Uploaded April 2026 | Updated September 2026, 2 weeks ago
Check out Mallory here - https://ul.live/mallory_yt
I caught up with JCran to check out Mallory, his awesome new AI platform for cyber defenders. He gave me a demo of how it automatically pulls together threat intel and handles security operations so teams don't have to spend tons of time doing it manually.
What we talk about:
The origin story of Mallory:
We discuss why Jonathan built the platform to help cyber defenders keep up with the overwhelming flood of daily threat intel, supply chain attacks, and breaches.
Breaking news and "Stories":
We look at how the platform automatically pulls together timelines, sources, and entity details for active threats, doing the heavy lifting of manual blog research.
Deep dives into threat actors:
We check out the massive collection of evidence-backed data on groups like Team PCP and Lazarus, and see how Mallory seamlessly maps out their aliases and attack patterns.
AI agents and automation:
We play around with Mallory's built-in chat agent, using it to generate tabletop exercises and set up automated daily intel alerts directly into Slack.
Asset inventory and API workflows:
We explore how Mallory links breaking threat intel right to internal software assets, plus a geek-out session on building custom skills and grabbing the open API spec.
00:00 - Introduction and building Mallory.
05:00 - Premium vs. Free Tier.
08:33 - Mapping Relationships.
14:33 - Querying Internal Controls.
16:23 - API Tiers.
17:10 - Product Packaging.
20:31 - Agent Auditability.
23:23 - Building Custom Skills.
24:07 - Accessing APIs.
Subscribe to the newsletter at:
danielmiessler.com/subscribe
Join the UL community at:
danielmiessler.com/upgrade
Follow on X:
https://x.com/danielmiessler
Follow on LinkedIn:
linkedin.com/in/danielmiessler
Check out Mallory here - https://ul.live/mallory_yt
I caught up with JCran to check out Mallory, his awesome new AI platform for cyber defenders. He gave me a demo of how it automatically pulls together threat intel and handles security operations so teams don't have to spend tons of time doing it manually.
What we talk about:
The origin story of Mallory:
We discuss why Jonathan built the platform to help cyber defenders keep up with the overwhelming flood of daily threat intel, supply chain attacks, and breaches.
Breaking news and "Stories":
We look at how the platform automatically pulls together timelines, sources, and entity details for active threats, doing the heavy lifting of manual blog research.
Deep dives into threat actors:
We check out the massive collection of evidence-backed data on groups like Team PCP and Lazarus, and see how Mallory seamlessly maps out their aliases and attack patterns.
AI agents and automation:
We play around with Mallory's built-in chat agent, using it to generate tabletop exercises and set up automated daily intel alerts directly into Slack.
Asset inventory and API workflows:
We explore how Mallory links breaking threat intel right to internal software assets, plus a geek-out session on building custom skills and grabbing the open API spec.
00:00 - Introduction and building Mallory.
05:00 - Premium vs. Free Tier.
08:33 - Mapping Relationships.
14:33 - Querying Internal Controls.
16:23 - API Tiers.
17:10 - Product Packaging.
20:31 - Agent Auditability.
23:23 - Building Custom Skills.
24:07 - Accessing APIs.
Subscribe to the newsletter at:
danielmiessler.com/subscribe
Join the UL community at:
danielmiessler.com/upgrade
Follow on X:
https://x.com/danielmiessler
Follow on LinkedIn:
linkedin.com/in/danielmiessler










