Welcome! My name is Wade Wells, and I hunt for evil inside networks.
My dad built our first computer by dumpster diving in the early 90s, and I learned how to spell “windows” in MS-DOS before I could spell most other words. I’ve always been passionate about technology, computers, and bending the rules, so working in cyber security was pretty much always the dream. What keeps me here is the continuous hunt for knowledge, the thrill of falling down the rabbit hole, and knowing I’m helping a more significant cause.
These days I manage a threat detection engineering team. I started out in 2016 triaging alerts in a 24/7 SOC for a managed security provider, and I’ve spent the decade since doing detection engineering, threat hunting, and cyber threat intelligence — by way of a hosting provider, an energy utility, a fintech SaaS company, a Fortune 500 financial services firm, and now a security software company. If you want the formal version of all that, my LinkedIn has it.
I also teach. I wrote and run Cyber Threat Intelligence 101 for Antisyphon Training, available as a one-day or two-day class — it’s built around frameworks and the reasoning behind them rather than a tour of tools. On top of that I’m an adjunct professor at National University, and I spent two years mentoring career changers into their first security roles through Springboard.
On the community side, I sit on the board of BSides San Diego and I organize the San Diego site of DEATHcon, the hands-on Detection Engineering and Threat Hunting conference that runs every November across a couple dozen cities at once. I co-host Random but Memorable, and I turn up regularly on Talkin’ About Infosec News with the Black Hills crew.
When I’m not doing any of that, I’m probably reading something, walking the dog, or arguing with a detection rule that refuses to behave. Below you’ll find links to recordings of most of the talks, podcasts, and webcasts I’ve had the pleasure to give.
Got a detection problem, a CTI program that isn’t landing, or a conference that needs a speaker? Email me — I answer.
Cheers,
Training
- Cyber Threat Intelligence 101 — Antisyphon Training, 8 hours. Frameworks, processes, and the logic behind CTI. Includes 6-month Cyber Range access and a certificate of completion. (preview)
- Cyber Threat Intelligence 101 — 2 Day — Antisyphon Training. Same foundation, deeper dives and more lab time. Good fit for teams.
Conference Talks
- SOC Summit (2026) - Speaker, “Augmented Detection Engineering” (video)
- Wild West Hackin’ Fest, Deadwood (2024) - Closing Keynote
- Blue Team Con (2024) - Speaker with David French, “Maturing Sec-Ops with Detection as Code”
- OffensiveCon (2023) - Panelist, “Red Team Rants”
- GrimmCon (2020) - Speaker, “Mapping Your Network to MITRE ATT&CK”
- Wild West Hackin’ Fest (2020, virtual) - Speaker, “Mapping and Testing Your Network to ATT&CK with Free Tools”
- BSides San Diego - Board member and recurring speaker since 2020
- Blue Team Con speaker directory - Speaking since 2022
Podcast Appearances
- Random but Memorable - co-host, ongoing
- Talkin’ About Infosec News - regular contributor, ongoing
- Detection Engineering Dispatch (Ep. 37) - “Maturing SecOps with Detection-as-Code” - 2024
- Hacker History - “The History of Wade Wells” - 2024
- Cybersecurity Defenders (Ep. 124) - “CTI & Detection Engineering” - 2024
- Team Cymru - “Innovative Deception Strategies for Blue Teams,” Black Hat edition - 2024
- Simply Defensive (S1, Ep. 2) - “Decoding Detection As Code” - 2024, former co-host
Webcasts & Video
- Turn Cybersecurity Headlines into Action - Antisyphon Anti-Cast, 2026
- Cyber Career Secrets: Landing Big Roles & Leveling Up Your Skills - GingerHacker, 2025
- Defender Fridays - LimaCharlie, 2024
- Cyber Threat Intel Fireside - Simply Cyber, 2024
- Threat Models, Landscape, and Profiles OH MY - Antisyphon, 2024
- Innovative Deception Strategies for Blue Teams - Team Cymru, 2024
- Detection as Code (DaC) - Null:404 Cyber Security, 2023
- Getting Started with CTI - Antisyphon, 2023
- Triad of Success: Education, Experience, and Networking - Antisyphon Anti-Cast, 2022
- Breaking Into Cybersecurity - 2022
Writing
I’ve written an article for four of Black Hills InfoSec’s Infosec Survival Guides — the community zines they hand out by the thousand at conferences. All of them are free to read.
- Threat Hunting: An Active Search for Risks - Yellow Book (PDF). (launch event)
- Detection Engineering: Stop Drowning in Alerts and Start Catching Bad Guys - Blue Book, SOC Analysts (PDF)
- Know Your Enemy: Threat Actor Standard Operating Procedure - Orange Book, Incident Response (PDF)
- Common Cyber Threats - Green Book (PDF). Written with Dieter Smith, Blake Regan, and Matthew Thomas.
Education & Certifications
- M.S. Cybersecurity - Georgia Institute of Technology (2019–2023)
- B.S. Information Technology / Cyber Security - Colorado State University, Global Campus (2017–2018)
- A.S. Information Technology - San Diego City College (2015–2016)
- Certifications: GIAC GMON, Recorded Future Certified Analyst, CompTIA CySA+, Security+, and Network+, MTA Windows Server Administration Fundamentals, ITIL Foundation, TestOut Security Pro