Intelligence Tradecraft - Sharpen your analytic edge

Freddy Murre

Join us on “Intelligence Tradecraft”, where we explore the adoption of intelligence tradecraft in the private sector. Hosted by an intelligence and cyber threat intelligence professional, each episode features interviews with top researchers, authors, and practitioners offering practical insights for experts and beginners alike. Whether you’re a seasoned intelligence analyst or just starting your journey, this videocast provides the tools, techniques, and inspiration to elevate your craft and sharpen your analytic advantage. Join our community and master intelligence tradecraft.

  1. Sep 16

    Breaking In, Proving Value, and Staying Ahead in CTI - Interview with Rebecca Ford S3E3

    In this episode of Intelligence Tradecraft, host Freddy Murre sits down with Rebecca Ford, a cyber threat intelligence analyst who started out on the government side with Army Cyber and DISA, focused heavily on North Korea and the Asia-Pacific region. From there, she moved into the private sector, where she's spent the better part of a decade helping grow a CTI function from an early-stage team into something far more mature. Rebecca traces her path into the field: an overheard conversation about true-crime shows that led an Army analyst to recruit her, on-the-job training in an era before cyber threat intelligence even had a name, and the 2014 Sony hack as the moment the discipline truly landed on the map. She and Freddy explore what separates useful intelligence from what she calls being reduced to "news reporters with a microphone." The difference lies in handing stakeholders a raw threat feed versus giving them analysis that actually drives a decision. Rebecca shares her working definition of intelligence, built around an adversary's intent, opportunity, and capability. They also get into the two very different audiences an analyst serves, senior leadership and network defenders, and why treating report counts as a success metric misses the point entirely. The conversation covers building real relationships with stakeholders, the argument for "fusion centers" that merge cyber, physical, travel, and financial-crime intelligence, and the considerable value of community and mentorship in a field where, as Rebecca puts it, your next opportunity usually comes from someone who already knows you. A large part of the discussion is about AI: where it genuinely speeds up research and helps an analyst get started, why Rebecca still verifies everything by hand before it goes out, and why she believes human judgment should stay in charge of the final call. Rebecca ends with a reminder that showing up and investing in the community, whether at conferences, in focus groups, or at vendor events, is part of the job for anyone hoping to build a career in the field. RESOURCES Sony Hack - https://www.bbc.com/news/world-asia-30573040 Gert Jan's Metrics - https://github.com/gertjanbruggink/metrics SANS CTI Summit 2026 Visual Summary - https://www.sans.org/blog/visual-summary-sans-cti-summit-2026 Rebecca's LinkedIn - https://www.linkedin.com/in/rebeccaford/ Freddy's Intelligence Architecture Mind Map - https://github.com/Errum/IntelArchitectureMap Reuters IKEA bets on remote interior design as AI changes sales strategy - https://www.reuters.com/technology/ikea-bets-remote-interior-design-ai-changes-sales-strategy-2023-06-13/ CHAPTERS 00:00 Welcome & Rebecca's Background 00:57 Breaking Into Cyber Threat Intel 02:58 Learning Cyber Intel From Scratch 04:30 The Sony Hack Turning Point 06:53 From Army Cyber to DISA 09:32 Adjusting to the Private Sector 12:29 Defining Intelligence and Stakeholders 15:16 Proving Value and Building Community 23:14 Good Intelligence vs. Bad Intelligence 26:20 Mentorship and Learning From Mistakes 34:01 Team Diversity and Fusion Centers 40:25 Misconceptions and Measuring Impact 47:00 Communicating With Stakeholders 55:07 Where AI Fits in Intel 1:13:15 Mentors, Advice & Closing Thoughts

    Breaking In, Proving Value, and Staying Ahead in CTI - Interview with Rebecca Ford S3E3
  2. Sep 2

    Intelligence Work Demands Honesty About Uncertainty - Interview with Rebekah Brown (S3E2)

