Ransomware groups disband and rebrand, but the people running them keep using what works. Recorded on location at Black Hat USA 2026, this conversation looks at what changes for defenders when the tracking follows the actor instead of the logo.
Proactive and actionable get used a lot in security, and Michael DeBolt, President and Chief Intelligence Officer at Intel 471, is direct about it. Inside Intel 471, proactive means moving past indicators of compromise, which he describes as temporary, and focusing on adversary behavior instead. Indicators still get blocked. Intent, capability, and motivation are what tell a defender whether they are actually a target.
So what is pre-attack intelligence? It is information gathered from inside adversary communities before an attack is launched, built on embedded access to the places where financially motivated actors communicate. DeBolt sets aside the deep and dark web framing, arguing the phrase suggests a space nobody can reach. Mapping it reveals a structured ecosystem of financially motivated cybercrime, with enabling services operating alongside the actors themselves.
Why track actors rather than ransomware groups? Because operators move and behaviors stay. Many current groups are staffed by people who ran earlier groups that have since disbanded, and techniques travel with them. A threat hunt built around the behavior holds up whether that person is operating under one banner, another, or on their own.
Intel 471 maps techniques to the MITRE framework, which lets a consuming team run threat profiling and decide which actors present more risk than others. The same logic applies to exposure work. An organization scanning its attack surface and finding internet facing vulnerabilities can ask which threat actors are discussing those vulnerabilities, and whether that moves an item to the top of the list.
The CISO conversations DeBolt describes land on numbers most security leaders already report on. Mean time to respond, mean time to detect, and alert volume that can absorb half or more of an analyst's day. He uses the phrase decision grade intelligence for intel that informs security operations rather than sitting beside it, with integrations pushing it straight into analyst workflows.
Two customer situations show the daily version. Intel 471 helped an organization locate an insider after its own monitoring flagged something unusual. Separately, initial access brokers advertise compromised credentials that feed ransomware operations downstream, and since actors lie and embellish, validating those claims is part of the work. DeBolt closes on a note that sits right next to everyone's AI investment. Credentials, identity, internet facing vulnerabilities, and open remote access tools are still how attackers get in.
GUEST
Michael DeBolt, President and Chief Intelligence Officer, Intel 471
LinkedIn: https://www.linkedin.com/in/mdebolt/
RESOURCES
Black Hat USA 2026 Event Coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas
Learn more about Intel 471: https://www.intel471.com/
Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings
KEYWORDS
Michael DeBolt, Intel 471, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, cyber threat intelligence, pre-attack intelligence, adversary behavior, ransomware, initial access brokers, insider threat, MITRE framework, threat hunting, decision grade intelligence, compromised credentials, attack surface, cybercrime underground, Black Hat USA 2026
Adversary Behavior Outlasts the Ransomware Brand | A Brand Spotlight at Black Hat USA 2026 with Michael DeBolt, President and Chief Intelligence Officer of Intel 471 | Hosted by Sean Martin
[00:00:00] Sean Martin: It's a city of fun.
[00:00:10] Michael DeBolt: City of fun.
[00:00:11] Sean Martin: Summer camp.
[00:00:12] Michael DeBolt: I'm just trying to regulate my body temperature.
[00:00:14] Sean Martin: Right.
[00:00:15] Michael DeBolt: It is like...
[00:00:16] Sean Martin: Hot, freezing in here.
[00:00:17] Michael DeBolt: Yeah.
[00:00:19] Sean Martin: Boiling outside.
[00:00:20] Michael DeBolt: I can't figure it out.
[00:00:21] Sean Martin: I know. You just have to go inside, outside, inside, outside. So maybe the pool's the best spot. I don't know.
[00:00:26] Michael DeBolt: Well, I go outside to thaw and then I come back inside to cool off a little bit in the igloo.
[00:00:32] Sean Martin: That's right. There's probably a security story in there somewhere.
[00:00:34] Michael DeBolt: Probably. We can make one up.
[00:00:36] Sean Martin: We can make one up.
[00:00:38] Sean Martin: It's good to meet you, man.
[00:00:39] Michael DeBolt: Likewise.
[00:00:40] Sean Martin: Glad to have you on. And, uh, we'll hear all about the Intel 471 story.
[00:00:45] Michael DeBolt: Yeah.
[00:00:45] Sean Martin: Let's do it. So, let's start with a little bit about your role and what you're up to, and then a snippet of what Intel 471 does.
[00:00:53] Michael DeBolt: Yeah, absolutely. So I'm President and Chief Intelligence Officer at Intel 471. Um, you know, we're a cyber threat intelligence company. We really, our bread and butter is getting deep, embedded access into adversaries, where they communicate, where they talk. Really all about trying to provide that pre-attack intelligence to our customers so they can be proactive and understand the adversary better and take proactive defensive measures.
