Ankur Tyagi
ankurt.20
• 7h3rAm
• ankurstyagi
I'm an infosec enthusiast with a strong background in network security (IDS/IPS), anti-malware technologies (EDR/XDR), research methodologies and innovation.
Experience [^]
• Cisco Talos Intelligence Group
Aug/2023 - Present
• Security Research Engineer, Network Threat Detection & Response (NTDR)
(2 yrs 5 mos)
• Detection Engineering and Vulnerability Research
• Snort & ClamAV
• Qualys Inc.
Apr/2015 - Aug/2023
• Principal Engineer, Threat Research Unit (TRU)
(4 yrs 7 mos)
• Breach Simulation, Security Control Validation, Attack Surface Mapping, Asset Remediation Trendmap
• Threat Intelligence feeds evaluation and aggregation, False Positive validation, event whitelisting, risk scoring, rule parsers and converters
• MITRE ATT&CK TTP correlation (adversary killchain), quantification and scoring
• Technologies: Python, Shell, Unix, Windows, AntiMalware, Yara, IoC, EDR, XDR, Threat Intelligence
• Research Engineer, Malware Lab
(3 yrs 9 mos)
• Research towards automated aggregation of threat behavior and generic (Yara/IoC) rule creation
• Lead for multiple in-house automation projects (sourcing/filtering/scanning of malware samples)
• Juniper Networks
Apr/2012 - Feb/2015
• Security Research Engineer, Network Signatures Team
(2 yrs 10 mos)
• Maintaining in-house automation tools for coverage against multiple exploitation frameworks
• Signature development for Juniper's security portfolio devices against latest vulnerabilities and exploits
• Regular updates of active signatures to increase accuracy and coverage against evolving evasion techniques
• Tech/Domain: Python, Shell, Unix, Windows, IDS, IPS
• SecurView Systems
Dec/2010 - Apr/2012
• Information Security Engineer, IntelliShield Alert Manager Team
(1 yr 4 mos)
• Vulnerability Researcher / Security Analyst for the Cisco Security IntelliShield Alert Manager Service
• Active member of the Secur-I Research Group with monthly publication of critical vulnerability assessments
• Tech/Domain: Python, Shell, Unix, Windows, Vulnerability Research
Research [^]
Dec/2021
Apr/2019
Media [^]
• Hackers of India, Hacking Archives of India
Oct/2020
Sep/2017
• Visual network and file forensics with Rudra, HelpNet Security
Sep/2017
• Rudra - Framework for inspection of network capture files, HelpNet Security
Sep/2015
• Network Sorcery with ChopShop and Libemu, PenTest Magazine
Mar/2014
Talks [^]
• svachal + machinescli
These tools are useful for creating and learning from CTF writeups
13/Aug/2022
• Breach and Attack Simulation
Automated simulation of adversary TTPs mapped to MITRE ATT&CK framework
14/Nov/2018
• Angad - Malware Detection using Multi-Dimensional Visualization
Angad is a tool that can perform visual malware clustering using Hilbert Curves
13/Oct/2018
14/Sep/2018
07/Sep/2018
11/Aug/2018
• Visual Network and File Forensics
This presentation showcases the effectiveness of visual tooling for malware and file-format forensics
29/Jul/2017
(could not attend)
• Rudra - The Destroyer of Evil
Rudra provides a framework for exhaustive analysis of PCAP and PE files
06/Aug/2016
03/Aug/2016
31/Mar/2016
13/Nov/2015
08/Aug/2015
05/Aug/2015
• Flowinspect - Network Inspection Tool on Steroids
Flowinspect is a tool for network monitoring and inspection purposes
06/Aug/2014
14/Feb/2014
Portfolio [^]
• Citations: 158
• h-index: 7
• i10-index: 4
💻 GitHub
• Rank: S (top 25%)
• Commits: 14.3k
• Followers: 179
• Pull Requests: 18
• Stars: 402
• Languages: javascript/html/python/c++/c
• Reputation: 1915
• Impact: ~634k people reached
• Badges: gold:2/silver:16/bronze:18
Certifications/Academics [^]
Nov/2024
Aug/2022
Mar/2012
• M.Tech Software Systems, BITS-Pilani
Dec/2014
• BE Information Technology, Pune University
Jul/2010