    In this episode of Intelligence Tradecraft, host Freddy Murre talks with Rebekah Brown, senior researcher at the University of Toronto's Citizen Lab, about what it actually takes to do intelligence work well, in government and in the private sector. Rebekah's background spans the field: she started as a Marine Corps cryptologic linguist and NSA analyst, later led threat intelligence at Nike, and worked the vendor side at Rapid7. Today, she co-authors the SANS FOR578 course and has co-written an incident response book with Scott Roberts.   The conversation traces how a clerical error sent her through Mandarin Chinese training instead of Korean, why private-sector CTI teams so often import government habits that don't fit the business they're protecting, and why translating between technical teams and leadership is often the real job description.  They spend real time on definitions: what separates intelligence from reporting, what makes intelligence good or bad, and why so much of what gets labeled cyber threat intelligence in the private sector is really just collected information without analysis behind it.  Rebekah and Freddy also trade stories about the growing pains of building a threat intelligence function inside a business that doesn't think in nation-state terms, and what it actually takes to make expensive training change how a team works day to day.  When it comes to AI, Rebekah explains where she believes LLMs can genuinely support brainstorming, coding, and research tasks, and where she draws a hard line at analysis itself. The two also debate how AI might reshape the size and shape of intelligence teams in the years ahead.  It's a grounded, experience-driven conversation for analysts, team leads, and anyone trying to prove the value of intelligence inside their organization.  RECOURCES  The Marine Corps Logo - https://www.war.gov/Multimedia/Photos/igphoto/2001789719/ Defense Language Institute  Foreign Language Center - https://www.dliflc.edu/  University of Toronto Citizen Lab - https://citizenlab.ca/  The Cuckoo's Egg - https://www.amazon.com/Cuckoos-Egg-Tracking-Computer-Espionage/dp/1668048167/  Ghost Net Report - https://citizenlab.ca/research/tracking-ghostnet-investigating-a-cyber-espionage-network/  Intelligence-Driven Incident Response - https://www.amazon.com/Intelligence-Driven-Incident-Response-Outwitting-Adversary/dp/109812068X/  Scott Roberts LinkedIn - https://www.linkedin.com/in/scottroberts/  SANS FOR578 - https://www.sans.org/cyber-security-courses/cyber-threat-intelligence  Rob M Lee LinkedIn - https://www.linkedin.com/in/robmichaellee/ CHAPTERS 00:00 Welcome and introductions  0:37 High school to the Marines  1:22 Becoming a Marine linguist  3:56 A lucky mix-up at NSA  5:45 Early training and mentors  9:44 What is intelligence?  14:17 Good intelligence versus bad  16:32 Leading and teaching Marines  20:37 Injury ends a military career  25:12 Standing up Nike's threat intel  31:28 Rapid7 and the CTI boom  38:19 Bridging techies and leadership  45:01 Writing the book and course  58:15 Measuring intelligence's real value  1:02:27 Where AI fits in intel

    Intelligence Work Demands Honesty About Uncertainty - Interview with Rebekah Brown (S3E2)
  3. Aug 19

    Good Intelligence vs Noise and the Skills AI Can't Replace - Interview with Josh D. MacLellan (S3E1)

