DURGESHGAURAV CTI RESEARCH & ARCHITECTURE
CONTACT
CYBER THREAT INTELLIGENCE RESEARCHER & ARCHITECT

Durgesh Gaurav

Cyber Threat Intelligence professional with 12 years of overall security and engineering experience (8+ years specializing in CTI and 4 years in Software Engineering). Expert in adversary tradecraft, AI security threat mapping (MITRE ATLAS, OWASP Top 10 LLM), quantum risk frameworks, honeynet architecture, and autonomous SOAR detection engineering.

8+ Yrs
Threat Intel Specialization
12 Yrs
Total Security & Tech
4 Yrs
Software Engineering
Parker, CO
Primary Location
CTI Domain Coverage v3.2
Adversary Tracking & CTI STIX / TAXII
AI & Quantum Threat Research ATLAS / OWASP
Supply Chain & Honeynets 3rd-Party Risk
Detection Content Dev YARA / Sigma
REAL-TIME THREAT INTELLIGENCE FEED

Global Cyber Threat Dashboards & Advisory Stream

Live aggregated intelligence updates curated from verified industry-leading security sources and forensic blogs.

Status: Active Stream
Mandiant Security Blog 2 hrs ago

Nation-State APT Campaign Targets Cloud Infrastructure via OAuth Token Manipulation

New forensic evidence highlights advanced persistent threat persistence mechanisms utilizing compromised service principals in Azure AD.

Severity: CRITICAL Read Advisory ↗
The Hacker News 4 hrs ago

Zero-Day Remote Code Execution Vulnerability Discovered in Popular Enterprise Gateway

Active exploitation in the wild observed targeting unpatched perimeter appliances. Emergency patching recommended immediately.

Severity: HIGH Read Advisory ↗
The DFIR Report & Diva 6 hrs ago

From Phishing to Ransomware in 43 Minutes: An In-Depth Execution Analysis

Detailed telemetry breakdown tracking rapid lateral movement using PsExec, compromised domain admin accounts, and customized loader scripts.

Severity: HIGH Read Report ↗
Microsoft Security Blog 9 hrs ago

AI-Driven Threat Intelligence: Tracking LLM Prompt Injection and Agentic Exploits

Insights into emerging MITRE ATLAS attack vectors targeting enterprise copilot pipelines and automated AI agent workflows.

Severity: MEDIUM Read Blog ↗
Dark Reading 12 hrs ago

Supply Chain Risks in Open-Source Python & Node.js Repositories Surge

Malicious typosquatting packages detected targeting developer CI/CD build pipelines with credential harvesters.

Severity: HIGH Read Article ↗
EC-Council Forensics 1 day ago

Advanced Memory Forensics: Uncovering Fileless Malware Artifacts in RAM

Step-by-step methodology using Volatility 3 to extract injected DLLs and hidden network connections from volatile memory.

Severity: INFORMATIONAL Read Guide ↗
CTI CORRELATION TABLE

Threat Intelligence Research Matrix

Search, filter, and sort a portfolio demonstration dataset derived from the threat-feed cards above. This table is a UI/data-model demonstration, not a claim of live telemetry.

RECORDS
0
HIGH+
0
VISIBLE
0
Reference
Mandiant OAuth token manipulation in cloud infrastructure Cloud CRITICAL Valid Accounts / Service Principals Threat Intel ↗
The Hacker News Enterprise gateway RCE / perimeter exploitation Cloud / Edge HIGH Exploit Public-Facing Application News ↗
The DFIR Report Phishing-to-ransomware execution chain Endpoint / DFIR HIGH Phishing / PsExec / Lateral Movement DFIR ↗
Microsoft Security LLM prompt injection and agentic exploitation AI Security MEDIUM Prompt Injection / Agentic Abuse MS Security ↗
Dark Reading Open-source Python / Node.js supply-chain risk Supply Chain HIGH Typosquatting / Dependency Abuse Dark Reading ↗
EC-Council Fileless malware artifacts in RAM Memory Forensics INFO Memory Injection / Hidden Connections Forensics ↗
INTERACTIVE TRAINING & RANGE

Durgesh's Cyber Threat Arcade & Range

Play the new Dot/Packet Catcher game, navigate 10 expanded CTI trivia questions, validate YARA rules, or solve IR scenarios!

