different teams use varying prompts and workflows. The CTI community faces the task of adapting its methodologies to ensure that trust and accountability are maintained in an era of AI-assisted research. In a notable case study, experts developed a large language model (LLM)-driven agentic system to analyze Russian internet content leaked by Ukrainian cyber activists, demonstrating the system’s ability to handle both simple data collation and complex analytical pipelines for adversary tracking. The architecture of such systems, their performance across diverse tasks, and the methods for evaluating their strengths and limitations are critical areas of focus. Communicating the judgments derived from AI-assisted analysis to peers and broader audiences is essential to preserve transparency and accountability. The integration of agentic systems into CTI workflows is not only a technical challenge but also a cultural and procedural one, requiring new standards and shared understandings. The broader cybersecurity community is also engaging in discussions about the real-world impact of AI and machine learning (ML) on threat detection and defense. Industry experts emphasize that while AI is often hyped in the media, its true value lies in practical, behind-the-scenes enhancements to security operations. AI and ML are being leveraged to improve endpoint security, automate threat detection, and streamline incident response, but their deployment must be carefully managed to avoid overreliance and ensure robust defense. The ongoing evolution of AI in cybersecurity underscores the need for continuous education, awareness, and adaptation among professionals. As AI becomes more embedded in security tools and processes, organizations must balance the benefits of automation with the imperative for human oversight and critical thinking. The future of CTI and cybersecurity defense will depend on the community’s ability to harness AI’s strengths while mitigating its risks. Collaborative efforts to develop best practices, share lessons learned, and foster transparency will be vital as the industry navigates the promises and pitfalls of AI-driven analytical tradecraft.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.