The Defender's Advantage Podcast
Hosted by Luke McNamara
Mandiant and Google Threat Intelligence Group analysts on the intrusions they responded to, in 30 tight minutes.
- Level
- Practitioner, assumes you work in or study security
- Status
- Active, last episode
- Who's behind it
- Vendor-run, Google (Mandiant) sourceMandiant is part of Google Cloud; Google acquired it in 2022.
- Last verified
- No transcripts
Listed underThreat intel and newsSOC and blue team
Editorial take
The Defender's Advantage is the frontline view from Mandiant, now part of Google Cloud. Luke McNamara of Google Threat Intelligence Group interviews the analysts and responders behind M-Trends, the Ivanti zero-day investigations, BRICKSTORM, and the North Korean IT worker research. Episodes stay near 30 minutes and are disciplined: one topic, the evidence, the defensive takeaway. The incident response episodes on remediation, tabletop exercises, and cloud compromises are evergreen teaching material. The limitation is cadence. Releases have become irregular, with gaps of two to three months, so treat it as an archive to mine rather than a weekly habit. Google products such as Google Threat Intelligence come up, mostly as the source of the data.
Last hand-checked 2026-09-30, Irregular cadence: eight episodes in the last twelve months, the latest on 2026-08-10.
Listen if you …
- do incident response or threat hunting and want lessons from Mandiant engagements
- follow edge-device exploitation, China-nexus espionage, or DPRK operations
- want an annual M-Trends briefing in audio form
- prefer short, single-topic episodes over panel chat
Skip if you …
- you want a predictable release schedule, gaps of several months are normal
- you want broad industry news, this covers what Google and Mandiant investigated
Start with these 3 episodes
- 01
How Threat Actors Bypass Multi-Factor Authentication
· 27 min · Beginner
An accessible tour of the MFA bypass techniques responders keep finding, useful well beyond threat intel teams.
- 02
Takeaways from the 2026 M-Trends Report
· 28 min · Practitioner
The show's annual anchor: dwell time, initial access vectors, and attacker trends from a year of Mandiant engagements.
- 03
The Art of Remediation in Incident Response
· 41 min · Practitioner
Covers the part of IR most training skips, evicting the attacker for good, and it will not date.
About the show
The Defender's Advantage Podcast is produced by Mandiant, which Google acquired in 2022 and which now sits in Google Cloud. The feed dates to 2016, when it ran as FireEye's Eye on Security podcast; it took its current name and threat-research focus under Mandiant. Host Luke McNamara works in Google Threat Intelligence Group.
Episodes are interviews of 25 to 45 minutes with Mandiant consultants, Google Threat Intelligence Group analysts, Google's Threat Analysis Group, and occasional outside guests. Recurring subjects include the yearly M-Trends report, nation-state campaigns, zero-day exploitation, cybercrime, and incident response practice.
Notable guests
- Kevin Mandia
- Alejandro Mayorkas
- Sandra Joyce
- Jurgen Kutscher
Pairs with
If The Defender's Advantage Podcast works for you, these likely will too.
Microsoft Threat Intelligence Podcast
Elliot Volkman
Microsoft's own threat hunters on the Blizzards, Typhoons, and crime crews they track, plus the takedowns they run.
Listen if you work in a SOC or CTI team and want the analyst story behind Microsoft's threat reports.
interviewbiweekly30–60mThreat Vector by Palo Alto Networks
David Moulton
Unit 42 incident responders and threat researchers explain what they saw on real engagements, in 35 minutes a week.
Listen if you want breach lessons from people who answer the incident response call.
interviewweekly30–60mBehind the Binary by Google Cloud Security
Josh Stroschein
Hour-long conversations with the reverse engineers who build the tools and crack the malware everyone else studies.
Listen if you are learning malware analysis or reverse engineering and want role models and tool context.
interviewmonthly60m+Research Saturday
Dave Bittner
One fresh threat research report a week, explained by the researcher who wrote it, in about 25 minutes.
Listen if you work in a SOC or CTI role and want the week's notable malware and campaign research.
interviewweekly<30m