Microsoft Threat Intelligence Podcast
Hosted by Elliot Volkman
Microsoft's own threat hunters on the Blizzards, Typhoons, and crime crews they track, plus the takedowns they run.
- Level
- Practitioner, assumes you work in or study security
- Status
- Active, last episode
- Who's behind it
- Vendor-run, Microsoft sourceProduced with N2K Networks.
- Last verified
- Transcripts for every episode
Listed underThreat intel and newsSOC and blue team
Editorial take
This is primary-source threat intelligence in audio form. Microsoft tracks a huge share of nation-state and criminal activity, and the guests are usually the analysts who wrote the blog post: Forest Blizzard router abuse, the Lumma Stealer takedown, device code phishing, payroll pirates. Episodes run 25 to 50 minutes every two weeks and go further than the written reports on how actors were found and why the naming matters. Expect Microsoft framing: actor names follow Microsoft's taxonomy and Defender detections come up. The show is also in transition. Sherrod DeGrippo hosted seasons one to three and left in July 2026; Elliot Volkman hosts season four, which started in August, so the tone may shift.
Last hand-checked 2026-09-30, Host changed in 2026: Sherrod DeGrippo left in July; Elliot Volkman hosts season four.
Listen if you …
- work in a SOC or CTI team and want the analyst story behind Microsoft's threat reports
- need to map Microsoft actor names (Blizzard, Typhoon, Tempest, Sleet) to real campaigns
- defend Microsoft 365 or Entra ID and want identity attack tradecraft from the vendor that sees it
Skip if you …
- you want vendor-neutral analysis, every insight comes through Microsoft's telemetry and naming
- you are new to security, episodes assume you know what C2, loaders, and APTs are
Start with these 3 episodes
- 01
Fact vs Hype: How Threat Actors Are Really Using AI Right Now
· 42 min · Beginner
A grounded answer to the question everyone asks, from analysts who see actor behavior rather than vendor demos.
- 02
Inside Microsoft’s Global Operation to Disrupt Lumma Stealer’s 2,300-Domain Malware Network
· 45 min · Practitioner
Shows what a coordinated legal and technical takedown looks like from the inside, the show's signature topic.
- 03
Russia’s Forest Blizzard Is Abusing Home + Small Office Routers for Cred Theft
· 52 min · Practitioner
Nation-state tradecraft at its most practical: how edge devices you ignore become credential theft infrastructure.
About the show
The Microsoft Threat Intelligence Podcast is made by Microsoft and produced with N2K Networks. It launched in October 2023 with Sherrod DeGrippo, then Microsoft's director of threat intelligence strategy, as host. She left after season three in July 2026, and Elliot Volkman, a director in Microsoft Threat Intelligence, now hosts.
Episodes are conversational interviews of 25 to 50 minutes, released every two weeks. Most feature Microsoft researchers discussing a specific actor, campaign, or disruption operation, with occasional outside guests from Huntress, academia, and the conference circuit.
Notable guests
- Sherrod DeGrippo
- Mark Russinovich
- Casey Ellis
- Yonatan Zunger
- Andrew Morris
- Lauren Proehl
- Crane Hassold
Pairs with
If Microsoft Threat Intelligence Podcast works for you, these likely will too.
The Defender's Advantage Podcast
Luke McNamara
Mandiant and Google Threat Intelligence Group analysts on the intrusions they responded to, in 30 tight minutes.
Listen if you do incident response or threat hunting and want lessons from Mandiant engagements.
interviewirregular30–60mThreat Vector by Palo Alto Networks
David Moulton
Unit 42 incident responders and threat researchers explain what they saw on real engagements, in 35 minutes a week.
Listen if you want breach lessons from people who answer the incident response call.
interviewweekly30–60mResearch Saturday
Dave Bittner
One fresh threat research report a week, explained by the researcher who wrote it, in about 25 minutes.
Listen if you work in a SOC or CTI role and want the week's notable malware and campaign research.
interviewweekly<30mRisky Business
PickPatrick Gray
Weekly news + analysis show for working security professionals.
Listen if you you work in security and need a weekly news synthesis.
panelweekly60m+