Hi, I'm Gaanesh. I'm a security engineer in Singapore who breaks things on purpose, then figures out what happened.

Offensive security and digital forensics, plus the automation nobody else wants to write. Currently an Analyst at GIC on the cybersecurity technology track. Before that, agentic AI for security operations at GovTech's Cyber Security Group.

GitHub LinkedIn Blog Tools

CISSP OSCP OSWE GREM GCFA CEH CCDL2 OSAI

Worked at NUS GIC GovTech CSA HTX

Selected work

Automating the write-up nobody wants to do

GovTech · Cyber Security Group · 2026

Every DFIR investigation ends in a written report, and producing it is slow manual work that happens when an analyst is already tired. The open question was how much of an investigation an autonomous agent could reasonably carry.

  • Built a self-reporting structure that drafts investigation write-ups from findings instead of leaving it to a human at the end.
  • Researched autonomous agents for DFIR investigations: what can be delegated, where the reasoning breaks down, and which steps still need a person.

Internship work inside GovTech CSG. Implementation details stay internal.

Answering security questions in seconds, not hours

GIC · 2025

Routine security questions meant a person digging through scattered internal documentation, and cloud security requests sat in a five-day queue.

  • Built an internal RAG chatbot on an agentic architecture, so the system retrieves and reasons rather than keyword-matching.
  • Automated the manual cloud security workflows behind the queue.
  • Wired security checks into CI/CD through API integrations so problems surface at commit time.
~1 hr to ~20 s
average response time
5 days to ~2 min
cloud security SLA

Most online utilities for security work ask you to upload the very thing you are trying to keep private. I kept needing these tools and kept not trusting where the data went.

  • Built a suite of utilities that run entirely in the browser: no uploads, no server, nothing leaves the tab.
  • Self-hosted and open to anyone, so the privacy claim can be checked rather than taken on trust.

Experience

  • Cybersecurity analyst on the 2026 GPP Technology Track.
  • Agentic AI for cybersecurity operations: built a self-reporting structure for investigation write-ups, and researched autonomous agents for DFIR.
  • Part of the NUS Vulnerability Disclosure Programme, a year-long NSWS contract.
  • Tested university systems and reported through the disclosure process.
  • Built an internal RAG chatbot with an agentic architecture. Average response time dropped from ~1 hour to ~20 seconds.
  • Wrote automation that retired manual workflows, cutting SLA from 5 days to ~2 minutes on key cloud security processes.
  • Embedded security checks into CI/CD via API integrations.
  • Acquired forensic evidence (system artefacts, logs) to support root-cause analysis during cyber incidents.
  • Performed digital forensics across files, network, system logs, and memory captures to determine attack vectors.
  • Liaised with CII providers and victim entities to coordinate incident response and mitigation.

What I do

Penetration testing and vulnerability research. Digital forensics and incident response, including two years at Singapore's Cyber Security Agency reconstructing attacks from logs, memory and network captures. And lately, AI systems that do security work themselves.

Projects

  • A suite of self-hosted utilities I kept needing. Runs entirely in your browser. No uploads, no server, nothing leaves the tab.
  • Browser-only · No uploads · Privacy-first
  • Visit tools.gaanesh.com
  • A CTF focused on digital forensics and malware analysis. Won the MCI Idea! Award.
  • DFIR · Education
  • A bed-sorting algorithm built on React + AWS for hospital capacity. Reached the semi-finals.
  • React · AWS
  • Automated form-processing pipeline on React + AWS. Top-5 finalist.
  • React · AWS · Automation

Writing

Aug 7, 2026 OSAI: Did AI Actually Make Me Better at Red Teaming? Notes from the OffSec AI Red Teamer (OSAI) exam: where AI assistants helped most when I was stuck, and where they never replaced operator judgment. 10 minMay 18, 2026 payment - CDDC 2026 From zero to RCE on a custom-allocator C++ server: an Overwrite-UAF, a hand-rolled slab page-recycle attack, and a wrap-defence that only validates the start of a read. 25 minSep 28, 2025 Now that things are ending, was it worth it? Final semester thoughts: grinding, FOMO, and learning to find balance. 8 min All writing

Education

National University of Singapore B. Computing in Information Security Honours with Distinction
2023 – 2025
Singapore Polytechnic Diploma in Aerospace Electronics, Diploma+ in Aviation Management
2017 – 2020
Portrait of Gaanesh Theivasigamani

Want to talk?

Open to security work, interesting problems, or a conversation about breaking things. I usually reply within a day.