CISA KEV Parity Check
A project focused on ensuring parity with CISA's Known Exploited Vulnerabilities catalog.
Senior Threat Security Researcher & DFIR Consultant
Abdelrahman Esmail is a senior threat security researcher with over 7 years of experience in incident response, threat analysis, and network signature rules. He has a proven track record in managing large-scale projects from both threat analysis and R&D perspectives, with expertise in customer handling and C-level board presentations.
Leading and conducting detailed investigations of cybersecurity incidents across various environments, including on-premises, hybrid, and container.
Developing and refactoring threat models, tracking APT group activities, and building XDR telemetry schemas to provide comprehensive visibility and rapid coverage against zero-day attacks.
Designing, optimizing, and maintaining vulnerability network signature rules and decoders, significantly improving performance and reducing false positives.
Expertise in securing cloud and containerized environments, including building XDR telemetry for K8s, OpenShift, and ECS orchestrations, and conducting forensics in these complex systems.
A project focused on ensuring parity with CISA's Known Exploited Vulnerabilities catalog.
Developed tools for daily testing, including regression, false positive, and unit testing using Atomic-Red-Script.
Impact: Enhanced operational efficiency in testing and validation processes.
A tool or project for inspecting network traffic for security analysis.
Led detailed investigations of cybersecurity incidents and threat hunting missions as Senior DFIR Consultant at Group-IB.
Developed and refactored threat models for hybrid, on-premises, container, and cloud environments, providing 360 visibility for customers.
Optimized vulnerability network signature rules, achieving a 20% performance improvement and 35% reduction in false positives.
Co-ordinated the GGC region as a Systems Engineer, contributing to a $7.5 million deal and generating $3M in new revenue.
Completed a Cybersecurity Specialization at the University of Maryland, building a project to apply Cryptanalysis techniques.