    Staff Threat Intelligence Advisor Josh Darby MacLellan at Feedly kicks off season three by unpacking his path into CTI, what separates intelligence that gets used from intelligence that gets ignored, and why core skills like stakeholder communication may outlast technical specialties as AI reshapes the field. Josh started his career with childhood dreams of becoming a criminal lawyer, shifted through academic study of international relations and security, and unfolded into more than a decade of private-sector threat intelligence work across Canada, the US, and multiple specialties within CTI. Josh is blunt about where the field falls short. Good intelligence is connected to a decision and a decision-maker, versus reports written for other analysts that never get read. Josh and Freddy discuss team structure, and why CTI teams that skew small and heavily technical tend to miss the core skills of stakeholder conversation that keep a function relevant when budgets tighten. Josh argues communication is a trainable skill, the same way he trained himself to become a clearer public speaker despite two speech impediments and years of mumbling through bombed public talks.As for AI, Josh draws a clear line between what he'll delegate and what he won't. He uses LLMs for collection support, editing, and even as a stand-in second analyst to catch his own blind spots, but he won't hand over the analysis stage. Trusting an unreviewed AI process, he argues, is a bit like citing a source you've never actually read. Freddy pushes back with his own testing of LLMs on structured analytic techniques, and the two get into what's actually lost when a black box quietly decides what information matters.RESOURCES NATO Intelligence Cycle - https://ac.nato.int/resources/uploads/2284/picture2-intel-8Wgsa2.png Freddy's Intelligence Architecture Mind Map - https://github.com/Errum/IntelArchitectureMap/files/14615837/240315.-.Intelligence.Architecture.v0.7.42.pdf Gert Jan's Measuring value of CTI - https://github.com/gertjanbruggink/metrics Feedly - https://feedly.com/ Intel471's CU-GIRH - https://github.com/intel471/CU-GIR Sherman Chu's Tyranny of Current Intelligence - https://www.youtube.com/watch?v=IETRHdMejaw Sherman's slides - https://www.sans.org/presentations/were-in-now-now-the-tyranny-of-current-intelligence-and-how-to-manage-it Intel Tradecraft Courses and Trainings - https://inteltradecraft.com/sat-certifications IRM Workshop - https://www.intel471.com/lp/building-an-intel-workshop SANS FOR578 CTI - https://www.sans.org/cyber-security-courses/cyber-threat-intelligence Josh Darby's SANS presentation "Can We Forecast Our Own Fate" - https://www.youtube.com/watch?v=B9TkeUbD1Mk Josh's slide deck - https://www.sans.org/presentations/can-we-forecast-our-own-fate-mapping-the-future-of-the-cti-industry-with-sats Feedly CTI Essentials - https://feedly.com/ti-essentials Webinar: What CTI practitioners recommend you focus on in 2026 - https://feedly.com/ti-essentials/posts/what-cti-practitioners-recommend-you-focus-on-in-2026 Freddy and Josh Think smarter, not harder: Making SATs work in CTI - https://feedly.com/ti-essentials/posts/think-smarter-not-harder-making-sats-work-in-cti Feedly AI - https://feedly.com/ai MLitt in Terrorism Studies - https://www.st-andrews.ac.uk/subjects/international-relations/terrorism-mlitt/ CHAPTERS 0:00 Intro and Welcome 1:01 Josh's Path Into CTI 4:04 CTI Maturity Across Countries 8:08 Pivot to Protective Intelligence 12:12 Defining Intelligence and CTI 13:13 Good vs Bad Intelligence 16:16 The Intelligence Cycle 23:23 Engaging Stakeholders Directly 26:26 Core Skills and Job Security 33:33 Training and Certifications 40:40 Building Well-Rounded Teams 43:43 Mentoring and Giving Back 49:49 AI's Role in the Cycle 58:58 How Josh Uses AI 1:05:05 People Who Shaped His Career

    Good Intelligence vs Noise and the Skills AI Can't Replace - Interview with Josh D. MacLellan (S3E1)
  4. Jul 1

    The librarian who founded modern OSINT: Sources, tradecraft & AI - Interview with Arno Reuser (S2E8)

