Decision-grade cyber intelligence
for security leaders, executives
and sensitive investigations.

Identify exposed assets, leaked credentials, hostile actors and executive digital risks before they become incidents. Receive clear findings, evidence and prioritized remediation — not another automated scan.

30+ years in cybersecurity Former Head of Research & CTI Five years, Israel National Cyber Directorate Financial-sector security leadership Skyhawk and Rapid7 threat research English, Hebrew and Russian service

Services

Intelligence services

From one-off investigations to ongoing retainer engagements — OSINT-led, intelligence-grade.

Specialist engagements
🎯

Threat Actor Attribution & CTI

Deep-pattern analysis and intelligence tradecraft to identify who is targeting you, profile threat actors, map TTPs, and attribute campaigns. Available for security teams and law firms.

Learn more →
🔍

Complex OSINT Investigation

Custom intelligence research across open sources — due diligence, identity investigation, business intelligence, or pre-engagement background checks. Scoped and quoted per engagement.

Learn more →
🕵️

HUMINT-informed Intelligence Support

Combining open-source signals with human-source tradecraft for complex investigations that require depth beyond digital traces alone.

Learn more →

How it works

The engagement process

A structured four-stage methodology — designed for sensitive situations where clarity and control matter.

01

Confidential intake

I understand the issue, the decision you need to make, and the sensitivity level. Nothing leaves this conversation.

02

Scope & intelligence requirements

I define the specific questions to answer, sources to use, ethical and legal constraints, and the form the deliverables will take.

03

Collection & analysis

Open-source and permitted intelligence is collected, findings are cross-validated, and relationships between data points are mapped and assessed.

04

Reporting & action

Decision-level findings, supporting technical evidence, and prioritized recommendations — structured for the people who need to act on them.

Experience

Why work with me

Three decades across national-level intelligence, financial sector security, and the forefront of commercial threat research.

Israel National Cyber Directorate · 5 Years

Head of Research & CTI

Led national-level cyber threat intelligence operations — monitoring nation-state threats, directing research on critical-infrastructure attack trends, and building intelligence-sharing frameworks with international partners and the private sector.

First International Bank of Israel · 2M+ Customers

Cyber Defense & InfoSec Audits Manager

Established cyber defense operations and a risk-based audit program across banking systems. PCI DSS compliance, vulnerability management, and threat detection for one of Israel's major financial institutions.

Skyhawk Security · Rapid7

Head of Research / Lead Security Expert

At Skyhawk, developed CADR capabilities mapping complete attack paths from application-layer vulnerabilities through lateral movement. At Rapid7, drove threat research that shaped platform detection methodology for global enterprise customers.

TriplEye · Independent Consultancy

Founder & Principal Consultant

Created UTI (Universal Threat Intelligence) — an open-source Python platform integrating 20+ global threat feeds with Elasticsearch and the ELK stack, used by SOC analysts and threat researchers worldwide. Delivered security and CTI engagements for financial services and technology clients.

Credentials

Certifications & capabilities

Professional certifications

CISSP CISO CSO CC

Service languages

🇺🇸 English 🇮🇱 Hebrew 🇷🇺 Russian

Domain expertise

OSINT / HUMINT Cloud Security Financial Cybersecurity AI for Security Nation-State CTI

Case Studies

Results from real engagements

All client details are anonymized. Situations, findings, and outcomes are drawn from actual engagements.

Executive Digital Exposure
Situation

A founder preparing for a public listing anticipated significant press attention and investor scrutiny. She had no visibility into what was publicly findable about her online and wanted to understand her exposure before the IPO process began.

Findings
  • Home address and personal phone number listed on three data broker sites
  • Personal email credentials found in two breach databases with cracked passwords still matching active account format
  • Active impersonation account on a professional platform — sending connection requests to her real contacts for four months undetected
  • Family member locations deducible from tagged social media posts over six months
  • Domain registered in her name by an unknown party, pointing to a parking page
Outcome

All data broker listings removed. Impersonation account taken down within 48 hours. Compromised credentials rotated with MFA enforced. Domain acquired and secured. Continuous monitoring established ahead of the IPO.

External Attack Surface
Situation

A fintech platform preparing for Series B needed an independent external assessment before lead investor due diligence. The company had a full-time security engineer and considered their external posture well-managed.

Findings
  • Three forgotten development servers running live — two with embedded production API keys in their configuration
  • 47 employee credentials in public breach databases, 11 matching the current active-directory password format
  • Wildcard subdomain pointing to a decommissioned third-party system still serving a valid authentication page
  • Sensitive internal documentation in a public repository belonging to a former contractor
Outcome

All critical findings resolved within 72 hours of report delivery. Series B due diligence passed without security issues. Round closed on schedule.

Threat Actor Attribution
Situation

A European technology company in a specialized engineering sector suffered three separate targeted intrusions over fourteen months. Each focused specifically on proprietary design data and consistently evaded existing detection tooling. The MSSP had contained each incident but could not explain the pattern.

Findings
  • Attack infrastructure linked to a known commercial espionage group with confirmed state adjacency
  • Dark web intelligence: explicit targeting directive naming the company's product sector appeared six weeks before the first intrusion
  • TTP match to seven prior confirmed campaigns targeting the same engineering sector across three jurisdictions
  • Motivation profile: competitive intelligence on behalf of a known foreign commercial actor
Outcome

Attribution assessment accepted as expert evidence in legal proceedings. IP handling restructured to prevent exfiltration even under future successful intrusions. Legal action filed; intrusion attempts ceased within weeks.

Financial-Sector Investigation
Situation

A mid-market private equity firm was finalizing a significant secondary transaction and commissioned founder due diligence. The subject had passed standard background checks and had been vetted by a previous investor three years earlier.

Findings
  • Undisclosed insolvency in a prior business registered under a name variant in another jurisdiction — invisible to English-language searches
  • Regulatory inquiry into a prior employer (subject served as director) documented in a Hebrew-language financial regulator publication — resolved without admission
  • Corporate connections to a subsequently sanctioned individual via shared nominee director in a low-disclosure jurisdiction
Outcome

Transaction restructured with enhanced representations and warranties. Deal closed on revised terms. All three findings would have been missed by standard English-language due diligence services.

Sample deliverables

Format and structure of typical report outputs. All content is illustrative — no client data is shown.

Executive Summary — sample format
Executive Summary
Exposure Map — sample format
Exposure Map
Investigation Timeline — sample format
Investigation Timeline
Infrastructure Relationship Graph — sample format
Infrastructure Relationship Graph
Risk-Prioritization Table — sample format
Risk-Prioritization Table

Contact

Let's work together

Intelligence engagements are confidential. Reach out to discuss your situation — initial consultations are discreet and commitment-free.

Free · 20 minutes
📞

Book a confidential scoping call

Discuss your situation confidentially. I'll ask the right questions, tell you honestly whether I can help, and outline what an engagement would look like — no commitment required.

Book a Call
No commitment
📄

View a sample intelligence report

See a redacted example of a delivered intelligence report — format, depth, and the type of findings you can expect before committing to an engagement.

Download Sample Report (PDF)
Paid · Fixed scope
🔒

Paid initial assessment

60-minute confidential intelligence consultation, preliminary exposure review, written summary and recommended next actions. Secure payment via PayPal.

Book via Calendly

Secure Intake

Submit a confidential enquiry

I review every request personally and respond within one business day.

🔒 Do not submit confidential evidence, credentials, or personally sensitive information through this form. Secure transfer instructions will be provided after initial contact.

Reviewed personally. Responds within one business day.

Enquiry received

Thank you — I'll review your request and be in touch within one business day.