Building an Adversary Tracking Pipeline
A practical model for collection, normalization, enrichment, correlation, confidence scoring, and dissemination across actors, IOCs, TTPs, infrastructure, and campaigns.
Security news, advisories, and investigative feeds.
Click chart segments to inspect dataset provenance.
Read the 2017 cyber-defense book from the local PDF.
Casual games for visitors who do not live in a SOC.
Cyber Threat Intelligence professional with 12 years of overall security and engineering experience (8+ years specializing in CTI and 4 years in Software Engineering). Expert in adversary tradecraft, AI security threat mapping (MITRE ATLAS, OWASP Top 10 LLM), quantum risk frameworks, ICS/OT and SCADA security, honeynet architecture, and autonomous SOAR detection engineering.
A continuously refreshed innteligence signal belt. Provides headlines that matters; clicking an item takes the visitor to the original publisher.
A live vendor-sourced cyber-threat visualization is embedded below. The map reflects the provider's telemetry and sampling rather than every attack on the Internet.
Interactive portfolio notes covering adversary tracking, emerging AI threats, supply-chain intelligence, honeynet research, CTI standards, and detection engineering.
A practical model for collection, normalization, enrichment, correlation, confidence scoring, and dissemination across actors, IOCs, TTPs, infrastructure, and campaigns.
Map LLM threats and agentic abuse into intelligence workflows using MITRE ATT&CK / MITRE ATLAS concepts, telemetry, detection engineering, and human validation.
Turn adversary research into YARA, Sigma, hunting logic, and validation scenarios that can move from intelligence to SOC action.
Connect actors, malware, infrastructure, vulnerabilities, victims, campaigns, and TTPs through structured intelligence objects and graph relationships.
Correlate dependency risk, malicious packages, vendor infrastructure, exposed services, and internal telemetry to identify emerging third-party threats.
Use controlled deception environments to capture tradecraft, tooling, infrastructure indicators, and behavioral telemetry for research and detection.
This is the operating loop behind the portfolio: collect external and internal signal, correlate it into an analyst-readable threat picture, operationalize the finding into hunts and detections, brief decision-makers, then feed the outcome back into collection. The loop is presented as a system model here; the surrounding sections provide the live evidence and research artifacts.
The live demo starts with publisher RSS/Atom feeds and advisories; the operating model extends to OSINT, dark web, partner intelligence and internal security telemetry.
SYSTEM STAGE · EVIDENCE SHOWN ELSEWHEREAnalyst lenses group current reporting into operational questions, then connect evidence to MITRE ATT&CK, MITRE ATLAS, MITRE FIGHT, Malware Analysis, Threat Hunting, and ICS/OT or SCADA context.
SYSTEM STAGE · EVIDENCE SHOWN ELSEWHERETranslate intelligence into detection content, data pivots, hunting hypotheses, YARA/Sigma logic, SIEM/SOAR/EDR workflows and response priorities.
SYSTEM STAGE · EVIDENCE SHOWN ELSEWHERETurn the current signal into a concise decision artifact: what was observed, why it matters, what evidence supports it, and which operational lane should inspect it next.
SYSTEM STAGE · EVIDENCE SHOWN ELSEWHEREA compact view of the analytic frameworks, investigative methods, and detection tradecraft used across the roles and research material in this portfolio — including MITRE ATT&CK, MITRE ATLAS, MITRE FIGHT, ICS/OT and SCADA security.
A connected source desk for established security publishers, advisories, and a traceable correlation register. Publisher tabs now isolate both the dashboard card and the matching research-matrix record.
New forensic evidence highlights advanced persistent threat persistence mechanisms utilizing compromised service principals in Azure AD.
Active exploitation in the wild observed targeting unpatched perimeter appliances. Emergency patching recommended immediately.
Detailed telemetry breakdown tracking rapid lateral movement using PsExec, compromised domain admin accounts, and customized loader scripts.
Insights into emerging MITRE ATLAS attack vectors targeting enterprise copilot pipelines and automated AI agent workflows.
Malicious typosquatting packages detected targeting developer CI/CD build pipelines with credential harvesters.
Step-by-step methodology using Volatility 3 to extract injected DLLs and hidden network connections from volatile memory.
Use Talos research for technical threat intelligence, indicators, malware analysis, and campaign reporting.
Follow actor activity, intrusion tradecraft, identity threats, cloud security, and response research.
ESET research combines accessible explainers with technical campaign and malware analysis.
Unit 42 brings threat research and incident-response reporting, including actor tracking and technical investigations.