Cyber Points (CP) 0 PTS
Streak 0 🔥
Catch the Malicious Packets! (Avoid Benign Blue Packets) Time Left: 30s

Malicious Packet Interception Challenge

Click on falling/appearing red malicious packets (+100 CP) while avoiding blue benign packets (-50 CP)!

Game Score: 0
BREAK ROOM / NOT JUST CYBER

Fun Games for Everyone

No cybersecurity knowledge required. Two quick browser games with local high scores.

TIP // Try the reflex game, then challenge your memory.
GAME 01

Reflex Rush

BEST
-- ms

Wait for the circle to turn green, then click it as fast as possible.

GAME 02

Memory Match

MOVES
0
Match all 4 pairs.
Games use local browser storage only for personal best scores.

Security Lore & Fun Facts

Loading security facts...

Updated dynamically from security archives.
RESEARCH BLOG & LAB NOTES

CTI Research Focus

Interactive portfolio notes covering adversary tracking, emerging AI threats, supply-chain intelligence, honeynet research, CTI standards, and detection engineering.

CTILAB NOTE 01

Building an Adversary Tracking Pipeline

A practical model for collection, normalization, enrichment, correlation, confidence scoring, and dissemination across actors, IOCs, TTPs, infrastructure, and campaigns.

AI SECURITYLAB NOTE 02

Operationalizing AI Threat Intelligence

Map LLM threats and agentic abuse into intelligence workflows using ATT&CK/ATLAS concepts, telemetry, detection engineering, and human validation.

DETECTIONLAB NOTE 03

From CTI Findings to Detection Content

Turn adversary research into YARA, Sigma, hunting logic, and validation scenarios that can move from intelligence to SOC action.

PLATFORMSLAB NOTE 04

Designing a CTI Knowledge Graph

Connect actors, malware, infrastructure, vulnerabilities, victims, campaigns, and TTPs through structured intelligence objects and graph relationships.

CTILAB NOTE 05

Supply-Chain Intelligence as an Early Warning Layer

Correlate dependency risk, malicious packages, vendor infrastructure, exposed services, and internal telemetry to identify emerging third-party threats.

PLATFORMSLAB NOTE 06

Honeynets for Adversary Discovery

Use controlled deception environments to capture tradecraft, tooling, infrastructure indicators, and behavioral telemetry for research and detection.

cti-terminal@durgesh-gaurav:~
Durgesh Gaurav Threat Intel Console [Version 3.2.0]
Type 'help' to view available terminal commands or select chips below.
All feeds online. Threat database synchronized.
$
CAREER TRAJECTORY

Professional Timeline

LATEST ROLE

Threat Intelligence Researcher

Dish Network (An EchoStar Company) • Littleton, CO

Aug 2024 – Present

Key Responsibilities:

