Program Sikkerhetsfestivalen 2026

Threat Intelligence

Zero-Infrastructure Intelligence: Building Serverless CTI Pipelines with GitHub Actions

Tirsdag 9 · Victoria Scandic, sal 1+2

EnglishDetailed 40 min

William Thomas

William Thomas

Senior Threat Intelligence Advisor

Will Thomas is a Senior Threat Intelligence Advisor at Team Cymru with over 9 years experience in cybersecurity. He previously worked as the Head of Threat Hunting at Equinix, the world’s largest data center company, and is the co-author of the SANS FOR589 Cybercrime course and SANS Instructor. Before this, he worked for Cyjax, a CTI vendor that works with UK banks and police. He is well-known for the research on his personal blog (bushidotoken.net) and his work as the co-founder of the Curated Intel trust group. He has presented his research at various conferences including Underground Economy, DEFCON, Sleuthcon, and CyberThreatUK.

Cyber Threat Intelligence (CTI) and Threat Hunting teams often find themselves trapped between two extremes: tedious manual data collection or the high cost and complexity of enterprise SOAR platforms. But what if you could build a robust, automated pipeline without managing a single server?

In this session, we explore a lean and mean approach to CTI automation using a serverless architecture. We will dive into how to leverage GitHub Actions as a powerful orchestration engine to automate the collection, enrichment, and distribution of threat data.

Attendees will learn how to:

- Orchestrate Workflows: Use GitHub Actions to trigger Python scripts on a schedule.

- Interact with the CTI Ecosystem: Interface with popular threat intel APIs to pull indicators of compromise (IoCs) and infrastructure context.

- Data Normalization: Use Python to transform messy JSON API responses into structured, high-value datasets.

- Human-Centric Output: Generate and store CSV artifacts directly within GitHub for immediate human analysis and easy integration into existing security tools.

Whether you are a solo analyst looking to reclaim your time or a mature team seeking to decentralize your automation, this talk provides a practical blueprint for building reliable CTI pipelines using tools you likely already have but have not yet operationalized.

  1. Claude, Make Me a Security Engineer. Make No Mistakes. 1 · Frimurerlosjen, rom 1
  2. Key Challenges in API Security 1 · Frimurerlosjen, rom 2
  3. The Quantum Countdown: Procrastinate or Migrate? 10 · HeartBox ,Teatersalen
  4. Sitter vi fast i skyen? 10 · HeartBox, Byscenen
  5. Krav til cybersikkerhet i en usikker tid – NIS2, digitalsikkerhetsloven og personlig ansvar 11- Breiseth, Storlon
  6. Fra compliance til testet robusthet. Reell sikring av kontrollsystem demonstrert live 2 · Home hotel Hammer, moen nede
  7. Lås, kort, alarm og kode –Hvorfor fysiske systemer ikke er så sikre som vi tror 2 · Home hotel Hammer, moen oppe
  8. Fallgruver og suksessfaktorer i personellsikkerhetsarbeidet - hva du bør vite før du setter i gang? 3 · Hvelvet, Gullsalen
  9. Når mat blir geopolitikk: Slik sikrer vi Norges matfat sammen 4 · Kommunestyresalen, Lillehammer rådhus
  10. At the DNA of every company: Identity and Access Management 5 · Kulturhuset Banken, Expedisjon
  11. Ground Control to Major Tom: your circuit's dead! - Space Cybersecurity 5 · Kulturhuset Banken, Festsalen
  12. Forretningskontinuitet i to perspektiver - styring og beskyttelse 5 · Kulturhuset Banken, Holbøsalen
  13. Emerging Cyber Forensics Challenges: What the C‑Suite Must Know Before the Next Incident 5 · Kulturhuset Banken, Kafeen
  14. EU-regelverk er egentlig bare sunn fornuft (om du gjør det rett) 6 · Lillehammer kino, sal 2
  15. Sikkerhet som den ideelle lagspiller - Teamforskning som viser vei til sterk sikkerhetskultur 6 · Lillehammer kino, sal 4
  16. Podcast O3C 7 · Microbryggeriet
  17. Vi må ha fabrikken opp igjen innen søndag! 9 · Victoria Scandic, sal 3