Ismael Valenzuela
Speaking & Media
Featured Interviews & Presentations
A selection of spotlight interviews and talks.

From Building Defenders to Commanding Cyber Labs — Ismael Valenzuela
Open
▶AI, Automation & Threat Modeling: Lessons Learned from Hacking the Planet
Open
▶AI-Powered BladeRunners, Part 2: Threat Intelligence Meets Zero Trust
OpenLatest Videos
AI, Automation & Threat Modeling: Lessons Learned from Hacking the Planet
A Conversation With Ismael Valenzuela About AI and Threat Intelligence
Threat Researcher Insights: A Day with Ismael Valenzuela
Zero Assumptions: Expert Threat Intel Roundtable on Emerging Cybersecurity Threats
Hunting Threats Inside Your Network with rastrea2r
In the Press
Loading press…
Conference Talks
AI, Automation & Threat Modeling: Lessons Learned from Hacking the Planet
Defensible Security Architecture: Building Defenses That Hold
Think Red, Act Blue: A Framework for Threat-Informed Defense
Disrupting the Disruptors: How to Threat Hunt Like a Pro
Hunting Threats Inside Your Network with rastrea2r
Podcasts & Audio
From Building Defenders to Commanding Cyber Labs: Ismael Valenzuela's Journey
A Conversation With Ismael Valenzuela About AI and Threat Intelligence
Threat Researcher Insights: A Day with Ismael Valenzuela
Arctic Wolf Labs Threat Intelligence Expert Roundtable on Emerging Threats
Cyber and Business are Becoming One with Ismael Valenzuela
On Cyber Security Interviews — Episode 009
Open Source Projects
View all on GitHub →attck-lens
Think Red. Act Blue. | A MITRE ATT&CK v18 Intelligence Dashboard
rsac2025
AI, Automation, & Threat Modeling: Lessons Learned from Hacking the Planet
jupyter-notebooks
My Jupyter Notebooks — threat hunting, data science for cybersecurity
blueteam_homelabs
Great List of Resources to Build an Enterprise Grade Home Lab
rastrea2r
Collecting & Hunting for IOCs with gusto and style
Talks-and-Presentations
Slides and other resources from my latest talks and presentations
Latest News
Fetching latest press…
The Framework
Think Red.
Act Blue.
As the creator of the Think Red, Act Blue philosophy — the foundational framework behind SANS SEC530: Defensible Security Architecture & Engineering — I've spent my career bridging the gap between offensive threat understanding and defensive security operations. Think Red, Act Blue challenges security teams to adopt the adversary's perspective not to attack, but to architect smarter, more resilient defenses. This approach has shaped how thousands of security professionals worldwide design detection strategies, build zero-trust architectures, and operationalize threat intelligence — moving the industry away from checkbox compliance toward continuous, threat-informed defense. As a SANS course author and instructor, I bring this philosophy to life through hands-on labs and real-world scenarios that equip defenders to stay ahead of evolving threats.
The Ecosystem
Where the Work Lives
Think Red. Act Blue.
The philosophy and framework site — adversary-perspective defense methodology for security practitioners.
www.thinkredactblue.comThe Monday Brief
Weekly signals-to-decisions newsletter on security, strategy, and threat intelligence.
themondaybrief.comATT&CK Lens
Interactive MITRE ATT&CK coverage and gap analysis tool built on the Think Red, Act Blue framework.
lens.thinkredactblue.comAll Around Defender
Practitioner school for security defenders — hands-on training for the modern security operations team.
SANS Institute
Upcoming Courses
Let's Connect
Get In Touch
Follow the work across platforms or reach out directly.
Newsletter
Get The Monday Brief
Weekly signals to decisions — curated intelligence, threat trends, and practitioner insights delivered every Monday.
Subscribe on Substack →