Rick Henderson

Threat Intelligence & Malware Analysis · Vulnerability Management · Ex-BlackBerry/Cylance PSIRT

Over 20 years in information security and IT, three of them in Product Security. I dig into malware and maldocs, prioritize vulnerabilities, and build the tooling that turns research into detections.

About

At BlackBerry, I served on the Product Security Incident Response Team (PSIRT), helping safeguard over 2 million endpoints worldwide. I investigated and wrote detections for malware including Jupyter, BlackBasta loaders, Spyboy Terminator, Emotet, GootLoader, WhisperGate, and HermeticWiper — work that shaped what I want to keep doing: researching malware and maldocs, and turning that research into detections that protect people at scale.

I prioritize vulnerabilities using CVSS scoring, CVE assessment, business impact, and exploit likelihood, using SAST tooling (Black Duck) against open-source and internally developed code. I write proof-of-concept exploits (Python, C#, C/C++) against frameworks like Metasploit, Sliver, Mythic, and Havoc, and use IDA Pro, WinDbg, and Wireshark for binary analysis. I've threat hunted live environments using SQL in Databricks, working alongside MDR analysts and Threat Research to build detections deployed to government, financial, and healthcare organizations globally.

Outside of work, I've built an automated CTI pipeline — an LLM-driven briefing bot feeding a MISP instance — and I maintain a public portfolio of YARA rules and malware analysis notes.

Featured Projects

CTI Automation Pipeline — LLM Briefings to MISP

A Telegram bot integrating an open-source LLM agent (Hermes Agent) to generate threat briefings from OSINT sources, paired with a custom script that packages links and indicators into a MISP instance — automating the workflow from collection through briefing to threat-intel-platform ingestion.

MISPLLM AgentsPythonTelegram Bot API

OSINT Persona Development for CTI Tradecraft

Research into synthetic human imagery generation applied to persona resilience — supporting the kind of sock-puppet and cover-identity work CTI researchers rely on for safe collection against threat actor communities.

OSINTGenerative AITradecraft Research

YARA Detection Rules & Malware Write-ups

Published detection rules and analysis notes covering malware families investigated professionally, including loader and wiper analysis, maldoc deobfuscation (PowerShell/JavaScript/VBA), and IOC extraction methodology.

YARAMalware AnalysisMaldocs

Experience

Security Response Analyst II — PSIRT

BlackBerry / Cylance · July 2021 – February 2025
  • Vulnerability assessment, CVSS scoring, and binary/SAST analysis defending 2M+ endpoints globally
  • Malware simulation and detection efficacy testing using Metasploit, Sliver, Mythic, and Havoc
  • Malware and maldoc research, IOC extraction, and finished intelligence production for internal stakeholders
  • Product vulnerability triage and mitigation guidance for development teams

Concierge Security Engineer 2

Arctic Wolf · August 2025 – Present
  • Managed security and risk guidance across 60 customers in North America
  • Endpoint and network security posture improvement using Sysmon, Wazuh, and Aurora Endpoint agents