[00:01:18] Sean Martin: Nice. So let's, so there's a, there's three words. Pre... oh geez, and I just forgot 'em. Pre...
[00:01:27] Michael DeBolt: Pre-attack intelligence.
[00:01:27] Sean Martin: Pre-attack intelligence. There we go.
[00:01:29] Michael DeBolt: Yeah.
[00:01:29] Sean Martin: Pre-attack. So that seems really cool to me. I'm gonna come back to that. But there's a word that's been used a lot in security. Proactive.
[00:01:38] Michael DeBolt: Proactive. How about actionable?
[00:01:39] Sean Martin: And actionable. So I want to go there first, if you don't mind, and 'cause I think people might hear that and say, eh...
[00:01:47] Michael DeBolt: Yeah, it's a bit of a buzzword.
[00:01:48] Sean Martin: I know, it's, we're supposed to be proactive. What does that really mean? So maybe a definition of proactive from your perspective, and is it what people think it is, or is it something different based on what you...
[00:01:59] Michael DeBolt: Yeah, I mean, you're right, it's a bit of a buzzword that gets thrown around quite a bit. I'm sure you walk the floor at Black Hat, you're gonna see it quite a bit, probably alongside AI and agentic and all of those fun words.
For us, it really means, you know, going beyond the IOCs, going beyond indicators, um, which are really temporary, and more focusing on the adversary behaviors. So really understanding who the adversaries are. You know, I look at the threat landscape like a battlefield, kind of like a war. We're fighting a war as defenders, and you know, really it's about how can I counter the adversaries' attacks against me? And really the best way to do that is to go behind enemy lines and become intimately familiar with who you're up against. And that means understanding not just the tools that they're using.
Of course, indicators are important because we have to block those, but really start to understand what their intentions are, their capabilities, what their motivations are, so that I can understand whether truly I'm at risk and I'm a target.
[00:03:09] Sean Martin: Right. So, pre-attack intelligence. Um, maybe unpack that a bit as well, because you talk about knowing what their intent is, and not just doing stuff doesn't necessarily expose intent, I'm gonna guess. Um, so how do you find that, and how do you use that to get to the...
[00:03:30] Michael DeBolt: Yeah.
[00:03:30] Sean Martin: ...attack.
[00:03:30] Michael DeBolt: There's a couple ways. I mean, let me just start by saying, so we focus predominantly on the financially motivated cyber underground.
[00:03:38] Sean Martin: Okay.
[00:03:39] Michael DeBolt: And speaking of buzzwords, you'll hear all about the deep and dark web. We don't typically use that because it's sort of nebulous and it kind of denotes this hard to reach space that no one really understands. Um, but in fact it's quite organized. And sure, there are millions upon millions of handles out there and lots of noise. But really when it comes down to it, you're dealing with a structured ecosystem of financially motivated cybercrime.
You have services that are enabling cybercrime. You've got certainly the individual actors who are conducting attacks. But really our job, our mission at Intel 471, is to enumerate and map out that space. And when you do that, you realize it's not nebulous, it's not deep, and it's not dark.
Um, so once you do that, once you map out this space, then you start to become more intimately familiar with who these adversaries are. And so a good example might be, okay, so everybody knows ransomware. Ransomware has been around for a long, long time. A lot of ransomware groups have come up over the years, new ones, new branding. But you know, a lot of these ransomware groups consist of former operators of ransomware groups that have disbanded in the past.
[00:04:52] Sean Martin: Okay, so it's kind of...
[00:04:53] Michael DeBolt: Yeah, they kind of...
[00:04:53] Sean Martin: ...switch...
[00:04:54] Michael DeBolt: ...jobs. And what happens, you know, it's human behavior, right? To continue on doing what works. And so if a behavior or a technique works by one adversary, it really doesn't matter which ransomware group they fall into, they're gonna carry on those same behaviors and those techniques. And so we track the actors themselves and the behaviors of those actors, so that when they do make a change into a new ransomware group, or they're operating on their own, maybe their behaviors still remain the same.
So that might impact the way you, say for instance, do threat hunting operations. So the way I hunt for that adversary is gonna be the same, whether that adversary is part of ransomware group A or ransomware group B.
[00:05:35] Sean Martin: Right. So not dark, not deep.
[00:05:40] Michael DeBolt: That's right.
[00:05:40] Sean Martin: Still mysterious, maybe a little bit.
[00:05:42] Michael DeBolt: It's a little bit mysterious.
