{"id":40147,"date":"2021-03-24T19:00:23","date_gmt":"2021-03-24T19:00:23","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=93191"},"modified":"2021-03-24T19:00:23","modified_gmt":"2021-03-24T19:00:23","slug":"how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/","title":{"rendered":"How one data scientist is pioneering techniques to detect security threats"},"content":{"rendered":"<p><em>Data science is an increasingly popular field of study that\u2019s relevant to every industry. When Maria Puertas Calvo was a student, she never imagined that one day she would pioneer data science techniques to <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/azure-active-directory-identity\/10-reasons-to-love-passwordless-8-you-won-t-get-phished\/ba-p\/2147056\" target=\"_blank\" rel=\"noopener noreferrer\">detect security threats<\/a>. She started her Microsoft career on the Safety Platform team, developing algorithms to identify Microsoft accounts that send spam emails. She then worked on machine learning to detect account compromise in real-time for Microsoft accounts.<\/em><\/p>\n<p><em>Maria now leads the data science team for <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/identity-access-management\" target=\"_blank\" rel=\"noopener noreferrer\">security in the identity division<\/a>, working on several problems: protecting users from account compromise, protecting our own infrastructure from fraud and abuse, and making sure that spammers and bots don\u2019t create accounts that will harm people or other organizations. Her work has been so critical that her team is doubling in size, expanding from Redmond to Dublin and Atlanta.<\/em><\/p>\n<p><em>In honor of Women\u2019s History Month, Alex Simons, Corporate Vice President of Identity Program Management, sat down with Maria to learn more about her groundbreaking work and inspiring story. The interview has been edited for clarity and length.&nbsp;<\/em><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"wp-image-93198 alignright\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2121\/03\/Maria-Puertas-Calvo-1.jpg\" alt=\"Maria Puertas Calvo leaning against a wall next to an open window.\" width=\"385\" height=\"514\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2121\/03\/Maria-Puertas-Calvo-1.jpg 900w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2121\/03\/Maria-Puertas-Calvo-1-225x300.jpg 225w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2121\/03\/Maria-Puertas-Calvo-1-768x1024.jpg 768w\" sizes=\"auto, (max-width: 385px) 100vw, 385px\"><\/p>\n<p><strong>Alex: Maria, how did you get into engineering?<\/strong><\/p>\n<p><strong>Maria: <\/strong>I am originally from Madrid, Spain. I was always interested in math and science. Since I was little, I was always the straight-A student\u2014really in love with numbers. When I started studying physics in high school, I knew that I wanted to have a career in science, doing something innovative.<\/p>\n<p>In Spain, you don\u2019t really leave for college. You go to class during the day, and then you go back to your parents\u2019 home at night. A really good university was only 10 minutes away from my house. It wasn\u2019t really engineering-focused, but it did have one technical school that offered electrical engineering and computer science.<\/p>\n<p><strong>Alex: What prompted you to make the transition from pure electrical engineering into something more forensics-focused and then eventually data science-focused?<\/strong><\/p>\n<p><strong>Maria: <\/strong>It was all pretty accidental, not something I had planned. I did really well in college\u2014I was first in my class. And I finished in 2010, in the middle of the Great Recession, which hit the Spanish labor market horribly. At that time, the unemployment rate was 25 percent. The lucky ones, like people in engineering, were getting job offers. But when you\u2019re in technology, the only options in Spain are to work for a consulting company or to do support or sales. There weren\u2019t any entry-level jobs in research and development.<\/p>\n<p>So, I started a master\u2019s with a group doing research on biometrics. The master\u2019s was also in computer science and very related to artificial intelligence and a lot of interconnected fields like multimedia signal processing, computer vision, and natural language processing. I did my thesis on statistics around forensic fingerprints, and the probability of a random match between a latent fingerprint found at a crime scene and a random person that could have been wrongly convicted of that crime.<\/p>\n<p><strong>Alex: So what is the likelihood of that happening?