    If you've ever read a text or sat in a briefing and quietly wondered what actually separates this "intelligence" from someone's hot take on LinkedIn, a journalist with a deadline, an analyst with a search bar, or an AI, this episode is for you. The host, Freddy Murre, sits down with Arno Reuser, the man who founded the Dutch Defence Intelligence Service's open-source intelligence (OSINT) capability in the early 1990s, before most of Europe had a word for it. What follows is less an interview than a working argument about how OSINT should actually be done, and where the field has gone soft. Arno doesn't mince words. He'll tell you the "information explosion" everyone complains about is just proof you skipped your stakeholder and requirement analysis. That most of what gets sold as OSINT is the word "OSINT" stapled to “everything”, such as tools. That he has, by deliberate choice, never written an analytical judgment in his life, and why that line between collection and analysis matters more than people think. For anyone who's argued about what counts as OSINT versus PAI (Publicly Available Information), or where collection ends and all-source begins, this is the debate you want to engage with. Along the way: the librarian's discipline, he says, underpins all good intelligence work, the collection plan he calls "worth gold," the classroom trick thousands of students have failed, and a run of war stories from his teachings, such as a prison break by email to a deepfake that fooled cyber experts who personally know him. The back half takes on two problems every practitioner is living with right now. How do you put a value on intelligence when the same report is priceless to one decision-maker and useless to the next? And what is AI actually good for? Arno uses LLMs daily and is genuinely amazed by them, but only for things he can verify. He and Freddy get specific on hallucinations, sycophancy, model collapse, and the difference between a real summary and a machine that just shortens the text and deletes the one sentence that mattered. RESOURCES Maersk Website - https://investor.maersk.com/news-releases/news-release-details/cyber-attack-update Dutch Police Data Breach - https://www.politie.nl/nieuws/2024/oktober/2/update-over-datalek-politie.html When does something go from a Google answer to Intelligence - https://www.linkedin.com/posts/fmurre_in-your-opinion-when-does-something-go-from-activity-7181221399561203712-mV-m/ LexisNexis Library - https://www.lexisnexis.com/en-us/products/digital-library.page Vague questions in OSINT - https://opensourceintelligence.biz/vague-osint-questions/ Structured Analytic Techniques (SAT) Training - https://inteltradecraft.com/sat-certifications Pherson Structured Analytic Techniques for Intelligence Analysis - https://www.amazon.com/Structured-Analytic-Techniques-Intelligence-Analysis/dp/150636893X/ Routledge Handbook of Terrorism Research - https://www.routledge.com/The-Routledge-Handbook-of-Terrorism-Research/Schmid/p/book/9780415520997 AI Model Collapse - https://scholar.google.com/scholar?hl=en&as_sdt=0%2C5&q=AI+model+collapse&btnG= CHAPTERS 00:00 From literature searcher to founding military OSINT 04:00 Becoming a librarian: the Kampen archive moment 08:00 Where OSINT stops and intelligence begins 11:00 Why "cyber" keeps getting OSINT wrong 15:00 What actually makes something "intelligence"? 24:00 The information explosion myth 32:00 The classroom trick: think before you type 36:00 The collection plan that's "worth gold" 42:00 The human factor cyber keeps ignoring 45:00 War stories: validation and getting fooled 51:00 Learning the craft: sources, sources, sources 55:00 Customers ask for what they think you can do 01:08:00 Can you measure the value of intelligence? 01:11:00 AI and LLMs: amazed but skeptical 01:32:00 Deepfakes, the NATO photo & "how likely is it?"

    The librarian who founded modern OSINT: Sources, tradecraft & AI - Interview with Arno Reuser (S2E8)
  5. Jun 17

    From Dutch Military Intelligence to Private Sector Cyber Threat Intelligence (CTI) - Interview w/Martijn (S2E7)

