OpenTide: From Raw Intelligence to Structured Threat-Informed Detections @FIRSTdotorg
OpenTide: From Raw Intelligence to Structured Threat-Informed Detections  @FIRSTdotorg
Uploaded June 2026 | Updated September 2026, 1 hour ago
Amine Besson (European Commission CSOC, NL), Rémi Séguy (European Commission CSOC, LU)

OpenTide (Open Threat Informed Detection Engineering), developed at the European Commission CSOC, bridges the gap between unstructured threat intelligence and actionable detections.

By modeling adversary behaviors as Threat Vectors and linking them to detection objectives and supporting rules, OpenTide enables faster operationalization of new intelligence, and understanding detection coverage in a much finer way than ATT&CK mappings. This session will show how OpenTide reframes TTP‑focused intelligence into a scalable workflow for modern detection engineering.

---

Amine Besson has one goal: figuring out what on earth we should be doing to detect actual threats. As an independent international contractor, Amine works around the world with the smallest to the largest SOCs and MDRs to discover how to answer to that question. Amine's projects usually span across Intelligence, Detection and Response Engineering, with a strong focus on automation and system-thinking over analyst driven workflows. Amine also maintains OpenTide (Open Threat Informed Detection Engineering), a project that was incubated at the European Commission and that aims at providing Detection Engineering teams with a platform to work in a repeatable manner.

Rémi Seguy has over 20+ years in the cybersecurity field, and has dedicated their career to safeguarding organisations by developing robust SOC and effective incident response teams. As a passionate advocate for knowledge sharing and collaboration - "sharing is caring"- Remi has actively contributed to the cybersecurity community and related open-source projects, such as MISP. In their current role, Remi has led the OpenTide initiative, turning it into a project at the core of the Detection Engineering team. Remi is looking for exchanging and collaborating with other Detection Engineering teams to develop repeatable, traceable, and pragmatic processes, effectively bridging the gap between Threat Intelligence, Threat Hunting, and Threat Detection.
OpenTide: From Raw Intelligence to Structured Threat-Informed DetectionsThe Vulnerability Ecosystem’s Vendor Bias — Exposed by Open SourceRouting Security for Enterprises: Secure Your Supply ChainEmbracing the Era of Transparency: Automating VEX Application for Scalable, Context-Aware SecurityAttack or Noise?: Tracking and Evaluating the Impact of Internet-Wide Survey ScannersAI Is Writing Your Bug Reports. Can You Tell?Dark Silicon: Unmasking GPU Threats in the Age of AIAxiomatic Events that Evolved Vulnerability DatabasesOrganizational Context Matters: Security Control Effectiveness on Vulnerabilities for PrioritizationNIST’s National Vulnerability Database Update and the Vulnerability Enrichment EcosystemDefeating Node.js Malware through API TracingDetection Engineering 101 : Establishing a Structured Approach to Detection Engineering
FIRST |

OpenTide: From Raw Intelligence to Structured Threat-Informed Detections

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER