Join us on “Intelligence Tradecraft”, where we explore the adoption of intelligence tradecraft in the private sector. Hosted by an intelligence and cyber threat intelligence professional, each episode features interviews with top researchers, authors, and practitioners offering practical insights for experts and beginners alike. Whether you’re a seasoned intelligence analyst or just starting your journey, this videocast provides the tools, techniques, and inspiration to elevate your craft and sharpen your analytic advantage. Join our community and master intelligence tradecraft.

Intelligence Tradecraft - Sharpen your analytic edge
Claim This Podcastby Freddy Murre
Podcast Overview
Join us on “Intelligence Tradecraft”, where we explore the adoption of intelligence tradecraft in the private sector. Hosted by an intelligence and cyber threat intelligence professional, each episode features interviews with top researchers, authors, and practitioners offering practical insights for experts and beginners alike. Whether you’re a seasoned intelligence analyst or just starting your journey, this videocast provides the tools, techniques, and inspiration to elevate your craft and sharpen your analytic advantage. Join our community and master intelligence tradecraft.
Language
🇺🇲
Publishing Since
9/28/2025
1 verified contact email on file for Intelligence Tradecraft - Sharpen your analytic edge
Pitch yourself as a guest, propose sponsorships, or reach out directly to the host.
Recent Episodes

July 1, 2026
The librarian who founded modern OSINT: Sources, tradecraft & AI - Interview with Arno Reuser (S2E8)
<p>If you've ever read a text or sat in a briefing and quietly wondered what actually separates this "intelligence" from someone's hot take on LinkedIn, a journalist with a deadline, an analyst with a search bar, or an AI, this episode is for you.</p><p><br></p><p>The host, Freddy Murre, sits down with Arno Reuser, the man who founded the Dutch Defence Intelligence Service's open-source intelligence (OSINT) capability in the early 1990s, before most of Europe had a word for it. What follows is less an interview than a working argument about how OSINT should actually be done, and where the field has gone soft.</p><p><br></p><p>Arno doesn't mince words. He'll tell you the "information explosion" everyone complains about is just proof you skipped your stakeholder and requirement analysis. That most of what gets sold as OSINT is the word "OSINT" stapled to “everything”, such as tools. That he has, by deliberate choice, never written an analytical judgment in his life, and why that line between collection and analysis matters more than people think. For anyone who's argued about what counts as OSINT versus PAI (Publicly Available Information), or where collection ends and all-source begins, this is the debate you want to engage with.</p><p><br></p><p>Along the way: the librarian's discipline, he says, underpins all good intelligence work, the collection plan he calls "worth gold," the classroom trick thousands of students have failed, and a run of war stories from his teachings, such as a prison break by email to a deepfake that fooled cyber experts who personally know him.</p><p><br></p><p>The back half takes on two problems every practitioner is living with right now. How do you put a value on intelligence when the same report is priceless to one decision-maker and useless to the next? And what is AI actually good for? Arno uses LLMs daily and is genuinely amazed by them, but only for things he can verify. He and Freddy get specific on hallucinations, sycophancy, model collapse, and the difference between a real summary and a machine that just shortens the text and deletes the one sentence that mattered.