<\/strong><\/p>\n<p><strong>Maria: <\/strong>It\u2019s really, really low. But it\u2019s not zero.<\/p>\n<p><strong>Alex: Okay, that\u2019s totally fascinating! I recall that you actually did your graduate work here in the United States, right?<\/strong><\/p>\n<p><strong>Maria: <\/strong>When I finished my master\u2019s, I was dating my now-husband, who is American. And I did not want to finish the whole PhD. I wanted to go work in the industry because I had been a student for seven years already, plus the rest of my life before that. I also wanted to start a life, and not do long distance between Madrid and Washington, D.C. So, I took advantage of my scholarship to become a visiting researcher at the University of Maryland working on iris recognition biometrics. I ended up staying about nine months.<\/p>\n<p><strong>Alex: Oh, wow. My father actually got his PhD from the University of Maryland\u2014I was born there. Small world! So then, tell us how you ended up at Microsoft.<\/strong><\/p>\n<p><strong>Maria: <\/strong>I didn\u2019t find academia very rewarding. So, I said, \u201cLet\u2019s go find an industry job.\u201d I was living in the U.S. with my fianc\u00e9 on a student visa. And in the D.C. area, most technology companies are government contractors that require security clearances, which only American citizens can get. I also didn\u2019t have any industry experience whatsoever.<\/p>\n<p>I spent a couple months applying for jobs and never getting called back. Then out of the blue, I got a LinkedIn message from a Microsoft recruiter saying, \u201cHey, I have a role for a data scientist on the Safety Platform team in Seattle.\u201d And I was like, \u201cSeattle, no, no way.\u201d All I knew about Seattle is that it rains a lot, and it\u2019s on the other side of the country. And it\u2019s so far away from Spain. But my husband said, \u201cHey, you got an interview, go do it, see how it goes, you\u2019ll get to practice.\u201d<\/p>\n<p><strong>Alex: In the Safety Platform team, you did innovative work that has been the underpinnings of the success we\u2019ve had so far. Tell us a little more.<\/strong><\/p>\n<p><strong>Maria: <\/strong>I worked on machine learning to detect compromises in real-time for Microsoft accounts. When a user signed into their Outlook.com account or Xbox account, or any service Microsoft offers, we would run a machine learning (ML) model to determine if that sign-in was legitimate, or if some hacker had gotten the user\u2019s password. I was the data scientist working on training the model and improving its accuracy. Although I stopped working on it a while ago, we\u2019re still monitoring it and it\u2019s still working really well.<\/p>\n<p><strong>Alex: At the time, nobody else in the industry was succeeding at this kind of work. Today, there\u2019s a whole industry around user entity behavioral analytics, but you were one of the first in the world to do it! <\/strong><strong>I love the work your team does, Maria. I feel like you are superheroes defending the world, but I don\u2019t know that our customers have a great view into the kind of magic you do.<\/strong><\/p>\n<p><strong>Maria: <\/strong>Thanks, Alex. We use analytics and machine learning to detect bad activity in the identity ecosystem. Our goal is to protect our customers from fraud and account compromise using advanced AI techniques and data science. We come up with ways to detect malicious attacks, fraud, or account compromises among all the security data that we examine at Microsoft, which is hundreds of terabytes every day. It\u2019s a complicated problem, but it\u2019s really cool.<\/p>\n<p><strong>Alex: Some of your most innovative work recently was around <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/azure-active-directory-identity\/advancing-password-spray-attack-detection\/ba-p\/1276936\" target=\"_blank\" rel=\"noopener noreferrer\">password spray detection<\/a>. Can you tell us how having data from multiple customers enables you to detect things maybe no one else could?<\/strong><\/p>\n<p><strong>Maria:&nbsp;<\/strong>In a password spray attack, a person grabs a list of email addresses that they find or collect from a breach. And then they try a few common passwords against all those email addresses\u2014against thousands of users from thousands of organizations.<\/p>\n<p>We knew these attacks were happening to our customers, but we wanted to detect them really accurately. These attacks are spread across tons of different IP addresses and countries and proxies, so it\u2019s not easy to isolate the sign-ins that are part of an actual attack. We created a detection rule that says, \u201cOkay, we\u2019re seeing IP addresses that have a lot of failed sign-ins that all are using the same password.