Applied AI in Cyber Threat Intelligence: Build agentic workflows to scale the intelligence lifecycle

Applied AI in Cyber Threat Intelligence: Build agentic workflows to scale the intelligence lifecycle book cover

Applied AI in Cyber Threat Intelligence: Build agentic workflows to scale the intelligence lifecycle

Author(s): Joe Fleurat (Author), Austin Nowak (Author), Dennis Chow (Author)

  • Publisher: Packt Publishing
  • Publication Date: July 29, 2026
  • Language: English
  • Print length: 628 pages
  • ISBN-10: 1806020319
  • ISBN-13: 9781806020317

Book Description

Transform cyber threat intelligence operations with multi-agent AI workflows. Automate intelligence collection, corroborate threat signals, apply structured analysis, and produce tailored, high-fidelity intelligence at scale.

Key Features

  • Build multi-agent AI pipelines to automate the cyber threat intelligence lifecycle
  • Automate threat intelligence workflows for collection and cross-source corroboration
  • Apply Structured Analytic Techniques to automated threat intelligence workflows

Book Description

Cyber threat intelligence teams face growing volumes of data, evolving adversaries, and increasing demands for timely analysis. Applied AI in Cyber Threat Intelligence is your engineering toolkit for transforming manual intelligence processes into scalable workflows using agentic AI and Python.

Designed for threat intelligence analysts, security engineers, and SOC practitioners, this book takes a practical approach to operationalizing threat intelligence with multi-agent AI systems. You will build specialized AI agents that automate the intelligence lifecycle. Using the Google Agent Development Kit (ADK) alongside Machine Learning techniques, you will build automated systems that score intelligence requirements, generate structured collection plans, and corroborate cross-source signals to determine breach fidelity.

You will also integrate Structured Analytic Techniques (SATs) into your AI pipelines to mitigate cognitive bias. You will build agents that generate visual argument maps, tailor intelligence products for different audiences, automate secure primary research, forecast threat actor behavior, and strengthen threat hunting operations. By the end of this book, you will be able to develop practical AI-powered cyber threat intelligence workflows that improve scale, consistency, and decision support.

What you will learn

  • Build multi-agent AI pipelines for CTI workflows
  • Automate intelligence requirements and collection planning
  • Corroborate cross-source threat signals to score breach fidelity
  • Scaffold Structured Analytic Techniques with AI agents
  • Generate argument maps and tailored intelligence reports
  • Automate secure primary research, forecasting, and threat hunting

Who this book is for

This book is for cyber threat intelligence analysts looking to scale their daily workflows with agentic AI and automation. Security engineers, detection engineers, and SOC practitioners seeking to automate intelligence operations will also benefit. To get the most out of the hands-on projects, you should have an intermediate understanding of cybersecurity, experience with threat intelligence methodologies, and basic Python 3.x scripting skills. No prior expertise in AI expert is required.

Table of Contents

  1. Applying the Intelligence Lifecycle to Cybersecurity
  2. Scoping Automation for Threat Intelligence
  3. Discovering Data Management Principles
  4. Grasping Machine Learning Fundamentals
  5. Diving Into Artificial Intelligence
  6. The Requirements Stage – Architecting and Prioritizing Intel Needs
  7. The Collection Stage – Automating Data Discovery and Source Mapping
  8. The Processing Stage – Validating and Corroborating Signals
  9. The Analysis Stage – Scaffolding Structured Analytic Techniques (SATs)
  10. The Production Stage – Visualizing Logic and Argument Mapping
  11. The Dissemination Stage – Tailoring Intelligence to Stakeholders
  12. The Feedback Stage – Closing the Loop with Continuous Improvement
  13. Machine Learning for the Threat Intelligence Lifecycle
  14. Automating Threat Hunting Campaigns
  15. Integrating Threat Intelligence with Detection Engineering
  16. Automating Tactical Research

Editorial Reviews

Editorial Reviews

About the Author

Joe Fleurat is the Director of Intelligence at UKG with over 20 years of experience in global intelligence and cyber defense leadership. After 12 years in the US Intelligence Community as a counterterrorism analyst and intelligence officer for the FBI and Defense Intelligence Agency, he moved into the private sector to help build and scale holistic threat intelligence teams. In his current role, Joe is responsible for UKG’s Threat Intelligence, Insider Prevent, Threat Hunting, and M&A Security Due Diligence missions. Outside of his corporate responsibilities, Joe volunteers as a task force analyst with Skull Games, providing analytic and operational support to law enforcement for human trafficking interdiction. Joe holds a Juris Doctor from Suffolk University Law School, a Certificate of Terrorism Studies from the University of St. Andrews in Scotland and is a Certified Cyber Counterintelligence Analyst.

Austin Nowak is a Detection Engineer & Data Scientist at UKG and holds dual bachelor’s in Math & Physics and a master’s in Computer Science, focusing on Machine Learning & Data Science. With over 15 years of teaching STEM subjects and more than 6 years in the security industry, Austin has worked in both startup and enterprise environments where he led multiple security data science projects, handled data strategy and management, managed technology platforms, and established security compliance programs.

Dennis Chow is an experienced security engineer and manager who has led global security teams in Fortune 500 industries with over 14 years of experience. Dennis started from an IT and security analyst background, working upwards to engineering, architecture, and consultancy in blue- and red-team-focused roles. In 2015, the US Department of Health and Human Services awarded Dennis a grant to standardize cyber threat intelligence sharing for the entire US healthcare vertical. In that time, Dennis achieved over 30 certifications and became GIAC Security Expert #288. During his time at Amazon Web Services (AWS), Dennis worked as a professional services consultant, focusing on security transformation for detection-focused automation.

View on Amazon

未经允许不得转载:Wow! eBook » Applied AI in Cyber Threat Intelligence: Build agentic workflows to scale the intelligence lifecycle