</p><p><br></p><p><br></p><p><strong>RESOURCES</strong></p><p>Maersk Website - <a href="https://investor.maersk.com/news-releases/news-release-details/cyber-attack-update" target="_blank" rel="noopener noreferer">https://investor.maersk.com/news-releases/news-release-details/cyber-attack-update</a> </p><p>Dutch Police Data Breach - <a href="https://www.politie.nl/nieuws/2024/oktober/2/update-over-datalek-politie.html " target="_blank" rel="noopener noreferer">https://www.politie.nl/nieuws/2024/oktober/2/update-over-datalek-politie.html </a></p><p>When does something go from a Google answer to Intelligence - <a href="https://www.linkedin.com/posts/fmurre_in-your-opinion-when-does-something-go-from-activity-7181221399561203712-mV-m/" target="_blank" rel="noopener noreferer">https://www.linkedin.com/posts/fmurre_in-your-opinion-when-does-something-go-from-activity-7181221399561203712-mV-m/</a> </p><p>LexisNexis Library - <a href="https://www.lexisnexis.com/en-us/products/digital-library.page" target="_blank" rel="noopener noreferer">https://www.lexisnexis.com/en-us/products/digital-library.page</a> </p><p>Vague questions in OSINT - <a href="https://opensourceintelligence.biz/vague-osint-questions/" target="_blank" rel="noopener noreferer">https://opensourceintelligence.biz/vague-osint-questions/</a> </p><p>Structured Analytic Techniques (SAT) Training - <a href="https://inteltradecraft.com/sat-certifications" target="_blank" rel="noopener noreferer">https://inteltradecraft.com/sat-certifications</a> </p><p>Pherson Structured Analytic Techniques for Intelligence Analysis - <a href="https://www.amazon.com/Structured-Analytic-Techniques-Intelligence-Analysis/dp/150636893X/" target="_blank" rel="noopener noreferer">https://www.amazon.com/Structured-Analytic-Techniques-Intelligence-Analysis/dp/150636893X/</a></p><p>Routledge Handbook of Terrorism Research - <a href="https://www.routledge.com/The-Routledge-Handbook-of-Terrorism-Research/Schmid/p/book/9780415520997" target="_blank" rel="noopener noreferer">https://www.routledge.com/The-Routledge-Handbook-of-Terrorism-Research/Schmid/p/book/9780415520997</a> </p><p>AI Model Collapse - <a href="https://scholar.google.com/scholar?hl=en&as_sdt=0%2C5&q=AI+model+collapse&btnG=" target="_blank" rel="noopener noreferer">https://scholar.google.com/scholar?hl=en&as_sdt=0%2C5&q=AI+model+collapse&btnG=</a> </p><p><br></p><p><br></p><p><strong>CHAPTERS</strong></p><p>00:00 From literature searcher to founding military OSINT</p><p>04:00 Becoming a librarian: the Kampen archive moment</p><p>08:00 Where OSINT stops and intelligence begins</p><p>11:00 Why "cyber" keeps getting OSINT wrong</p><p>15:00 What actually makes something "intelligence"?</p><p>24:00 The information explosion myth</p><p>32:00 The classroom trick: think before you type</p><p>36:00 The collection plan that's "worth gold"</p><p>42:00 The human factor cyber keeps ignoring</p><p>45:00 War stories: validation and getting fooled</p><p>51:00 Learning the craft: sources, sources, sources</p><p>55:00 Customers ask for what they think you can do</p><p>01:08:00 Can you measure the value of intelligence?</p><p>01:11:00 AI and LLMs: amazed but skeptical</p><p>01:32:00 Deepfakes, the NATO photo & "how likely is it?"</p>

June 17, 2026
From Dutch Military Intelligence to Private Sector Cyber Threat Intelligence (CTI) - Interview w/Martijn (S2E7)
<p><strong>SUMMARY</strong></p><p>Former military intelligence analyst turned consultancy director Martijn Docters van Leeuwen joins Freddy Murre to unpack what cyber threat intelligence really is, and why so many teams "talk the talk" without "walking the walk", i.e. doing the work. </p><p><br /></p><p>Martijn Docters van Leeuwen has done the whole journey, infantry, military intelligence, stopping ATM skimming and gas attacks in the Netherlands, to building a bank's first CTI team, and now being a cybersecurity consultant.</p><p><br /></p><p>So when he talks about CTI being a tradecraft and not a report that magically lands in your inbox, he's not theorizing. He's been the only analyst in the room wearing all seven hats, the guy getting asked "why does this cost so much?", the one trying to prove value in the six quiet months when nothing's on fire.