[00:05:43] Sean Martin: But not a place organizations really should go. They should look for a partner who has access and an understanding and the ability to be in there and look for the right things.
[00:05:54] Michael DeBolt: That's right.
[00:05:55] Sean Martin: So tell me a little bit about how that works and what you bring back to the organization then, so they don't have to do that work.
[00:06:00] Michael DeBolt: That's right. Well, it's a gray area. You're right, it's mysterious. And organizations don't want to take on the risk of operating in that gray area themselves. That's number one. Number two is it takes expertise. It takes native language proficiency, because a lot of these actor communities and networks are Russian speaking or Chinese speaking, or languages that organizations just are not equipped to understand what's going on. And so, uh, and then also it takes some cultural understanding, and understanding the nomenclature of how actors talk. It's a totally, you know, it's a different slang, it's a different language.
[00:06:37] Sean Martin: It's just like the kids with the, uh, the emojis, right?
[00:06:39] Michael DeBolt: That's right. Yeah. It's like me trying to understand what my teenage girls are talking about on their text threads. Right? Um, and so that's the kind of visibility and capability that we offer. We have researchers all over the world who have that native language proficiency and cultural understanding, that really, and here's the key, it gets us as close as we possibly can to the adversary to elicit that kind of really rich behavioral insight that the organizations that we support and we partner with really rely on to understand those behaviors and be able to act on those preemptively.
[00:07:15] Sean Martin: So how do those behaviors surface as tools or tactics or techniques that...
[00:07:22] Michael DeBolt: Yeah.
[00:07:23] Sean Martin: Okay. Do you flag them as things that organizations should pay attention to, or do you just surface it and then they have to kind of figure out what...
[00:07:31] Michael DeBolt: Yeah, no. Great, great question. I already mentioned threat hunt, right? So one really great way to operationalize this kind of threat intelligence is by doing hunting operations that are targeting those specific behaviors that actors deploy.
Um, another one could be, you know, everything that we do, we map to the MITRE framework. Right? So all of these techniques are mapped to the MITRE framework. As an organization consuming that intel, I can start doing some threat profiling to understand which actors might be more of a threat to me than others. So it helps with prioritization. I'm not having to deal with all of this noise over here. I can just focus on these techniques and these actors.
Another one is exposure. So we offer an attack surface and third party risk solution to our customers. And this really helps to, let's say, I'm an organization that's scanning my attack surface and I find internet facing vulnerabilities. Well, I also want to know who are the threat actors out there that are discussing those vulnerabilities. And is this truly something that I need to raise to the top of the priority list? So it's a combination. There's many more, but that's a combination of the things that work for the organizations that we support.
[00:08:40] Sean Martin: So you probably have some really cool conversations with analysts. Um, what about people at the security operations management layer, CISOs, do you get a chance with them as well?
[00:08:53] Michael DeBolt: Yeah, absolutely.
[00:08:54] Sean Martin: What do those conversations sound like?
[00:08:56] Michael DeBolt: Yeah, well, how can I be more proactive? I mean, really it starts there.
[00:09:02] Sean Martin: Are there specific things like, we want to bring our... I don't know, what are they measured on? Mean time to detection, mean time to response?
[00:09:10] Michael DeBolt: Yeah, a hundred percent.
[00:09:11] Sean Martin: Is that the kind of stuff they're asking?
[00:09:11] Michael DeBolt: Yeah, mean time to respond is a big one. You know, prioritization I mentioned just a minute ago, that kind of embeds into that. So, you know, if I'm focusing on all of these alerts that absorb 50, 60% of my time, you know, I want to make sure I'm spending the right time on the right stuff.
So, helping organizations, you know, this is what threat intel does, right? When you have decision grade intelligence, it really should inform the rest of your security operations, and really wherever you're using threat intel across your business, to help you prioritize and make your job more efficient. And that's, you know, we have integrations that provide our intelligence downstream directly into analyst workflows, um, to make things as seamless as possible.
When I talk to CISOs, you know, that's really what it comes down to. Efficiency gains. How can I improve my mean time to respond, mean time to detect? And so that's ultimately the goal, the business goal that we're trying to achieve for our customers.
[00:10:08] Sean Martin: Right. So the world of tech has changed dramatically in the last couple years, and certainly the adversaries are using tools now that can scale.
[00:10:24] Michael DeBolt: That's right.
[00:10:25] Sean Martin: Right. Um, how do you help organizations counter that scale and the volume, perhaps, that they're seeing?
[00:10:32] Michael DeBolt: Yeah, and I would say, you know, we say this I feel like every year, but the barrier of entry is so low for actors to just come on the scene and be able to deploy pretty wide scale, impactful attacks against organizations these days. I mean, I would even go so far as to say that the barrier of entry is like, it's nothing now. Right?
