RomHack Camp 2026

From IOC to Detection: Turning Threat Intelligence Into Something Your SOC Can Actually Use
2026-10-03 , WORKSHOP 1 (Neon Genesis Exploitation)
Language: English

Threat intelligence teams collect indicators, follow threat actors and produce reports. SOC teams build detections and investigate alerts. Too often, the connection between the two ends with a list of IP addresses, domains and hashes added to a SIEM.

This talk looks at how to move beyond that model.

Using practical attack examples, I'll walk through how intelligence can be transformed from an IOC or threat report into an investigative hypothesis, observable attacker behaviour and ultimately a detection. We will look at what information gets lost when intelligence is reduced to indicators, how to identify the behaviour behind those indicators, and how to decide which telemetry can actually expose it.

The session follows a simple workflow:

Threat Intelligence → Adversary Behaviour → Detection Hypothesis → Telemetry → Detection → Hunt → Validation

I'll also cover what happens after a detection fires: how investigation results can feed back into threat intelligence, improve context and help identify what should be hunted for next.

The goal is not to collect more intelligence or generate more alerts. It is to make threat intelligence operational enough to change what your SOC can detect.

An IOC may tell you what the attacker used. A good detection should help you find what the attacker did.

Sanjay Kumar is Head of Security Operations & Threat Intelligence at EYKON, where he leads security operations, threat detection, incident response, and threat intelligence. With more than a decade of experience in cybersecurity, his work focuses on detection engineering, threat hunting, identity-driven attacks, incident response, and translating threat intelligence into actionable defenses. Sanjay is an international cybersecurity speaker who has presented at security conferences and industry events across Europe and the United States, including DeepSec in Vienna, the ICS Cyber Security Conference in Atlanta, Recorded Future PREDICT, Next IT Security in Stockholm, and CrowdTour Helsinki. He is the recipient of multiple cybersecurity and research recognitions, including the Recorded Future Excellence Award for Innovation in Threat Intelligence at PREDICT Europe 2025. Alongside his industry work, Sanjay is a PhD researcher exploring the application of artificial intelligence and machine learning to cybersecurity and threat detection. His interests lie at the intersection of threat intelligence, security operations, detection engineering, identity security, and emerging attacker tradecraft, with a particular focus on turning real-world attack patterns into practical detection and response strategies.