THREAT FIELD NOTESINTELLIGENCE FOR DEFENDERS
Back to home

Practitioners who sharpen the field

Researchers, presenters, writers, and defenders whose work is consistently useful.

A personal, evolving list with no ranking implied.

Vulnerability researchResearcher

Will Dormann

A longtime software-vulnerability analyst known for practical testing, careful disclosure analysis, and explaining real exploitation conditions.

VulnerabilitiesFuzzingResearch
Brief overview

Dormann worked at CERT/CC from 2004 and focused on browser technologies, ActiveX, fuzzing, and software behaviors that create security exposure. His public analysis is useful because it often distinguishes a theoretical flaw from the specific configurations and user actions required for exploitation. Follow his work for reproducible testing ideas and pragmatic risk context.

View official profile
Detection engineeringPractitioner

Florian Roth

A threat researcher and detection engineer associated with Sigma, THOR, YARA-based scanning, and widely used open-source defensive tooling.

SigmaYARADetection
Brief overview

Roth’s work connects threat research with detection content that security teams can operationalize. His projects include Sigma and multiple tools for compromise assessment and indicator-based scanning. Follow him for new detection rules, coverage discussions, incident-response observations, and practical ways to turn research into hunts.

Read Florian Roth’s research
Technical leadershipAuthor

Johanna Rothman

An author and consultant who writes about product development, management, organizational systems, risk, and decision-making under uncertainty.

LeadershipSystemsRisk
Brief overview

Rothman is not primarily a security researcher; her value for defenders is in the operating system around technical work. She explores how leaders structure teams, expose risk, manage portfolios, forecast work, and create conditions for better decisions. Her writing is especially useful for security leaders trying to communicate uncertainty and improve delivery without adding process for its own sake.

Visit official website
Critical infrastructureAdvisor

Alex Campbell

A cybersecurity adviser whose work focuses on digital trust, resilience, and cyber risk in energy and critical-infrastructure organizations.

Critical infrastructureEnergyRisk
Brief overview

Campbell has advised government and industry on protecting critical national infrastructure and on large technology-led transformation programs. His perspective is useful for connecting technical controls with operational resilience, investment decisions, and the physical consequences of cyber incidents. Follow his work for sector-level thinking on energy, utilities, and infrastructure risk.

View professional profile
Incident responsePractitioner

Lesley Carhart

An industrial-control-system incident responder, investigator, educator, and frequent source of practical guidance for defenders.

IROT/ICSForensics
Brief overview

Carhart leads and supports digital-forensics and incident-response work in operational technology and industrial environments. Their writing and teaching cover ransomware readiness, investigation under operational constraints, career development, and the differences between enterprise IT and systems that control physical processes. Follow for field-tested response lessons and clear explanations of complex incidents.

View official profile
Threat intelligenceAnalyst

Katie Nickels

A threat-intelligence leader and educator with experience in network defense, incident response, intelligence analysis, and MITRE ATT&CK.

CTIMITRE ATT&CKEducation
Brief overview

Nickels has led intelligence and research teams, previously worked on the MITRE ATT&CK team, and teaches SANS FOR578 Cyber Threat Intelligence. Her work is valuable for analysts learning to scope requirements, communicate confidence, map adversary behavior, and produce intelligence that supports an actual decision. Follow for rigorous tradecraft and accessible analyst education.

View faculty profile