About

What I do

Security systems that reason over graphs of trust, at work and in research.

I build security systems that reason over graphs of trust. At Cohesity that means detecting attacks on enterprise identity systems and working out how far an attacker can get. In my own research it means working out which AI models are tainted once one of their ancestors is found compromised, and which of them can still be saved. Different domains, same shape of problem.

Worked at

Identity threat detection

Detection and response across Entra ID, Okta, Ping and Active Directory, and attack-path analysis: modeling the relationships between accounts, groups, roles and machines as a graph, and asking what is reachable from a foothold.

Cohesity, now

AI supply chain recovery

The half of AI supply chain security that follows a detection. A formal model of how compromise propagates through model lineage, a blast-radius query that is provably a lower bound, and a planner that says what can be rolled back. Published as a preprint with code that reproduces every number.

Independent research, 2026

Cloud infrastructure at scale

Governance-critical services inside AWS License Manager: cross-region license visibility for enterprise and federal customers, an event-driven sweeper that reclaims dangling resources, and a statistical anomaly detector running at 87 percent alert precision.

AWS, 2025 to 2026

Open source

Upstream contributions to StackStorm, twice, from two different employers. The research implementation is public under Apache-2.0, and the paper is CC BY, because work that cannot be checked is not finished.

github.com/apoorve1577

Now
Software Engineer III, Security, Cohesity
Working on next
Measuring real model lineage at hub scale
Education
M.S. Computer Science, UNC Charlotte. B.E., Thapar Institute. Details
Reach me
apoorve1577@gmail.com