  • Directed end-to-end intelligence lifecycle operations covering adversary research, all-source collection, IOC lifecycle management, campaign analysis, and finished intelligence dissemination to SOC, DFIR, detection engineering, and C-suite stakeholders across 5+ concurrent threat domains.
  • Architected automated ETL pipelines for data ingestion, enrichment, normalization, and operationalization. Consolidating commercial feeds, OSINT, dark web, partner sharing, and internal telemetry into a single intelligence workflow, materially reducing analyst manual workload and accelerating time-to-detection.
  • Identified AI security and quantum security as critical unaddressed threat domains; recommended formalizing both as dedicated research functions and built them from scratch using MITRE ATLAS, NIST AI RMF, and OWASP for LLM as the analytic foundation.
  • Established 3 formal external intelligence-sharing partnerships; coordinated information sharing with public and private sector partners, ISACs, and government contacts to expand collective threat visibility.
  • Integrated LLM-augmented pipelines into collection, enrichment, and report generation workflows; served as internal SME for AI-driven intelligence operations, cutting report production time significantly and improving analytic throughput.
  • Authored and delivered executive-level threat intelligence briefings and all-source intelligence reports to C-suite, legal, and operational stakeholders; maintained intelligence knowledge bases tracking multiple adversary TTP profiles, detection coverage gaps, and mitigation recommendations.
  • Mentored analysts on structured analytic techniques, intelligence tradecraft, and report production standards; assessed, onboarded, and governed CTI platforms and threat intelligence data products to continuously improve program maturity.
  • Directed threat hunting missions and incident support operations, pivoting across network, log, and endpoint telemetry to investigate ransomware campaigns, APTs, and targeted attacks; provided intelligence context to responders in near-real time.
All-Source Intelligence IOC Lifecycle Threat Hunting CTI ETL / Automation OSINT / Dark Web External Intelligence Sharing AI Security Quantum Security MITRE ATLAS NIST AI RMF OWASP LLM LLM-Augmented CTI Executive Intelligence Ransomware / APT Analysis

Sr. Security Engineer | Supply Chain CTI

Tesla • Fremont, CA

Jan 2023 – Jun 2024

Key Responsibilities:

  • Researched and analyzed the latest attacker techniques observed via various INTs (OSINT, SMI/SOCMINT, TECHINT) and prescribed actions that resulted in improved security.
  • Collaborated with cross-functional teams to improve the organization's security posture and implement countermeasures based on research findings.
  • Researched and responded with actions on supply chain cyber threats involving internal and external security infrastructure.
  • Identified potential IOCs, developed hypotheses, mentored, and hunted for potential threats.
  • Produced and briefed threat reports and shared them with concerned stakeholders on daily, weekly, and monthly basis, highlighting major threats and vulnerabilities with security recommendations.
  • Provided detection and response using various security monitoring and automation tools including SIEM, SOAR, EDR, and related security tooling.
  • Conducted in-depth investigation of alerts; analyzed and correlated network traffic, OS, and application-level events/logs; performed threat hunting activities for potential incidents.
  • Prioritized threat alerts to conduct investigations based on threat severity.
  • Performed Threat Modeling to assess security posture and provide action-based recommendations.
  • Analyzed and extracted IOCs to trace threat infrastructure and malicious toolkits.
  • Captured malware and performed analysis to identify malware capabilities.
  • Created new and maintained existing security operation standards, procedures, and playbooks to investigate.
  • Analyzed security events, logs, and reported on threats and incidents across various platforms and environments.
  • Continuously tuned and improved existing security signals, detection rules, and alerts to improve detection and response time and reduce incident impact.
Supply Chain CTI OSINT / SMI-SOCMINT / TECHINT IOC / IOA Analysis Threat Hunting SIEM / SOAR / EDR Threat Modeling Malware Analysis Detection Engineering Incident Investigation Security Playbooks Threat Reporting

Threat Analyst | R&D

Fortinet • Sunnyvale, CA

Dec 2019 – Jan 2023

Key Responsibilities:

