Continuous Threat Exposure Management Platform

Santa Clara, CA
18 years at DISA. More than 12 as CTO, leading engineering for the agency’s IT and cybersecurity mission and representing DISA across Defense and Intelligence. Now, David Mihelcic is AttackIQ’s Field CTO – Federal. Read Dave's take: attackiq.com/2026/09/22/why-…
135
AI gives attackers faster access to techniques we already know, not new ones. Verizon's DBIR: median attacker used ~15 known ATT&CK techniques. Under 2.5% were rare. Learn why defense should target chokepoints, not procedures. forbes.com/councils/forbeste… @ForbesTechCncl
118
A patched vulnerability and a proven defense aren't the same thing. AttackIQ tests controls against adversary behavior, then revalidates after every fix. That evidence now flows into Falcon Next-Gen SIEM through @CrowdStrike Project QuiltWorks. Read how: attackiq.com/2026/09/01/crow…
1
153
Your team already works in ChatGPT, Claude, Cursor, and Copilot. AVA Agentic OS runs CTEM missions from there, start to finish, and returns validated defenses, working detections, and measurable threat debt reduction. See it live at Fal.Con, booth #2305.
1
139
Our most-taken course just got rebuilt for MITRE ATT&CK v19. Foundations of Operationalizing MITRE ATT&CK: turn ATT&CK from a reference chart into a working system for prioritizing threats, building detections, and proving they hold up. Enroll: academy.attackiq.com/courses…
168
Nobody approves threat debt. It accrues from configuration drift, identity sprawl, and stale controls, then compounds into viable attack paths to assets you can't lose. Here's how to measure it and pay it down: attackiq.com/2026/08/11/thre…
1
184
DISA selected AttackIQ as DoW's enterprise AEV platform. Alongside it comes AVA Agentic OS & Watchtower. Together they put AI to work prioritizing threats and validating defenses across every Military Service, Command, and Defense Agency. Get the update: attackiq.com/resources/press…
1
215
Before ransomware encrypts a single file, it dismantles your defenses. Our research traces Nova ransomware's Microsoft Defender evasion, security tool takedowns, and shadow copy deletion—plus the AttackIQ emulation that validates these TTPs. 🔬 Details: attackiq.com/2026/07/31/anal…
2
208
AI-driven attacks are getting faster. Cyber defense needs to keep pace. AVA Agentic OS helps security teams operationalize #CTEM through autonomous cybersecurity missions. Proud to continue working with @Accenture to help orgs defend at the speed of AI. attackiq.com/resources/press…
2
192
Threats now move at machine speed. Defense finally does too. Introducing AVA Agentic OS—the first agentic operating system for CTEM. The future of cyber defense isn't more alerts or more dashboards. It's autonomous cybersecurity missions. See why → attackiq.com/2026/07/30/intr…
1
141
An AI model was told to solve an evaluation. It inferred the answer key existed elsewhere, reasoned past the sandbox built to contain it, and reached Hugging Face's production infrastructure. Scary. Here's 6 priorities to help prepare your AI agents. 👉 attackiq.com/2026/07/23/the-…
2
156
Your AI systems are already part of the attack surface. MITRE ATLAS maps how adversaries target the models, data, and pipelines behind them, using real-world research. Join AttackIQ, MITRE CTID, Fujitsu, Ensign InfoSecurity & Fortinet July 16. Register: attackiq.com/resources/webin…
3
4
141
10,000+ critical/high severity vulnerabilities surfaced in a month across 50 orgs using the same AI tool. Finding flaws stopped being the hard part. The number worth watching now is threat debt: adversary opportunity in your environment. 📖 attackiq.com/2026/07/08/find…
125
"How do I apply CTEM?" "How do I get ahead of threat debt?" "How do I get an AttackIQ shirt?" All valid questions, all answered at Booth 1957, Black Hat 2026, Aug 4-6 at Mandalay Bay. Live demos, a Superfrico dinner, and yes, shirts. Book a meeting: attackiq.com/lp/black-hat-20…
1
1
167
Everest ransomware isn't done just because a machine is powered off. It scans the ARP cache and sends Wake-on-LAN packets to wake sleeping hosts, downgrades its own encryption, kills Raccine, and blocks taskkill from SYSTEM. Full breakdown: attackiq.com/2026/07/02/ever…
1
2
293
July 16: MITRE's Center for Threat-Informed Defense walks through what's new in Secure AI, the project sharpening MITRE ATLAS™ with real research on how adversaries attack AI systems. With Fujitsu, Ensign InfoSecurity & Fortinet. 1 CPE credit. Register: attackiq.com/resources/webin…
2
118
The bar for federal cyber just went up. Showing controls exist isn't enough anymore. Agencies have to prove defenses work. July 16 in DC: a half-day Lunch & Learn with FRC, Carahsoft, Trellix & AttackIQ on closing that gap. 2 CPE credits. 👉 fedresources.com/events-civ-…
135
Your vulnerability backlog says how busy your team is. It says nothing about what an attacker can actually reach. Threat debt measures the real opportunity: the paths that lead to your critical assets. How to pay it down 👇 attackiq.com/resources/white…
141
Your AI systems are part of your attack surface. The model, training data, inference APIs, and agents are all targets. MITRE ATLAS catalogs the tactics adversaries use against AI, backed by real-world case studies. Check out all the new updates: ctid.mitre.org/blog/2026/05/…
1
120
How mature is your threat-informed defense, and where are the real gaps? Our free MITRE INFORM assessment scores you in ~10 min. Finish before July 1 and you're entered to win one of two Black Hat USA 2026 Briefings passes (up to $3,399 each). 👉 attackiq.com/inform-tool
1
72