Episode 17: How Cyber Threat Hunters Think | Joe Slowik of Dataminr on Threat Intel, Detection Engineering & Cyber Warfare
Recorded live at the RSA Conference, this episode of the THREATCON1 Podcast features a deep-dive conversation with Joe Slowik — one of the cybersecurity industry’s leading voices in cyber threat intelligence, detection engineering, and adversary operations.
Hosted by Patrick Garrity and Kimber Duke from VulnCheck, the discussion explores how modern threat actors operate, why most organizations still struggle with cybersecurity fundamentals, and how defenders can build stronger, intelligence-driven security programs.
ABOUT OUR GUEST:
Before joining Dataminr, Joe held cybersecurity and threat intelligence roles across government and industry, including work with Dragos, Gigamon, Huntress, and MITRE. His background spans Navy cyber warfare operations, incident response, threat hunting, intrusion analysis, and large-scale detection engineering.
In this episode, the conversation covers:
* How cyber threat intelligence actually supports real security outcomes
* Why detection engineering is becoming essential for modern security teams
* The mindset defenders need to think like attackers
* Lessons from the Black Basta ransomware chat leaks
* Threat hunting methodologies and operational security practices
* VPN abuse, proxy infrastructure, and telecom compromise risks
* Why healthcare and manufacturing continue to be high-risk targets
* How attackers prioritize targets using sales and marketing-style tactics
* The future of cybersecurity talent, hacker culture, and defensive operations
* Why strong cybersecurity still comes down to fundamentals and operational discipline
Whether you work in a SOC, lead a security team, build detection content, hunt threats, or simply want to better understand how modern cyber adversaries operate, this episode delivers practical insights from leaders working on the front lines of cybersecurity.
Dataminr uses AI and real-time event discovery to help organizations detect emerging risks, cyber threats, geopolitical events, and breaking incidents faster — enabling security teams to respond before threats escalate.
VulnCheck provides exploit and vulnerability intelligence designed to help organizations prioritize real-world threats, understand exploitation activity, and stay ahead of emerging vulnerabilities before attackers weaponize them.