01
Threat research
Cyber threat intelligenceThreat-actor & TTP analysisVulnerability researchAdversary emulationMalware behavior analysisThreat-informed detection
Threat Research · Attack Paths · Identity Security · Detection Engineering
Lead Threat Research Engineer | Cybersecurity Researcher
I am a cybersecurity researcher with more than 10 years of experience across threat research, detection engineering, threat intelligence, exposure management, identity security, security operations, and incident response.
01 / About
My career has progressed from enterprise security operations and incident response to endpoint threat research and security-product research. Today, my work focuses on understanding how vulnerabilities, identities, assets, network relationships, threat intelligence, and defensive controls combine to create—or interrupt—real attack paths.
I enjoy working on problems where security research must become something practical: a detection, a data model, a validation method, a product capability, or a clear decision for defenders.
02 / Areas of expertise
No arbitrary percentages—just the disciplines I research, build, and connect.
03 / Selected work
Public high-level research summaries. Current product work is intentionally described without confidential implementation detail.
Researching how vulnerabilities, misconfigurations, identities, reachability, privileges, and critical assets combine into meaningful attack paths—helping teams move from isolated findings to connected risk.
PUBLIC HIGH-LEVEL SUMMARYExploring ways to translate threat-actor behavior, vulnerabilities, and MITRE ATT&CK techniques into environment-relevant scenarios that defenders can investigate and prioritize.
PUBLIC HIGH-LEVEL SUMMARYResearching human and non-human identity exposure, including identity-to-asset relationships, privilege paths, ownership, authentication context, and certificate-based identities.
PUBLIC HIGH-LEVEL SUMMARYStudying how endpoint, network, cloud, identity, and application-security controls influence whether an exposure is exploitable, detectable, preventable, or mitigated.
PUBLIC HIGH-LEVEL SUMMARYConnecting asset, vulnerability, cloud, endpoint, identity, and control telemetry through consistent data models that support correlation and prioritization.
PUBLIC HIGH-LEVEL SUMMARYUsing threat research, adversary emulation, ATT&CK mapping, and product evaluation to identify detection gaps and improve prevention and response effectiveness.
PUBLIC HIGH-LEVEL SUMMARY04 / Career journey
A decade-long progression across enterprise defense, endpoint research, and connected-risk innovation.
Contributing threat-research expertise to enterprise exposure management, identity security, threat intelligence, detection research, and attack-path capabilities. The work connects real-world attacker behavior with security data, product research, correlation models, and validation approaches.
Conducted threat and vulnerability research for endpoint detection and prevention capabilities. Developed and refined detection logic, performed adversary emulation and gap analysis, supported MITRE ATT&CK evaluations, and researched emerging threats and zero-day exploitation.
Supported global security operations across incident response, endpoint and email security, threat hunting, SIEM, SOAR automation, security-process development, and evaluation of new defensive technologies.
Worked across security monitoring, network and endpoint protection, vulnerability management, security investigations, IDS/IPS operations, incident handling, and coordination with enterprise infrastructure teams.
05 / Research & publications
Research on evolving adversary behavior, connected risk, and practical defensive action.
An exploration of why cloud security must move beyond isolated findings and toward relationship-aware attack-path analysis.
Research covering Black Basta’s behavior, attack lifecycle, tactics, and practical defensive considerations.
06 / Credentials & recognition
Selected certifications and professional training.
RECOGNITION / 2025
02Recognized for a hybrid security attack-path concept connecting multiple defensive domains.
Recognition for initiative, process creation, documentation, and knowledge enablement.
For investigation of a significant email-compromise incident.
EDUCATION
CDAC ACTS, Pune
Acropolis Institute of Technology and Research
07 / Contact
I'm always interested in thoughtful conversations around threat research, attack paths, exposure management, identity security, detection engineering, and the future of security products.