About
Travis Green — Staff Security Researcher
I’m a staff security researcher at Corelight with 20+ years of experience in cybersecurity. My work focuses on network detection engineering — building, testing, and tuning detection rules that catch real threats on real networks.
Core Technical Focus
- Network detection engineering — Suricata and Zeek rule development, signature logic, performance tuning
- CVE research — patch-diffing, lab exploitation, exploitability assessment, detection development
- Malware analysis — threat actor TTP analysis, network indicator extraction, C2 protocol reverse engineering
- Active Directory security — SMB/LDAP/Kerberos protocol detection, lateral movement, domain attack techniques
- Threat hunting — developing and maintaining the TGI HUNT Suricata ruleset
Certifications
- CISSP (Certified Information Systems Security Professional)
- CEH (Certified Ethical Hacker)
- SANS GCIA (GIAC Certified Intrusion Analyst)
Background
I’m a former core team member of the Open Information Security Foundation (OISF), where I led Suricata training and delivered presentations internationally, including SuriCon 2017 in Prague. I have 20+ years of experience spanning government and military advisory work, enterprise security consulting, and hands-on detection engineering. I am also a former CyberPatriot Mentor.
I currently reside in Denver, Colorado.