CTI Project Ecosystem
Purpose
This page connects the CTI documentation projects into one practitioner ecosystem. Each project has a different role, but they are designed to be used together.
The Ecosystem
| Project | Role | Use When |
|---|---|---|
| CTI as a Code | Lab platform + structured training assignments | You want a hands-on lab, worked case studies, Sigma rules, and methodology scaffolds |
| CTI Analyst Field Manual | General CTI tradecraft and analytic operating manual | You need evidence discipline, analytic judgment, attribution methodology, infrastructure pivoting, or CTI-to-detection reasoning |
| Customer-Driven AI CTI Project | Delivery methodology and customer engagement model | CTI work must become a managed project with phases, quality gates, and customer acceptance criteria |
| Israel Government Threat Actors CTI | Israeli sector and actor knowledge base | The question involves Israeli government, municipal, telecom, critical infrastructure, or supplier exposure |
| HexStrike AI | AI-powered offensive security automation | Adversarially validating detection coverage built in A04 or A08 against real TTPs |
How CTI as a Code Fits
CTI as a Code is the practice environment. It provides:
- The Docker Compose lab stack where you run OpenCTI, TheHive, and Elastic SIEM
- The structured training assignments (A01–A08) as worked case studies
- Distributed analytical files demonstrating the methodology in action
- Sigma rules derived from incident TTPs — ready for lab validation
The Field Manual is the reasoning standard behind everything. When CTI as a Code says "rate sources with the Admiralty Scale," "label claims," or "convert TTPs to detection logic" — the Field Manual explains the precise methodology those phrases refer to.
The Israel CTI knowledge base is the threat context for the NDSA narrative arc (A05–A08). The Iranian-nexus actor cluster, supply chain compromise patterns, and INCD regulatory context in those assignments are grounded in Israeli sector CTI documented there.
Cross-Project Workflows
Reactive Investigation → Sigma Rule → Lab Validation
- Use CTI as a Code A01 or A05 as the scenario
- Apply Field Manual — Evidence Labels and Source Reliability to each timeline event
- Convert findings to detection logic using Field Manual — CTI to Detection
- Deploy the Sigma rule to Elastic SIEM in the lab and validate with A04 or A08 emulation methodology
- Use HexStrike AI for adversarial red-team validation of coverage