Long-form investigative reporting adds context around people, infrastructure, criminal ecosystems and operational risk.
Official U.S. government reporting for advisories, current cyber activity, guidance and security initiatives.
A compact correlation register tied to the source desks above. Use the same publisher tabs to isolate both the dashboard card and its matching research record; search, filter, and sort the demonstration dataset here.
| Reference | |||||
|---|---|---|---|---|---|
| Mandiant | OAuth token manipulation in cloud infrastructure | Cloud | CRITICAL | Valid Accounts / Service Principals | M-Trends 2025 ↗ |
| The Hacker News | Enterprise gateway RCE / perimeter exploitation | Cloud / Edge | HIGH | Exploit Public-Facing Application | News ↗ |
| The DFIR Report | Phishing-to-ransomware execution chain | Endpoint / DFIR | HIGH | Phishing / PsExec / Lateral Movement | DFIR ↗ |
| Microsoft Security | LLM prompt injection and agentic exploitation | AI Security | MEDIUM | Prompt Injection / Agentic Abuse | MS Security ↗ |
| Dark Reading | Open-source Python / Node.js supply-chain risk | Supply Chain | HIGH | Typosquatting / Dependency Abuse | Dark Reading ↗ |
| EC-Council | Fileless malware artifacts in RAM | Memory Forensics | INFO | Memory Injection / Hidden Connections | Forensics ↗ |
This is the analysis and decision layer over the live morning brief: it reads current RSS headlines, groups them into six operational questions, surfaces the evidence an analyst would inspect, and turns one current signal into an analyst-ready decision artifact. Every original headline remains linked to its publisher; the decision panel is a portfolio triage demonstration, not automated attribution or risk scoring.
This panel uses the latest loaded morning-brief item and the same lightweight lens classifier used above. It demonstrates the handoff from reporting to action without pretending to perform attribution or automated risk scoring.
These figures are drawn from named industry reports rather than invented portfolio telemetry. Click any chart segment or bar to inspect the source, period, calculation method, and category definition.
Microsoft Digital Defense Report 2025 • Microsoft Incident Response engagements.
Microsoft Digital Defense Report 2025 • Microsoft Incident Response engagements.
M-Trends 2025 • investigations covering targeted attack activity during calendar year 2024.
Six source-linked cards currently represented in the advisory stream. This is coverage count, not global prevalence.
Published percentages are reproduced from the named reports for their stated populations and periods. Where this page displays “Other,” it is calculated as the mathematical remainder of the explicitly published categories; it is not an additional category reported by the source.
Play the new Dot/Packet Catcher game, navigate 10 expanded CTI trivia questions, validate YARA rules, or solve IR scenarios!
Click on falling/appearing red malicious packets (+100 CP) while avoiding blue benign packets (-50 CP)!
No cybersecurity knowledge required. Two quick browser games with local high scores.
Wait for the circle to turn green, then click it as fast as possible.
Loading security facts...
Dish Network (An EchoStar Company) • Littleton, CO
Tesla • Fremont, CA
Fortinet • Sunnyvale, CA
Pacific Gas & Electric (PG&E)
Apace Technology
Authored and published in 2017, this security defense guide translates complex cyber threat vectors into practical, actionable defense frameworks for non-technical executives, organizations, and security practitioners.
Webster University • St. Louis, MO (2016-2017)
Automated System & Network Self-Defense Architecture.
Electronics & Instrumentation Engineering (2007-2011)
Uttar Pradesh technical University
Biomimetics based autonomous robot healthcare self-driving system.
Voice processor and microcontroller based device to convert hand gestures into voice to aid speech disability.
For CTI leadership, threat research, AI security, detection engineering, collaboration, or research conversations, connect directly.
© 2026 Durgesh Gaurav. Unless otherwise indicated, the original writing, analysis, code, layout, visual design, branding, diagrams, and portfolio structure on this site are protected works. No license is granted to reproduce, republish, commercially redistribute, scrape, or create derivative works from those materials without written permission, except where applicable law permits.
Third-party publisher names, trademarks, logos, feed endpoints, article headlines, and linked materials remain the property of their respective owners. The live intelligence wire displays publisher attribution, headline, timestamp, and a direct link to the original source. Feed summaries are used for internal signal classification and are not republished in the page UI. No affiliation or endorsement is implied.
The portfolio's locally hosted publication artifact is presented as a published-work reference. Copyright in that publication remains with the applicable rights holder. Do not copy or redistribute the PDF without permission from the rights holder.
Rights or attribution questions: durgesh@durgeshgaurav.com