Skip to content
View gowthamaraj's full-sized avatar
Breaking
Breaking

Block or report gowthamaraj

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
gowthamaraj/README.md

Gowthamaraj Rajendran

Detection and response engineer at Meta. Before that I built detection content for Splunk Enterprise Security at Cisco.

Most of my work sits in the detection lifecycle: getting telemetry from cloud, endpoint, DNS, and identity sources into something usable, writing detections that map to ATT&CK, and building the automation that gets an analyst from alert to answer faster. Lately that includes figuring out how to detect AI agents attacking infrastructure at machine speed, which turns out to be a genuinely new problem, not just a faster version of the old one.

A few things worth knowing:

  • I own 90+ production detections at Meta across cloud, DNS, endpoint, and AI agent surfaces, with full ATT&CK TTP coverage.
  • Before Meta, I wrote 100+ detections for Splunk Enterprise Security, published to the Security Content library and running in production at thousands of companies.
  • DEF CON speaker three years running: Cloud Village 2025 on cross cloud detection and response, Cloud Village 2026 on detecting AI autonomous cloud compromise at non human identity scale, and Red Team Village 2026 running "Zero Signal: Operating Where Defenders Can't See," a hands on tactic table on cloud intrusions that leave zero endpoint telemetry.
  • Also spoke at fwd:cloudsec NA 2023 on Sigma based detection engineering.
  • 5 published CVEs, and hall of fame credits from Walmart, the UN, and American Express.
  • MS in Information Security, Carnegie Mellon University.
  • OSCE3, OSEP, OSWE, OSED, OSCP, OSWA, SSCP, CCNA.

Links: LinkedIn | Blog | Google Scholar (200+ citations)


Featured

Project What it is
OSINT-Explorer Modernized OSINT framework with a hierarchical, YAML configured tool catalog and interactive visualization
MultiBurst Distributed scanning infrastructure that orchestrates large scale content discovery across ephemeral droplets via Ansible/Terraform
zoom-scraper Forensic artifact collection tool for video conferencing software
CodeWhisper Pulls developer comments and notes left behind in deployed web content
shodan-autobot Shodan API automation for attack surface enumeration

Pinned Loading

  1. OSINT-Explorer OSINT-Explorer Public

    New-Generation OSINT Framework

    JavaScript 25 2

  2. MultiBurst MultiBurst Public

    When one instance just isn't enough!

    Python 1

  3. zoom-scraper zoom-scraper Public

    I build the “Zoom Scraper” tool which can collect user data, recordings, chat time, and configurations automatically and help forensic investigators.

    Python

  4. shodan-autobot shodan-autobot Public

    A python script which can harness the power of shodan API for better efficiency.

    Python

  5. CodeWhisper CodeWhisper Public

    Extracting silent "whispers" or notes left behind in the code

    Python 1