Rubén Díaz.

Available for CTI roles

I monitor the dark web, fraud campaigns and threat actors, and turn what I find into intelligence that decision-makers can use.

Málaga, Spain · Remote across the EU · EN/ES

01

Analyst
assessment

Two years and counting inside one of Europe's largest cybersecurity operations, across threat intelligence, digital risk protection and anti-fraud. Promoted twice in under two years. Today I am the intelligence point of contact for enterprise organizations, from eliciting requirements to delivering the finished product.

Key judgments

  • KJ-1Collection is the cheap part. The value is in finished analysis that people can act on.
  • KJ-2The dark web rewards patience and method over tooling. I bring both, plus Python to automate the repetitive parts.
  • KJ-3Bilingual reporting in English and Spanish, fully remote, for technical and executive audiences.

02

Service
record

2026

→ Present

Threat Intelligence Analyst II · Digital Risk Protection

Intelligence point of contact for enterprise organizations: eliciting intelligence requirements, running OSINT investigations, and delivering tailored threat and vulnerability reporting.

2025

→ 2026

Digital Risk Protection & Anti-Fraud Analyst

Open, deep and dark web monitoring to detect phishing, fraud, brand abuse and credential exposure. Coordinated domain and social-media takedowns, and built Python automation for collection and reporting.

2024

Threat Intelligence Analyst · Financial sector project

Embedded analyst supporting a bank's SOC: IOC triage, MITRE ATT&CK mapping, and daily threat bulletins.

03

Tradecraft

CTI craft
PIRs and the intelligence lifecycle, threat actor profiling, ransomware tracking, finished reporting, structured analytic techniques.
Collection
OSINT and SOCMINT, Tor, paste sites, criminal forums and markets, dark web investigations.
Platforms
OpenCTI, Cybersixgill, TIP administration.
Automation
Python, Git, Linux, LLM-assisted analysis.
Frameworks
MITRE ATT&CK, Diamond Model, Cyber Kill Chain.

04

Sample
products

RPT-2026-07 · Ransomware

What ten months of leak-site data say about The Gentlemen's operational tempo

618 victim posts, one backend leak, and what publishing cadence reveals about a ransomware operation's health.

Read →

In preparation · Anti-fraud

Coming soon.

A walkthrough of identifying, attributing and dismantling a credential-harvesting campaign.

Certifications: CrowdStrike Falcon Intelligence Specialist · Intro to SecOps (Palo Alto Networks) · more on request.

Section 05 · Contact

Let's talk.

Hiring for CTI, digital risk or anti-fraud? My inbox is open. CV and references on request.

PGP: 448F BA79 93F5 52DA C189 045E F252 E3B9 8CD2 FFC2