</p><p><br /></p><p>We get into the stuff analysts actually argue about: why most teams are great at talking the talk and bad at doing it, the trap of living in your own little football field while the business has no idea what you do, how people game their own metrics to manufacture a crisis, and where AI genuinely helps versus where it's just a confident liar with no fingers. Threat vs. risk, mirror imaging, incident-driven vs. intel-driven, and the brutal truth that training does nothing if you walk out the door and never apply it.</p><p><br /></p><p>If you do this work, or you're trying to convince someone it's worth doing, pour a coffee and settle in.</p><p><br /></p><p><br /></p><p><strong>RESOURCES</strong></p><p>Structured Analytic Techniques (SAT) Certification Training by Intel Tradecraft and Pherson - https://inteltradecraft.com/sat-certifications</p><p>Intelligence Mind Map - https://github.com/Errum/IntelArchitectureMap</p><p>When does something go from a Google answer to Intelligence - https://www.linkedin.com/posts/fmurre_in-your-opinion-when-does-something-go-from-activity-7181221399561203712-mV-m/</p><p>Mitre Att@ck - https://attack.mitre.org/resources/attack-data-and-tools/</p><p>Mark Arena - CTI: Comparing the incident-centric and actor-centric approaches - https://medium.com/@markarenaau/cyber-threat-intelligence-comparing-the-incident-centric-and-actor-centric-approaches-f20cfba2dea2</p><p>ASML The world's supplier to the semiconductor industry - https://www.asml.com/en</p><p>SANS FOR578 CTI - https://www.sans.org/cyber-security-courses/cyber-threat-intelligence </p><p>TIBER European Central Bank - https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html</p><p>Freddy's resources on SANS - https://www.sans.org/profiles/freddy-murstad#resources </p><p>The intelligence cycle - https://github.com/Errum/IntelArchitectureMap</p><p>Basic cyber-hygiene guidance from CISA - https://www.cisa.gov/topics/cybersecurity-best-practices</p><p>NSM ICT Security Principles - https://nsm.no/advice-and-guidance/publications/nsm-ict-security-principles</p><p>SANS FOR578 CTI - https://www.sans.org/cyber-security-courses/cyber-threat-intelligence</p><p>Obsidian (note-linking/mind-mapping for research) - https://obsidian.md/</p><p>CTI-CMM - https://cti-cmm.org/</p><p>CREST - https://www.crest-approved.org/</p><p>Google Notebook LM - https://notebooklm.google/</p><p>Intelligence minor, Leiden University - https://www.universiteitleiden.nl/en/education/minors/minor/fgga-minor-intelligence-studies</p><p>Heuer & Pherson Structured Analytic Techniques for Intelligence Analysis - https://www.amazon.com/Structured-Analytic-Techniques-Intelligence-Analysis/dp/150636893X/</p><p><br /></p><p><br /></p><p><strong>CHAPTERS</strong></p><p>00:00 Introduction & from military intel to CTI</p><p>08:30 Building a bank's first CTI team</p><p>15:00 What is intelligence — and what is CTI?</p><p>26:00 Talking the talk vs. doing the work</p><p>35:00 Incident-driven vs. intelligence-driven CTI</p><p>46:00 Tradecraft, methodology & pricing CTI work</p><p>53:00 Collection, analysis & tailoring reports</p><p>01:04:00 Mirror imaging & understanding threat actors</p><p>01:08:00 Measuring the value of a CTI program</p><p>01:19:00 Threat vs. risk: capability, intent & opportunity</p><p>01:24:00 Training intel skills & making it stick</p><p>01:36:00 Can AI help us do intelligence better?</p>

June 4, 2026
Lessons from a Former US Navy Collector - Joe Slowik on intelligence tradecraft and AI in CTI (S02E06)
<p>In this episode of Intelligence Tradecraft, host Freddy Murre sits down with Joe Slowik, a threat intelligence veteran whose career spans the US Navy, Los Alamos National Laboratory, MITRE, and the vendor world (Dragos, DomainTools, Gigamon, Huntress, and now DataMinr).</p><p><br /></p><p>In the conversation, Joe makes the case that intelligence is fundamentally about decision support, not raw data feeds or research written for other analysts. He and Freddy dig into what separates good reporting from bad, why stakeholder alignment and rigor (ICD 203, clear separation of fact vs. assessment) matter, and when a "flash report" beats a polished deep-dive.