    SUMMARY Former military intelligence analyst turned consultancy director Martijn Docters van Leeuwen joins Freddy Murre to unpack what cyber threat intelligence really is, and why so many teams "talk the talk" without "walking the walk", i.e. doing the work. Martijn Docters van Leeuwen has done the whole journey, infantry, military intelligence, stopping ATM skimming and gas attacks in the Netherlands, to building a bank's first CTI team, and now being a cybersecurity consultant. So when he talks about CTI being a tradecraft and not a report that magically lands in your inbox, he's not theorizing. He's been the only analyst in the room wearing all seven hats, the guy getting asked "why does this cost so much?", the one trying to prove value in the six quiet months when nothing's on fire. We get into the stuff analysts actually argue about: why most teams are great at talking the talk and bad at doing it, the trap of living in your own little football field while the business has no idea what you do, how people game their own metrics to manufacture a crisis, and where AI genuinely helps versus where it's just a confident liar with no fingers. Threat vs. risk, mirror imaging, incident-driven vs. intel-driven, and the brutal truth that training does nothing if you walk out the door and never apply it. If you do this work, or you're trying to convince someone it's worth doing, pour a coffee and settle in. RESOURCES Structured Analytic Techniques (SAT) Certification Training by Intel Tradecraft and Pherson - https://inteltradecraft.com/sat-certifications Intelligence Mind Map - https://github.com/Errum/IntelArchitectureMap When does something go from a Google answer to Intelligence - https://www.linkedin.com/posts/fmurre_in-your-opinion-when-does-something-go-from-activity-7181221399561203712-mV-m/ Mitre Att@ck - https://attack.mitre.org/resources/attack-data-and-tools/ Mark Arena - CTI: Comparing the incident-centric and actor-centric approaches - https://medium.com/@markarenaau/cyber-threat-intelligence-comparing-the-incident-centric-and-actor-centric-approaches-f20cfba2dea2 ASML The world's supplier to the semiconductor industry - https://www.asml.com/en SANS FOR578 CTI - https://www.sans.org/cyber-security-courses/cyber-threat-intelligence TIBER European Central Bank - https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html Freddy's resources on SANS - https://www.sans.org/profiles/freddy-murstad#resources The intelligence cycle - https://github.com/Errum/IntelArchitectureMap Basic cyber-hygiene guidance from CISA - https://www.cisa.gov/topics/cybersecurity-best-practices NSM ICT Security Principles - https://nsm.no/advice-and-guidance/publications/nsm-ict-security-principles SANS FOR578 CTI - https://www.sans.org/cyber-security-courses/cyber-threat-intelligence Obsidian (note-linking/mind-mapping for research) - https://obsidian.md/ CTI-CMM - https://cti-cmm.org/ CREST - https://www.crest-approved.org/ Google Notebook LM - https://notebooklm.google/ Intelligence minor, Leiden University - https://www.universiteitleiden.nl/en/education/minors/minor/fgga-minor-intelligence-studies Heuer & Pherson Structured Analytic Techniques for Intelligence Analysis - https://www.amazon.com/Structured-Analytic-Techniques-Intelligence-Analysis/dp/150636893X/ CHAPTERS 00:00 Introduction & from military intel to CTI 08:30 Building a bank's first CTI team 15:00 What is intelligence — and what is CTI? 26:00 Talking the talk vs. doing the work 35:00 Incident-driven vs. intelligence-driven CTI 46:00 Tradecraft, methodology & pricing CTI work 53:00 Collection, analysis & tailoring reports 01:04:00 Mirror imaging & understanding threat actors 01:08:00 Measuring the value of a CTI program 01:19:00 Threat vs. risk: capability, intent & opportunity 01:24:00 Training intel skills & making it stick 01:36:00 Can AI help us do intelligence better?

    From Dutch Military Intelligence to Private Sector Cyber Threat Intelligence (CTI) - Interview w/Martijn (S2E7)
  6. Jun 4

    Lessons from a Former US Navy Collector - Joe Slowik on intelligence tradecraft and AI in CTI (S02E06)

    In this episode of Intelligence Tradecraft, host Freddy Murre sits down with Joe Slowik, a threat intelligence veteran whose career spans the US Navy, Los Alamos National Laboratory, MITRE, and the vendor world (Dragos, DomainTools, Gigamon, Huntress, and now DataMinr). In the conversation, Joe makes the case that intelligence is fundamentally about decision support, not raw data feeds or research written for other analysts. He and Freddy dig into what separates good reporting from bad, why stakeholder alignment and rigor (ICD 203, clear separation of fact vs. assessment) matter, and when a "flash report" beats a polished deep-dive. They also tackle the attribution debate — how-centric vs. who-centric attribution, the mess of overlapping naming schemas (APT10 vs. APT31, the Visma case), and why "trust us, we're Microsoft" isn't tradecraft. Joe explains the thinking behind his Applied Threat Intelligence training and the gap it was built to fill. The back half turns to AI: where LLMs genuinely help (research, scripting), where they're dangerous (cognitive offloading, model decay, drying up the junior-to-senior pipeline), who's accountable for AI-generated output, and how threat actors are using these tools, from better phishing to voice cloning. Joe's bottom line for newcomers: critical thinking, communication, and curiosity come before any prompt-engineering skill. Resources Joe Slowik's LinkedIn - https://www.linkedin.com/in/joe-slowik/ Joe Slowik's Blog and Courses - https://paralus.co/ Freddy' Structured Analytic Techniques (SAT) Training - https://inteltradecraft.com/sat-certifications Los Alamos National Laboratory - https://www.lanl.gov/ NIST Cyber Threat Intelligence definition - https://csrc.nist.gov/glossary/term/cyber_threat_intelligence CTI used in books (Google Search) - https://books.google.com APT 1 Report - https://services.google.com/fh/files/misc/mandiant-apt1-report.pdf Moonligh Maze on Wikipedia - https://en.wikipedia.org/wiki/Moonlight_Maze SANS FOR578 CTI - https://www.sans.org/cyber-security-courses/cyber-threat-intelligence ICD 203 - https://www.dni.gov/files/documents/ICD/ICD-203.pdf MLitt in Terrorism and Political Violence - https://cstpv.wp.st-andrews.ac.uk/masters-in-terrorism-and-political-violence/ Routledge Handbook of Terrorism Research - https://www.routledge.com/The-Routledge-Handbook-of-Terrorism-Research/Schmid/p/book/9780415520997 APT Groups and Operations Rosetta Stone (not mine) - https://docs.google.com/spreadsheets/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/edit?pli=1&gid=1864660085#gid=1864660085 Structured Analytic Techniques (SAT) Training - https://inteltradecraft.com/sat-certifications Tradecraft Primer: SATs - https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf An Illustrated Book of Bad Arguments - https://bookofbadarguments.com/ Weston's Rulebook for Arguments - https://hackettpublishing.com/philosophy/logic-mathematics/critical-thinking/a-rulebook-for-arguments-group Joe's Critique of Practical Threat Intelligence - https://pylos.co/2026/05/03/a-brief-critique-of-practical-threat-intelligence/ Cognitive Offloading - https://sistemasi.ftik.unisi.ac.id/index.php/stmsi/article/view/6180 OpenAI Research - https://openai.com/research/index/ Chapters 00:00 Intro and Joe's career path 06:11 The Evolution of Cyber Threat Intelligence and intelligence 15:05 Rigor, reporting, & attribution 29:50 The Relevance of Intelligence in Incident Response and CTI 47:09 Building & measuring a CTI function 01:00:13 Training teams (and why it doesn't stick) 01:07:37 Integrating LLMs in Intelligence Work 01:19:50 Skills for the Future of CTI

    Lessons from a Former US Navy Collector - Joe Slowik on intelligence tradecraft and AI in CTI (S02E06)
  7. Apr 22

    From US Army Intelligence to Private Sector Intelligence Advisor - Interview with Jeremy Levin (S02E05)

    In this interview, Jeremy Levin shares his journey into US Army intelligence and subsequent move into private sector intelligence. Jeremy has extensive experience in intelligence analysis, training, and management, emphasizing the importance of adaptable skills, continuous learning, and effective team utilization in the field. Jeremy Levin accidentally entered military intelligence in the mid-90s by joining the U.S. Army intelligence. He served nearly 30 years in various government intelligence roles and as a contractor. After moving into the private sector he founded Questimation (“Better decisions discovered”) to teach thinking, analytic methods, and explore more objective calibration of qualitative probabilities. This in-depth interview explores the challenges and opportunities in intelligence analysis, focusing on metrics, training, AI integration, and the mindset needed for future success. Discover how to measure impact, foster analyst development, and adapt to technological advances. Resources and references mentioned Questimation - https://www.questimation.com/ Julia Galef - The Scout Mindset - https://www.amazon.com/Scout-Mindset-Perils-Defensive-Thinking/dp/0735217556 IARPA Reason Project for AI in Analysis - https://www.iarpa.gov/research-programs/reason US Intelligence Standards ICD 203 - https://www.dni.gov/files/documents/ICD/ICD-203.pdf UK Intelligence Standards - https://www.gov.uk/government/publications/phia-common-analytical-standards/phia-common-analytical-standards New Zealand Code of Ethics - https://nziip.org.nz/code-of-ethics/ Chapters 00:00 Meet Jeremy Levin 07:52 Contractor Life and 9/11 22:43 Going Independent and forming Questimation 30:30 What Counts as Intelligence 35:22 Analyst Tasks and Management 41:53 Value of Warning and Training 57:51 Metrics Drive Output 01:02:20 Measuring Intelligence Value 01:12:00 Defining Success Metrics 01:22:18 Analytic Standards Matter 01:25:48 AI and Tradecraft Future 01:48:10 Mentors and Closing This conversation is a compressed edit of an interview Freddy has conducted as part of his PhD research. The interview happened on July 2nd, 2025 in London, UK. #intelligenceagencies #intelligenceanalysis

