Behavioural intelligence: Analytical frameworks for the future of threat intelligence
Abstract
Traditional cyber threat intelligence (CTI) remains a valuable mechanism for attribution, contextualisation, and strategic awareness; however, its reliance on post-disclosure indicators imposes inherent temporal limitations. As adversaries increasingly exploit pre-disclosure vulnerabilities, legitimate credentials, and cloud-native attack pathways, indicator-driven detection models are frequently unable to provide timely defensive insight. This paper draws from real-world case studies on pre-vulnerability disclosure exploitation, multistage intrusions and nation-state activity to present behavioural intelligence as a complementary and operationally critical detection paradigm, capable of identifying malicious activity through deviations from established system and user behaviour days to weeks before traditional CTI signals emerge. It further addresses a gap in existing research, going beyond detection to interpretability by proposing two practical frameworks for operationalising behavioural intelligence within security operations centre and threat hunting workflows. These frameworks integrate unsupervised and supervised machine learning, graph analytics, and agentic reasoning to correlate low-signal anomalies into high-confidence threat narratives. The findings highlight behavioural intelligence as a necessary evolution of CTI, enabling earlier detection, improved contextual understanding, and more adaptive defence against modern, rapidly evolving adversaries. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
The full article is available to subscribers to the journal.
Author's Biography
Nicole Wong is a Principal Cyber Analyst at Darktrace and an international presenter known for her work at the intersection of artificial intelligence (AI)-driven security, operational technology (OT) defence, and advanced threat investigations. She manages high-profile incidents and leads multidisciplinary research across critical sectors including finance, healthcare, telecommunications, and energy, advising global security teams on how to operationalise AI for proactive threat hunting and analysis. During the 2022 Qatar World Cup, Nicole was deployed onsite as Darktrace’s technical analysis lead, covering the IT and OT environments of all six stadiums. Before joining Darktrace, Nicole worked for the UK’s National Health Service, where she delivered enterprise security initiatives and contributed to the cyber security standards underpinning NHS England’s Digital Technology Assessment Criteria. Nicole holds certifications in GIAC Response and Industrial Defense and Systems Security Certified Practitioner.
Nathaniel Jones is Vice President, Security and AI Strategy, Field Chief Information Security Officer at Darktrace, where he leads initiatives including strategic customer engagements, threat research, and industry collaborations to increase the use of artificial intelligence (AI)-driven cyber security solutions. Drawing on his extensive background in both government and private sector cyber security, Nathaniel brings a global perspective to threat analysis and defence strategies. Prior to Darktrace, he spent six years at the US Cybersecurity and Infrastructure Security Agency (CISA), where he served as CISA’s operational liaison to the UK’s Government Communications Headquarters. His expertise spans threat hunting, cyber intelligence, and incident response across multiple countries, including spending over three years in China (achieving fluency in Mandarin) and holding positions at the US Embassies in Beijing and London. At Darktrace, Nathaniel applies this diverse experience to drive threat research initiatives across industries and regions, and helps to translate market insights and customer feedback into product innovation that addresses the evolving challenges in today’s cyber security landscape. He holds a master’s degree in international management and security policy from UC San Diego, and is a Certified Information Security Manager and Certified Ethical Hacker.
Calum Hall is a Cyber Analyst and Malware Researcher with over six years’ experience in cyber security. Currently part of the Threat Research team at Darktrace, his work includes reverse engineering malware, designing honeypot environments, authoring technical white papers, and researching threats affecting a wide range of critical industries. Prior to Darktrace, Calum worked within the Research and Development team at Cado Security. His experience spans sectors including manufacturing, energy, and transport infrastructure, as well as hands-on experience with Industrial control systems.
Daniel Levy is a Data Scientist within the Threat Research team at Darktrace. In this role, Daniel applies statistical and machine learning methods to large-scale security telemetry to uncover threat activity clusters and campaigns across Darktrace’s anomaly detection metadata. Daniel holds a BSc in mathematics from the University of Bath and an MSc in mathematical data science from the Technical University of Munich. His master’s thesis focused on the unsupervised analysis of high-dimensional latent representations derived from passing satellite imagery to a variety of multimodal earth observation models, demonstrating that distinct urban morphological types are encoded within these representations.
Adam Potter is a Senior Cyber Analyst at Darktrace, where he leads threat research investigations involving n-day common vulnerabilities and exposures, emerging malwares, and advanced persistent threats. His most recent work has focused on Chinese-nexus cyber operators, culminating in the release of the ‘Crimson Echo’ report in April 2026. This project featured a long-term retrospective study of Chinese-nexus cyber operators to identify core trends in targeting, tactics, techniques, and characteristic kill-chain elements. Adam has represented the threat analysis team as an onsite consultant during high-profile sporting events with partners such as Major League Baseball, and as a key presenter at external technical webinars hosted by Darktrace. He is skilled in delivering tactical threat-hunting sessions to technical teams and strategic threat briefings to C-level executives. He also frequently provides analytic support for incident management cases. Adam holds a bachelor’s degree from Georgetown University’s School of Foreign Service where he majored in science, technology, and international affairs. His previous academic research has explored topics at the intersection of national security and cyber power.
Emma Foulger oversees Threat Research Operations within the analyst team at Darktrace. Her work focuses on analysing and contextualising cyber threats across a global customer base, identified through anomaly-based behavioural detection, with the aim of identifying emerging trends in the cyber threat landscape and supporting actionable intelligence development in collaboration with threat intelligence partners and the wider industry. Previously she studied pure mathematics at the University of Birmingham.
Nicole Carignan is Senior Vice President, Security and AI Strategy, Field Chief Information Security Officer at Darktrace. In this role, Nicole focuses on providing technical strategic guidance and expertise in cyber security, threat research, artificial intelligence (AI), and data science to customers, partners, and organisations within Darktrace. An expert in the safe, secure, and responsible application of AI in cyber security, Nicole engages in product innovation and advisory, thought leadership, research, and cyber security and AI community engagement to ensure Darktrace delivers solutions that meet customers’ evolving needs. Her insights have been cited by global cyber security publications, and she is a frequent speaker at industry conferences and professional associations such as Women in Data Science, AUSA Cyberworld, ISACA Houston and more. With over 25 years’ experience, Nicole has deep expertise in data science, machine learning (ML), cyber security, threat intelligence, operations, and network engineering. Prior to Darktrace, Nicole served as the Head of North America Operations for CounterCraft Security, a leader in deception technology and threat intelligence solutions. Nicole worked in and supported the US federal government for over 20 years, serving in multiple technical and operational roles for the Intelligence Community and US Department of Defense, and consulted on multiple large-scale data science efforts.