Uploaded June 2026 | Updated September 2026, 1 hour ago
Amine Besson (European Commission CSOC, NL), Rémi Séguy (European Commission CSOC, LU)
OpenTide (Open Threat Informed Detection Engineering), developed at the European Commission CSOC, bridges the gap between unstructured threat intelligence and actionable detections.
By modeling adversary behaviors as Threat Vectors and linking them to detection objectives and supporting rules, OpenTide enables faster operationalization of new intelligence, and understanding detection coverage in a much finer way than ATT&CK mappings. This session will show how OpenTide reframes TTP‑focused intelligence into a scalable workflow for modern detection engineering.
---
Amine Besson has one goal: figuring out what on earth we should be doing to detect actual threats. As an independent international contractor, Amine works around the world with the smallest to the largest SOCs and MDRs to discover how to answer to that question. Amine's projects usually span across Intelligence, Detection and Response Engineering, with a strong focus on automation and system-thinking over analyst driven workflows. Amine also maintains OpenTide (Open Threat Informed Detection Engineering), a project that was incubated at the European Commission and that aims at providing Detection Engineering teams with a platform to work in a repeatable manner.
Rémi Seguy has over 20+ years in the cybersecurity field, and has dedicated their career to safeguarding organisations by developing robust SOC and effective incident response teams. As a passionate advocate for knowledge sharing and collaboration - "sharing is caring"- Remi has actively contributed to the cybersecurity community and related open-source projects, such as MISP. In their current role, Remi has led the OpenTide initiative, turning it into a project at the core of the Detection Engineering team. Remi is looking for exchanging and collaborating with other Detection Engineering teams to develop repeatable, traceable, and pragmatic processes, effectively bridging the gap between Threat Intelligence, Threat Hunting, and Threat Detection.
Amine Besson (European Commission CSOC, NL), Rémi Séguy (European Commission CSOC, LU)
OpenTide (Open Threat Informed Detection Engineering), developed at the European Commission CSOC, bridges the gap between unstructured threat intelligence and actionable detections.
By modeling adversary behaviors as Threat Vectors and linking them to detection objectives and supporting rules, OpenTide enables faster operationalization of new intelligence, and understanding detection coverage in a much finer way than ATT&CK mappings. This session will show how OpenTide reframes TTP‑focused intelligence into a scalable workflow for modern detection engineering.
---
Amine Besson has one goal: figuring out what on earth we should be doing to detect actual threats. As an independent international contractor, Amine works around the world with the smallest to the largest SOCs and MDRs to discover how to answer to that question. Amine's projects usually span across Intelligence, Detection and Response Engineering, with a strong focus on automation and system-thinking over analyst driven workflows. Amine also maintains OpenTide (Open Threat Informed Detection Engineering), a project that was incubated at the European Commission and that aims at providing Detection Engineering teams with a platform to work in a repeatable manner.
Rémi Seguy has over 20+ years in the cybersecurity field, and has dedicated their career to safeguarding organisations by developing robust SOC and effective incident response teams. As a passionate advocate for knowledge sharing and collaboration - "sharing is caring"- Remi has actively contributed to the cybersecurity community and related open-source projects, such as MISP. In their current role, Remi has led the OpenTide initiative, turning it into a project at the core of the Detection Engineering team. Remi is looking for exchanging and collaborating with other Detection Engineering teams to develop repeatable, traceable, and pragmatic processes, effectively bridging the gap between Threat Intelligence, Threat Hunting, and Threat Detection.