    From US Army Intelligence to Private Sector Intelligence Advisor - Interview with Jeremy Levin (S02E05)
  8. Apr 8

    From UK Defense intelligence, Warning Intelligence, and IEDs, to Private Sector Intelligence - Interview with Will Woodall (S2E4)

    Summary Will Woodall shares his 14-year journey through intelligence roles in the UK government and transitioning to private sector intelligence. He explains motivations for leaving government (slow recruitment and limited recognition), contrasts public vs private sector work, and emphasizes core intelligence methodology: the yardstick/estimated probability language, source evaluation and confidence, structured analytical techniques, and clear writing and delivery tailored to customers. In the interview. Will and Freddy debate what distinguishes information from intelligence, how to measure intelligence program value through customer action and feedback, challenges like expert bias and stakeholder alignment, and how AI/LLMs can help with volume and practical tasks but require validation and human questioning. He advises aspiring analysts to pursue analytical subjects, develop domain expertise, and learn core intelligence components. Resources Extrac AI - https://www.extrac.ai/index.html SANS Admiralty Scale blog post 1 - https://www.sans.org/blog/enhance-your-cyber-threat-intelligence-with-the-admiralty-system SANS Admiralty Scale blog post 2 - https://www.sans.org/blog/admiralty-code-part-2-ticketmaster-data-breach-claims LinkedIn Post on what makes something intelligence - https://www.linkedin.com/posts/fmurre_in-your-opinion-when-does-something-go-from-activity-7181221399561203712-mV-m King's College London, the Intelligence Studies Program - https://www.kcl.ac.uk/study/postgraduate-taught/courses/intelligence-and-international-security-ma/teaching Structured Analytic Techniques (SATs) Training - https://inteltradecraft.com/sat-certifications Analytic standards ICD203 - https://www.dni.gov/files/documents/ICD/ICD-203.pdf PHIA UK Analytic Standards - https://www.gov.uk/government/publications/phia-common-analytical-standards/phia-common-analytical-standards LinkedIn Freddy M - https://www.linkedin.com/in/fmurre/ LLMs getting worse - https://royalsocietypublishing.org/rsos/article/12/4/241776/235656/Generalization-bias-in-large-language-model Chapters 00:00 Introduction to Intelligence and Personal Journey 07:15 Transitioning from Government to Private Sector 11:53 Understanding Intelligence Methodology and Standards 18:59 Defining Intelligence vs. Information 23:27 The Role of AI in Intelligence 31:02 Training and Methodologies in Intelligence 47:06 Challenges in Implementing Intelligence in the Private Sector 54:16 Measuring Success of Intelligence Programs 58:13 Challenges in Applying Intelligence in Organizations 01:02:06 Advice for Aspiring Intelligence Professionals 01:15:50 Influential People and Career Moments 01:17:28 Closing Remarks and Future Outlook This conversation is a compressed edit of an interview Freddy has conducted as part of his PhD research. The interview happened on July 2nd, 2025 in London, UK.

    From UK Defense intelligence, Warning Intelligence, and IEDs, to Private Sector Intelligence - Interview with Will Woodall (S2E4)

About

Join us on “Intelligence Tradecraft”, where we explore the adoption of intelligence tradecraft in the private sector. Hosted by an intelligence and cyber threat intelligence professional, each episode features interviews with top researchers, authors, and practitioners offering practical insights for experts and beginners alike. Whether you’re a seasoned intelligence analyst or just starting your journey, this videocast provides the tools, techniques, and inspiration to elevate your craft and sharpen your analytic advantage. Join our community and master intelligence tradecraft.

You Might Also Like