The Cyber Threat Intelligence Special Interest Group (CTI SIG) of FIRST brings together a global community of practitioners, researchers, and experts who collaborate to advance the field of cyber threat intelligence. As a Special Interest Group, it serves as a forum for sharing expertise, developing methodologies, and addressing common challenges within the incident response and intelligence community.
This page highlights the individuals who contribute to the CTI SIG's body of knowledge. Their work spans a range of outputs, including educational curriculum, blog articles, and presentations delivered through webinars and events. These contributions reflect the SIG's ongoing efforts to explore emerging topics, refine analytical approaches, and promote practical guidance for CTI practitioners.
By sharing insights, research, and real-world experience, these authors play a key role in shaping the CTI SIG's resources and supporting the broader cybersecurity community. This page recognizes their contributions and provides visibility into the people behind the content that drives the SIG's work forward.

4D5A Security
CEO
Ken Dunham is a pioneering cybersecurity leader with a career rooted in innovation, education, and intelligence. Beginning his professional journey as a middle school math and science teacher, he simultaneously built a successful consulting practice and discovered a new class of computer viruses—precursors to today’s macro file infections. His work led to the creation of the world’s top-downloaded Macintosh security software and the most visited antivirus website of its time. By 1995, Ken had developed more than 30 custom programs, including projects for Polytechnic University, and was the top antivirus expert on About.com, reaching over 350,000 readers weekly, coupled with a leading published book (published via McGraw-Hill).
In 1997, Ken advanced into aerospace innovation, developing training programs for elite pilots and contributing to classified U2 and Warthog programs and innovating the Predator drone program. Driven by family values, he transitioned into full-time cybersecurity leadership, where he became one of the most quoted experts globally and an ISSA Distinguished Fellow—an honor reserved for the top 1% worldwide. Over the past 25 years, Ken has been at the forefront of cyber threat intelligence, directly supporting U.S. federal agencies, international law enforcement, and multi-governmental security initiatives with 15 years TS-SCI (NSA/DHS – redacted) experience performing counterterrorism, counter nation-state, and counter e-crime operations against most advanced persistent threat (APT) groups and leading global threats.
As a global CISO-level strategist and innovator, he spearheaded the creation of Optiv’s Threat DNA™ platform and built high-performing consulting practices with multimillion-dollar success. Ken is also the author of a multitude of successful books including his most recent, Cyber CISO Marksmanship (CRC Press, 2024). Today, Ken continues to blend visionary leadership, technical depth, and a passion for mentorship to advance the future of cybersecurity and threat defense.
ken@4D5ASecurity.com 208-283-7010
Ken Dunham

Hydrolix
Director Security Engineering
Purdue University
Post-graduate Researche
Dr. Tzvetanov has served for the past six years as a graduate researcher at Purdue University, where his work concentrates on Homeland Security, Cyber Threat Intelligence, and Influence Operations within the cyber domain. In parallel, he is an instructor of record for graduate coursework in Cybersecurity and Homeland Security. In parallel, for the past three years, Dr. Tzvetanov has served as Director of Security Engineering at Hydrolix. He previously held the position of Security Architect at Fastly, a global content delivery network, where he directed programs in secrets management, threat intelligence, and the investigation of distributed denial-of-service attacks and adversaries, and where he provided technical expertise to multiple law enforcement efforts, including expert witness services and the Mirai botnet takedown. His prior industry experience includes senior technical roles at Cisco Systems and A10 Networks, with responsibilities encompassing threat research and information sharing, DDoS mitigation, product security, and secure software development practices. Earlier in his career, he served at Yahoo! as a member of the Paranoids, the company's security organization, contributing to the design and protection of its production edge infrastructure. He began his professional career at Google as a Site Reliability Engineer supporting two mission-critical systems: the global advertising database, which processed the company's advertising revenue, and the authentication infrastructure underpinning all Google services.Dr. Tzvetanov is an active contributor to the global security research and incident response communities. He has served on multiple Special Interest Groups within the Forum of Incident Response and Security Teams (FIRST), participated in the Honeynet Project, and organized the BayThreat security conference. He led the Radio Communications department at DefCon and served on the program committees of ShmooCon, NANOG, BayThreat, and several FIRST annual conferences, and the Underground Economy. Dr. Tzvetanov holds a Doctor of Philosophy and a Master of Science in Technology, both with a concentration in Homeland Security; a Master of Science in Digital Forensics and Investigations; and a Bachelor of Science in Electrical Engineering with a specialization in Communications Equipment Engineering.
Krassimir Tzvetanov

Threat Analysis in the CERT Directorate, part of the Software Engineering Institute (SEI), managed by Carnegie Mellon University (CMU)
Senior Member of the Technical Staff
Laurie is actively coordinating and publishing vulnerability notes as part of CERT Coordination Center. She participates in several FIRST SIGs and is currently an Editor for the revision of Internation Standards, ISO 29147, Vulnerability Disclosure, and ISO 30111, Vulnerability Handling.
Prior to joining the SEI 13 years ago, Laurie was at the Department of Energy (DOE) as a member of the Intelligence and Counterintelligence Team for 12 years, working as a Technical Analyst. Prior to DOE, Laurie worked for 10 years at Argonne National Laboratory as the Associate Computer Protection Program Manager, leading Argonne's incident response team.
Laurie A Tyzenhaus

Trend Micro
Threat Researcher
Vladimir Kropotov is an Advisor and principal researcher with the TrendAI. Active for over 20 years in information security projects and research, he previously built and led incident response teams at Fortune 500 companies. He holds a master's degree in applied mathematics and information security. He also participates in various projects for leading financial, industrial, and telecom companies. His main interests lie in network traffic analysis, incident response, and botnet and cybercrime investigations. Vladimir was a speaker at a variety of cyber security events, including BHEU, BHAsia, HITB, hack.lu, FIRST and others.
Vladimir Kropotov

Trend Micro
Threat Researcher
Fyodor Yarochkin is a Senior Researcher, Forward-Looking Threat Research Senior at Trend Micro with a Ph.D. from EE, National Taiwan University. An early Snort Developer and Open Source Evangelist as well as a Programmer, his professional experience includes several years as a threat investigator and over eight years as an Information Security Analyst.
Fyodor Yarochkin

Shreshta IT Technologies Pvt. Ltd.
Swapneel Patnekar is Chief Security Researcher and CEO of Shreshta IT Technologies, a DNS security, threat intelligence and cybercrime investigation company in India. He has 15 years of experience in information security and has presented at cybersecurity and cybercrime conferences across 22 countries. He trains law enforcement agencies on countering cybercrime, most recently delivering training to Karnataka Police, Kerala Police and Belagavi Police. Swapneel is the Liaison Member(India) at FIRST (Forum of Incident Response and Security Teams) and previously co-chaired the DNS Abuse Special Interest Group. He has served on the board of the India Internet Engineering Society.
He volunteers as a FIRST trainer and APNIC Community Trainer, delivering technical workshops across multiple countries.
Swapneel Patnekar