Um, with AI, and even before AI hit on the scene, there were services in the underground that really enabled these. There are dedicated services and products in the underground marketplace that threat actors can just use and deploy at their will.
So again, it's, you know, you can look at the IOCs and you can look at the telemetry and try to protect yourself in a more defensive, reactive posture. But what we try to do is get ahead of that and say, hey look, we're tracking this new malware as a service. We have early samples of the malware that's being offered by this actor, because we have that placement and we have that access, um, to give our customers a head start on what they could expect as that malware as a service grows.
[00:11:38] Sean Martin: Right. So decision grade, is that what you said? Decision...
[00:11:43] Michael DeBolt: Decision grade intelligence. Yeah.
[00:11:45] Sean Martin: It's all about making decisions quickly, right? Confidence, I think, is also important. Um, maybe as we wrap, is there a story or two from a customer where you helped them make a decision that could have been, I'll say, life or death for their business, or certainly seriously impactful?
[00:12:05] Michael DeBolt: Well, uh, I don't know if it's fortunate or unfortunate, but this is a daily occurrence for us. Uh, recently we found an insider, actually two separate organizations had an insider that we helped them with. They had some indications based on their own monitoring internally that something weird was happening. And so they asked us to support, and we ended up finding and locating the insider.
[00:12:27] Sean Martin: So the insider was connected outside as well?
[00:12:29] Michael DeBolt: That's right. Yeah. They were trying to earn a profit by sharing some internal sensitive stuff. Okay. Another one is, you know, initial access brokers. Credential theft and initial access using credentials is still a basic hygiene problem, but it's there. I mean, that's how threat actors are getting in still, even in the age of AI.
And so one of the things that we're constantly doing is monitoring the initial access broker space, and a lot of these initial access brokers will be feeders into ransomware, right? So there's downstream impact. And so initial access brokers will come out and they'll say, we've got access to all of these compromised credentials. Do you want to buy them? You know, we'll share them with you. And you might not believe this, but threat actors lie.
[00:13:13] Sean Martin: Really.
[00:13:13] Michael DeBolt: And they embellish. Yeah. Criminals lie. It's pretty, you know, astounding fact. But you know, one of our jobs, using our placement and access, is to validate that. Right? You know, maybe this is a Russian language actor and organizations are just seeing it maybe on a forum and they're like, maybe I'm impacted, maybe I'm not. Can you help us with that? And so we could go in...
[00:13:34] Sean Martin: For a diversion, or...
[00:13:35] Michael DeBolt: ...who knows, or it could be a completely different, uh, so one of my favorite things is when we're able to validate that for them and actually say, no, it's not your organization. The criminal was lying, or he was wrong. So now they can move on to something that's more impactful for them.
[00:13:50] Sean Martin: I just want to dig into so much more. We only have a couple seconds here though. Um, how about a call to action to CISOs and security leaders who, I don't know, maybe a lot of companies think they need to be mature enough to take in intelligence and actually do something with it. Um, I feel we've come a long way and it's almost a fundamental element of security operations. So maybe a word to the CISOs who might have a misunderstanding of where that might sit in their...
[00:14:25] Michael DeBolt: Well, I would say, and this is maybe not directly related to intel, but you know, just a note on AI.
[00:14:34] Sean Martin: Okay.
[00:14:34] Michael DeBolt: Right? So the AI hype is real. You know, we're investing in AI ourselves. AI is a real thing. Agentic AI is gonna be amazing for us, as we're already seeing on the defender side, producing amazing results.
However, I would say basic hygiene is still a big problem. Okay? Credentials, identity, internet facing vulnerabilities, leading remote access tools open to the internet. These are things that, you know, again, as we talk about lowering the barrier of entry and becoming a hard target, right? Organizations want to become a hard target. As you're focusing on AI, as we all should, don't skimp out on the basics.
[00:15:13] Sean Martin: Because you're seeing a lot of stuff.
[00:15:15] Michael DeBolt: That's right. Yeah.
[00:15:18] Sean Martin: Well, good advice, Michael. All right. I think I've thought out a little bit.
[00:15:21] Michael DeBolt: Talking, so it's good.
[00:15:23] Sean Martin: I'm thought out a little as well. So, alright, great conversation, and uh, appreciate all that you're doing. Connect with, uh, Michael and the Intel 471 team. Get your own intelligence from this crew. Pre-attack intelligence so you can make decisions that stick, that matter, with confidence. All that, that's great. Thank you.
[00:15:55] Michael DeBolt: Thank you.
[00:15:56] Sean Martin: Alright, thanks everybody. Stay tuned for more here on ITSPmagazine.