Hi, I am Chintan

9 years breaking in. 5 years of building teams that catch it.

I spent 9 years as a pentester and red teamer, then moved to product companies since last 5 years to build and lead vulnerability management, threat intelligence and detection engineering teams.

Portrait of Chintan Gurjar
14 years
in cybersecurity, since 2011
2 CVEs discovered
CVE-2016-7786 (Sophos UTM) and CVE-2020-35387
Offensive & Defensive
9 years pentest and red team, then 5 years leading defensive teams
Black Hat USA 2025 Arsenal
Presented my open-source attack surface toolkit

What I bring

I have worked on both sides, attack and defense, so I can talk to the board and to the engineer at the terminal.

Builder of Security Programs

I have built and run vulnerability management, threat intelligence and detection engineering teams at large product companies across retail, automotive and fintech, and managed the MSSPs and vendors around them.

  • Program Design
  • MSSP/vendor mgmt
  • VM/CTI/ASM/VAPT/TH
  • Roadmaps & KPIs
  • Playbooks & SOPs
  • Metrics & Dashboards

Strategic Security Leader

I connect security work to business goals: 3 to 5 year roadmaps, reporting to executives and boards, and turning CISO priorities into work a team can measure.

  • 3–5 yr strategy
  • Exec/Board reporting
  • CISO Priorities
  • Risk → Business
  • Maturity Model
  • Governance

Offensive + Defensive Depth

Nine years of hands-on pentesting and red teaming, two CVEs discovered, and an offensive edge kept sharp through bug bounty, side projects and open-source tools outside my day job.

  • Pentest & Red-team
  • Adversary Emulation & Purple Teaming
  • Detection Engineering
  • Threat Intelligence & Hunting

Tech & Tools Matrix

Hands-on with the tools of pentest, red team, vulnerability management, detection engineering, threat hunting and CTI: I have assessed, deployed, integrated and used them daily.

  • BurpSuite
  • Bloodhound
  • Nmap
  • Nessus/Qualys
  • CTI Solutions
  • MITRE ATT&CK
  • Wiz
  • MS Sentinel/Defender
  • CrowdStrike
  • Docker
  • Kenna Security
  • GitHub

Things I have built

Open-source tools, dashboards and checklists. Free to use.

All projects

Threat Actor DB

Unified dashboard of APT and threat-actor groups: state sponsors, victims, sectors, timelines and searchable detail per actor.

FrogScope

External attack-surface and exposure management in one Docker container. Correlates hosts, ports, certs and DNS, ranks findings in plain English and diffs against the last scan. Successor of Frogy2.0.

Latest writing

Long-form, practical posts from the field.

All posts

Let’s connect

Questions on a post, feedback on a tool, or just want to talk security? Write to me or find me on the links here.