</p><p><br /></p><p>They also tackle the attribution debate — how-centric vs. who-centric attribution, the mess of overlapping naming schemas (APT10 vs. APT31, the Visma case), and why "trust us, we're Microsoft" isn't tradecraft. Joe explains the thinking behind his Applied Threat Intelligence training and the gap it was built to fill.</p><p><br /></p><p>The back half turns to AI: where LLMs genuinely help (research, scripting), where they're dangerous (cognitive offloading, model decay, drying up the junior-to-senior pipeline), who's accountable for AI-generated output, and how threat actors are using these tools, from better phishing to voice cloning. </p><p><br /></p><p>Joe's bottom line for newcomers: critical thinking, communication, and curiosity come before any prompt-engineering skill.</p><p><br /></p><p><br /></p><p><strong>Resources</strong></p><p>Joe Slowik's LinkedIn - <a href="https://www.linkedin.com/in/joe-slowik/" target="_blank" rel="ugc noopener noreferrer">https://www.linkedin.com/in/joe-slowik/</a></p><p>Joe Slowik's Blog and Courses - <a href="https://paralus.co/" target="_blank" rel="ugc noopener noreferrer">https://paralus.co/</a></p><p>Freddy' Structured Analytic Techniques (SAT) Training - <a href="https://inteltradecraft.com/sat-certifications " target="_blank" rel="ugc noopener noreferrer">https://inteltradecraft.com/sat-certifications </a> </p><p>Los Alamos National Laboratory - <a href="https://www.lanl.gov/" target="_blank" rel="ugc noopener noreferrer">https://www.lanl.gov/</a> </p><p>NIST Cyber Threat Intelligence definition - <a href="https://csrc.nist.gov/glossary/term/cyber_threat_intelligence" target="_blank" rel="ugc noopener noreferrer">https://csrc.nist.gov/glossary/term/cyber_threat_intelligence</a></p><p>CTI used in books (Google Search) - <a href="https://books.google.com/ngrams/graph?content=Cyber+threat+intelligence&year_start=2000&year_end=2022&corpus=en&smoothing=3&case_insensitive=false " target="_blank" rel="ugc noopener noreferrer">https://books.google.com</a> </p><p>APT 1 Report - <a href="https://services.google.com/fh/files/misc/mandiant-apt1-report.pdf " target="_blank" rel="ugc noopener noreferrer">https://services.google.com/fh/files/misc/mandiant-apt1-report.pdf </a></p><p>Moonligh Maze on Wikipedia - <a href="https://en.wikipedia.org/wiki/Moonlight_Maze" target="_blank" rel="ugc noopener noreferrer">https://en.wikipedia.org/wiki/Moonlight_Maze</a></p><p>SANS FOR578 CTI - <a href="https://www.sans.org/cyber-security-courses/cyber-threat-intelligence" target="_blank" rel="ugc noopener noreferrer">https://www.sans.org/cyber-security-courses/cyber-threat-intelligence</a> </p><p>ICD 203 - <a href="https://www.dni.gov/files/documents/ICD/ICD-203.pdf" target="_blank" rel="ugc noopener noreferrer">https://www.dni.gov/files/documents/ICD/ICD-203.pdf</a></p><p>MLitt in Terrorism and Political Violence - <a href="https://cstpv.wp.st-andrews.ac.uk/masters-in-terrorism-and-political-violence/ " target="_blank" rel="ugc noopener noreferrer">https://cstpv.wp.st-andrews.ac.uk/masters-in-terrorism-and-political-violence/ </a></p><p>Routledge Handbook of Terrorism Research - <a href="https://www.routledge.com/The-Routledge-Handbook-of-Terrorism-Research/Schmid/p/book/9780415520997 " target="_blank" rel="ugc noopener noreferrer">https://www.routledge.com/The-Routledge-Handbook-of-Terrorism-Research/Schmid/p/book/9780415520997 </a></p><p>APT Groups and Operations Rosetta Stone (not mine) - <a href="https://docs.google.com/spreadsheets/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/edit?pli=1&gid=1864660085#gid=1864660085 " target="_blank" rel="ugc noopener noreferrer">https://docs.google.com/spreadsheets/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/edit?pli=1&gid=1864660085#gid=1864660085 </a></p><p>Structured Analytic Techniques (SAT) Training - <a href="https://inteltradecraft.com/sat-certifications " target="_blank" rel="ugc noopener noreferrer">https://inteltradecraft.com/sat-certifications </a> </p><p>Tradecraft Primer: SATs - <a href="https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf " target="_blank" rel="ugc noopener noreferrer">https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf </a></p><p>An Illustrated Book of Bad Arguments - <a href="https://bookofbadarguments.com/ " target="_blank" rel="ugc noopener noreferrer">https://bookofbadarguments.com/ </a></p><p>Weston's Rulebook for Arguments - <a href="https://hackettpublishing.com/philosophy/logic-mathematics/critical-thinking/a-rulebook-for-arguments-group " target="_blank" rel="ugc noopener noreferrer">https://hackettpublishing.com/philosophy/logic-mathematics/critical-thinking/a-rulebook-for-arguments-group </a></p><p>Joe's Critique of Practical Threat Intelligence - <a href="https://pylos.co/2026/05/03/a-brief-critique-of-practical-threat-intelligence/ " target="_blank" rel="ugc noopener noreferrer">https://pylos.co/2026/05/03/a-brief-critique-of-practical-threat-intelligence/ </a></p><p>Cognitive Offloading - <a href="https://sistemasi.ftik.unisi.ac.id/index.php/stmsi/article/view/6180 " target="_blank" rel="ugc noopener noreferrer">https://sistemasi.ftik.unisi.ac.id/index.php/stmsi/article/view/6180 </a></p><p>OpenAI Research - <a href="https://openai.com/research/index/" target="_blank" rel="ugc noopener noreferrer">https://openai.com/research/index/</a></p><p><br /></p><p><br /></p><p><strong>Chapters</strong></p><p>00:00 Intro and Joe's career path</p><p>06:11 The Evolution of Cyber Threat Intelligence and intelligence</p><p>15:05 Rigor, reporting, & attribution</p><p>29:50 The Relevance of Intelligence in Incident Response and CTI</p><p>47:09 Building & measuring a CTI function</p><p>01:00:13 Training teams (and why it doesn't stick)</p><p>01:07:37 Integrating LLMs in Intelligence Work</p><p>01:19:50 Skills for the Future of CTI</p><p><br /></p>
15 total episodes available
Similar Podcasts
Discover related shows you might enjoy
Deep-dive analytics for Intelligence Tradecraft - Sharpen your analytic edge
Frequently asked questions
Have a different question and can't find the answer you're looking for? Reach out to our support team by sending us an email and we'll get back to you as soon as we can.
- What is Intelligence Tradecraft - Sharpen your analytic edge?
- How often does this podcast release new episodes?
This podcast updates daily.
- Where can I listen to this podcast?
This podcast is available on 4 platforms including Apple Podcasts, Spotify, and more. You can also use the RSS feed directly.
- Does this podcast accept guests?
Yes, this podcast regularly features guests.
Legal Disclaimer
Pod Engine is not affiliated with, endorsed by, or officially connected with any of the podcasts displayed on this platform. We operate independently as a podcast discovery and analytics service.
All podcast artwork, thumbnails, and content displayed on this page are the property of their respective owners and are protected by applicable copyright laws. This includes, but is not limited to, podcast cover art, episode artwork, show descriptions, episode titles, transcripts, audio snippets, and any other content originating from the podcast creators or their licensors.
We display this content under fair use principles and/or implied license for the purpose of podcast discovery, information, and commentary. We make no claim of ownership over any podcast content, artwork, or related materials shown on this platform. All trademarks, service marks, and trade names are the property of their respective owners.
While we strive to ensure all content usage is properly authorized, if you are a rights holder and believe your content is being used inappropriately or without proper authorization, please contact us immediately at hey@podengine.ai for prompt review and appropriate action, which may include content removal or proper attribution.
By accessing and using this platform, you acknowledge and agree to respect all applicable copyright laws and intellectual property rights of content owners. Any unauthorized reproduction, distribution, or commercial use of the content displayed on this platform is strictly prohibited.