  • Researched and developed system(s) to capture active zero-day threats and assess adversary latest TTPs.
  • Monitored Dark/Deep web for sensitive information, adversary activities, and potential threats to infrastructure.
  • Leveraged MITRE ATT&CK, Diamond, Pyramid of Pain, Cyber Kill Chain, and related models for threat investigations.
  • Hunted, investigated, and identified IOCs and IOAs to identify threats and threat actor TTPs in the environment.
  • Helped improve threat detection by providing latest adversary TTPs to relevant stakeholders.
  • Leveraged OSINT, SMI/SOCMINT, and TECHINT solutions to obtain and investigate intelligence.
  • Conducted threat emulation and simulation to identify security gaps and remediated security issues.
  • Identified infection/attack vectors and assessed impact of intrusions.
  • Performed incident identification and triage and provided response to incidents.
  • Developed Digital Forensics, Network Forensics, and Incident Response plans and procedures and performed incident investigations.
  • Identified, collected, and analyzed digital evidence and conducted investigations on security incidents.
  • Performed malware analysis and analyzed threat capabilities.
  • Analyzed malicious traffic and IOCs to perform correlation to attribute threat actors.
  • Researched, analyzed, and provided reports on attacker campaigns as required.
  • Wrote YARA and Sigma rules.
  • Managed and consolidated cyber threat data sources, compiled reports, and provided regular consultation and threat briefings to stakeholders.
  • Tested and analyzed vulnerabilities reported in Fortinet products and assessed the impact of the vulnerabilities.
Zero-Day Research Dark / Deep Web MITRE ATT&CK Diamond Model Pyramid of Pain Cyber Kill Chain Threat Hunting IOC / IOA Analysis Threat Emulation Digital / Network Forensics Incident Response Malware Analysis Threat Actor Attribution YARA / Sigma Vulnerability Research

Information Security Analyst

Pacific Gas & Electric (PG&E)

2018 – 2019

Key Responsibilities:

  • Ensured customer and employee data security against threats.
  • Conducted SIEM scans and generated dashboard/reports.
  • Scanned and identified IOCs and IOAs.
  • Performed threat analysis using MITRE ATT&CK framework, Pyramid of Pain, and Diamond model.
  • Assisted Cyber Kill Chain defense against APT emulations.
  • Leveraged cyber threat modeling techniques to identify malicious threats and malicious activities.
  • Analyzed network traffic for malicious and/or abnormal activity for attack vectors.
  • Identified adversary TTPs for technical mitigation strategies to prevent, control, and isolate incidents.
  • Performed malware analysis using various malware analysis methodologies.
  • Assisted architecture design and review for CCPA integration using data anonymization.
  • Performed digital forensics to identify suspicious malicious evidence.
  • Assisted intrusion detection and prevention techniques; performed log analysis and identified malicious activities.
  • Conducted data loss prevention and implemented appropriate measures.
  • Analyzed potential security violations to identify false positives and policy violations with immediate remediations.
  • Identified vulnerabilities via penetration tests to report the issues.
  • Prioritized data loss scans on repositories based on pre-defined criteria and policies.
  • Created risk matrices as per defined guidelines.
Critical Infrastructure Security SIEM IOC / IOA Analysis MITRE ATT&CK Pyramid of Pain Diamond Model Cyber Kill Chain Threat Modeling Network Intrusion Analysis Malware Analysis Digital Forensics IDS / IPS Log Analysis Data Loss Prevention Vulnerability Assessment Risk Matrix CCPA / Data Anonymization

Sr. Software Engineer

Apace Technology

2011 – 2015
  • Engineered enterprise software applications using Java SE, JSP, Hibernate, and MySQL backend systems.
PUBLISHED BOOK

Learn How to Defend Against Cyber Crimes, In Just One Day

Authored and published in 2017, this security defense guide translates complex cyber threat vectors into practical, actionable defense frameworks for non-technical executives, organizations, and security practitioners.

READ LOCAL COPY
2017 Publication Cyber Defense Executive Friendly Local PDF Source
AUTHOR / PUBLISHED WORK
Cyber
Defense
Field Guide
MS CAPSTONE RESEARCH
Automated System & Network Self-Defense
Webster University • Honors Graduate
ACADEMIC GRAPH

Education & Honors

GRADUATE DEGREE HONORS

Master of Science in Cybersecurity

Webster University • St. Louis, MO (2016-2017)

Specialization: Emerging Threat Research, Malware Analysis, Threat Modeling, Threat Hunt, Network Defense & Incident Response, Digital Forensics

Capstone: Automated System & Network Self-Defense Architecture

UNDERGRADUATE DEGREE BE DEGREE

Bachelor of Engineering

Electronics & Instrumentation Engineering (2007-2011)

Galgotias College of Engineering & Technology

Core Focus: ICS/OT Design & Security, Signal Processing, Embedded Systems, & Hardware Design