For security leaders
How I think about building and running security programs: structure, maturity and trade-offs.
Hi, I am Chintan
I spent 9 years as a pentester and red teamer, then moved to product companies since last 5 years to build and lead vulnerability management, threat intelligence and detection engineering teams.

How I think about building and running security programs: structure, maturity and trade-offs.
Hands-on work from both sides: detection logic, hunting methodology, tools and research.
I have worked on both sides, attack and defense, so I can talk to the board and to the engineer at the terminal.
I have built and run vulnerability management, threat intelligence and detection engineering teams at large product companies across retail, automotive and fintech, and managed the MSSPs and vendors around them.
I connect security work to business goals: 3 to 5 year roadmaps, reporting to executives and boards, and turning CISO priorities into work a team can measure.
Nine years of hands-on pentesting and red teaming, two CVEs discovered, and an offensive edge kept sharp through bug bounty, side projects and open-source tools outside my day job.
Hands-on with the tools of pentest, red team, vulnerability management, detection engineering, threat hunting and CTI: I have assessed, deployed, integrated and used them daily.
Open-source tools, dashboards and checklists. Free to use.
Unified dashboard of APT and threat-actor groups: state sponsors, victims, sectors, timelines and searchable detail per actor.
Coverage and gap assessment, CTI-to-detection mapper, detection-engineering workbench and purple-team board on ATT&CK Enterprise.
279+ reusable web, API and network test cases distilled from real HackerOne reports. Filter by category and tick as you test.
External attack-surface and exposure management in one Docker container. Correlates hosts, ports, certs and DNS, ranks findings in plain English and diffs against the last scan. Successor of Frogy2.0.
Long-form, practical posts from the field.
How Bad Is It Really? A Field Guide to Endpoint Security Severity Summary: Endpoint security findings get mis-rated in both directions - a scary-sounding privilege label …
A practical, no-BS guide based on real submissions, real rejections, and real lessons - not theory. Who is this for? If you are sitting there thinking “bug bounty is too …
If you have spent any meaningful time inside a Security Operations Centre - or have been responsible for one - you will know this feeling intimately. Alert fires. You …
Modern cars are not just machines that move you from A to B. They are packed with radios, sensors, SIM cards, Wi-Fi, Bluetooth, cloud backends, and mobile apps …
Questions on a post, feedback on a tool, or just want to talk security? Write to me or find me on the links here.
chintangurjar@outlook.com