Threat Research · Attack Paths · Identity Security · Detection Engineering

Lead Threat Research Engineer | Cybersecurity Researcher

Turning fragmented security signals into attack paths teams can act on.

I am a cybersecurity researcher with more than 10 years of experience across threat research, detection engineering, threat intelligence, exposure management, identity security, security operations, and incident response.

10+ years in cybersecurity04 career perspectives connected
CONCEPTUAL PATH / 01
DEFENDER VIEW

From isolated findings to connected risk

01ENTRY POINTExternal
Exposure
Risk signal
02ASSETCloud
Workload
Reachable
03RELATIONSHIPIdentity
Pivot
Privilege path
04IMPACTCritical
Asset
Business context
VALIDATED CONTROLProtection active
A conceptual security graph showing how exposure, assets, identity, and defensive controls combine into an explainable attack path. No customer data.
Exposure / risk Asset / relationship Defensive control

Connecting research, engineering, and real-world defense

My career has progressed from enterprise security operations and incident response to endpoint threat research and security-product research. Today, my work focuses on understanding how vulnerabilities, identities, assets, network relationships, threat intelligence, and defensive controls combine to create—or interrupt—real attack paths.

I enjoy working on problems where security research must become something practical: a detection, a data model, a validation method, a product capability, or a clear decision for defenders.

ABHINAV PALIWAL · CYBERSECURITY RESEARCHER
10+Years in cybersecurity
R · E · OResearch, engineering & operations
Endpoint, identity, cloud & enterprise

Depth across the modern security stack

No arbitrary percentages—just the disciplines I research, build, and connect.

01

Threat research

Cyber threat intelligenceThreat-actor & TTP analysisVulnerability researchAdversary emulationMalware behavior analysisThreat-informed detection
02

Exposure & attack paths

Attack-path modelingExposure prioritizationAsset & finding correlationNetwork reachabilityToxic-combination analysisControl-aware risk
03

Identity & cloud security

Identity exposure analysisActive Directory & Entra IDNon-human identitiesCloud security postureIdentity-to-asset relationshipsPrivilege & access paths
04

Detection & response

Detection engineeringEDR & endpoint securityThreat huntingSIEM & SOARIncident responseMITRE ATT&CKPurple teamingControl validation
05

Security engineering

Python automationREST & Graph APIsSecurity data normalizationIntegration researchData correlationResearch prototypes & POCs

Research that turns signals into decisions

Public high-level research summaries. Current product work is intentionally described without confidential implementation detail.

PROJECT THEME / 01

Exposure & attack-path research

Researching how vulnerabilities, misconfigurations, identities, reachability, privileges, and critical assets combine into meaningful attack paths—helping teams move from isolated findings to connected risk.

PUBLIC HIGH-LEVEL SUMMARY
PROJECT THEME / 02

Attack Path as Intelligence

Exploring ways to translate threat-actor behavior, vulnerabilities, and MITRE ATT&CK techniques into environment-relevant scenarios that defenders can investigate and prioritize.

PUBLIC HIGH-LEVEL SUMMARY
PROJECT THEME / 03

Identity security

Researching human and non-human identity exposure, including identity-to-asset relationships, privilege paths, ownership, authentication context, and certificate-based identities.

PUBLIC HIGH-LEVEL SUMMARY
PROJECT THEME / 04

Control-aware risk

Studying how endpoint, network, cloud, identity, and application-security controls influence whether an exposure is exploitable, detectable, preventable, or mitigated.

PUBLIC HIGH-LEVEL SUMMARY
PROJECT THEME / 05

Security data integration

Connecting asset, vulnerability, cloud, endpoint, identity, and control telemetry through consistent data models that support correlation and prioritization.

PUBLIC HIGH-LEVEL SUMMARY
PROJECT THEME / 06

Detection validation

Using threat research, adversary emulation, ATT&CK mapping, and product evaluation to identify detection gaps and improve prevention and response effectiveness.

PUBLIC HIGH-LEVEL SUMMARY

From security operations to product research

A decade-long progression across enterprise defense, endpoint research, and connected-risk innovation.

May 2024 — Present
01

Qualys

NOW

Lead Threat Research Engineer

Contributing threat-research expertise to enterprise exposure management, identity security, threat intelligence, detection research, and attack-path capabilities. The work connects real-world attacker behavior with security data, product research, correlation models, and validation approaches.

October 2021 — May 2024
02

VMware

Senior Threat Research Engineer

Conducted threat and vulnerability research for endpoint detection and prevention capabilities. Developed and refined detection logic, performed adversary emulation and gap analysis, supported MITRE ATT&CK evaluations, and researched emerging threats and zero-day exploitation.

March 2018 — October 2021
03

Crane Co.

Lead Security Analyst

Supported global security operations across incident response, endpoint and email security, threat hunting, SIEM, SOAR automation, security-process development, and evaluation of new defensive technologies.

August 2015 — March 2018
04

Atos

Security Analyst

Worked across security monitoring, network and endpoint protection, vulnerability management, security investigations, IDS/IPS operations, incident handling, and coordination with enterprise infrastructure teams.

Writing for defenders and builders

Research on evolving adversary behavior, connected risk, and practical defensive action.

Continuous learning, grounded recognition

Selected certifications and professional training.

AZ-500
Microsoft Certified

Azure Security Engineer Associate

CTIA
EC-Council

Certified Threat Intelligence Analyst

CEH
EC-Council

Certified Ethical Hacker

ITIL
Foundation

IT Service Management

PPA
Proofpoint

Email & Information Protection

CB
Carbon Black

Protection Administration

SOAR
Platform & Analyst

Professional Certifications

NSE
Fortinet

Network Security Expert 1 & 2

RECOGNITION / 2025

02

Second place, Qualys Innovation Odyssey

Recognized for a hybrid security attack-path concept connecting multiple defensive domains.

Atos

Certificate of Excellence

Recognition for initiative, process creation, documentation, and knowledge enablement.

Crane Co.

Executive appreciation

For investigation of a significant email-compromise incident.

EDUCATION

2015

PG Diploma in IT Infrastructure, Systems and Security

CDAC ACTS, Pune

2014

Bachelor of Engineering in Information Technology

Acropolis Institute of Technology and Research

Let's connect.

I'm always interested in thoughtful conversations around threat research, attack paths, exposure management, identity security, detection engineering, and the future of security products.