\u201d And then we see these attempts move to a different password.<\/p>\n<p>Doing that, we can isolate a possible attack, but there\u2019s also a lot of noise. So, one of the awesome data scientists in my team, Sergio, added a layer of <a href=\"https:\/\/securityunlockedpodcast.com\/episodes\/tackling-identity-threats-with-ai\" target=\"_blank\" rel=\"noopener noreferrer\">artificial intelligence<\/a> and trained a model with known attacks. He improved the accuracy of the initial heuristic by 50 percent.<\/p>\n<p><strong>Alex: This is such an important key set of capabilities for us. I\u2019m really excited we\u2019re growing your team. Switching gears, another thing that you and I share in common is the joy of being the parent of twins. My twins are obviously a lot older than yours, but tell us how you manage the challenge of, \u201cHey, I want to be a family person and I also want to be a real leader in the industry.\u201d<\/strong><\/p>\n<p><strong>Maria: <\/strong>I\u2019m still figuring it out! It\u2019s definitely a lot of work and you have to learn to better manage your time in order to be successful at both jobs. Luckily, Microsoft offers great parental leave that both my husband and I could enjoy (he\u2019s an engineer in Azure). I have an amazing team and they kept things running really smoothly in my absence. Also, working remotely because of the pandemic has made things easier for me. I can check on my kids in between meetings, and not having a commute gives me more time to be with my family.<\/p>\n<p><strong>Alex: The pandemic has definitely accelerated the move to remote work. As a parent, I think it\u2019s a beautiful thing to be able to manage your time and not have to worry about your location.<\/strong><\/p>\n<p><strong>So, Maria, one last question. Let\u2019s say I\u2019m a college student, or maybe I\u2019m working on my master\u2019s or PhD in data science and AI. If I wanted to come work on your team, what would you suggest I work on or think about to prepare for that kind of job?<\/strong><\/p>\n<p><strong>Maria: <\/strong>One good approach is to find an internship that has some connection between doing data science and security and fraud, even if it\u2019s just loosely related. Right now, there are so many people studying data science and machine learning, so specializing and really understanding the world of the cloud and cybersecurity is important. There are tons of resources just to learn about it, such as specific courses in cybersecurity. An internship doesn\u2019t have to be specific to hardcore security\u2014it could be fraud, like finance fraud. Anything in an adversarial-type world where you\u2019re trying to catch bad things happening would be useful. Internships are easier to get without any kind of specialization but having done an internship gives you a foot in the door for a full-time position that specializes in cybersecurity. In addition, Microsoft Security sponsors <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/03\/08\/international-womens-day-how-to-support-and-grow-women-in-cybersecurity\/\" target=\"_blank\" rel=\"noopener noreferrer\"><span data-ccp-charstyle=\"Hyperlink\">many cybersecurity educational programs<\/span><\/a><span data-contrast=\"auto\">&nbsp;and&nbsp;I would encourage women&nbsp;in&nbsp;high school&nbsp;to&nbsp;investigate&nbsp;these.<\/span><\/p>\n<h2>Learn more<\/h2>\n<p>To learn more about Microsoft Security solutions <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/solutions\" target=\"_blank\" rel=\"noopener noreferrer\">visit our website.<\/a>&nbsp;Bookmark the&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noopener noreferrer\">Security blog<\/a>&nbsp;to keep up with our expert coverage on security matters. Also, follow us at&nbsp;<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noopener noreferrer\">@MSFTSecurity<\/a>&nbsp;for the latest news and updates on cybersecurity.<\/p>\n<div class=\"interruption interruption-icon-type\">\n<div class=\"interruption-icon-container\"> <img decoding=\"async\" alt=\"Security Unlocked podcast icon displaying illustration of lock with microphone inside\" class=\"interruption-icon\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/03\/Microsoft_Security_Unlocked_300pxw-150x150.png\"> <\/div>\n<div class=\"interruption-content-wrap\">\n<h3 class=\"interruption-title\">Listen to the Security Unlocked podcast<\/h3>\n<p class=\"interruption-text\">To learn more about applying data science to cybersecurity, listen to Maria\u2019s guest appearance on the episode <em>Identit<\/em><span data-ccp-charstyle=\"Hyperlink\"><em>y Threats, Tokens, and Tacos<\/em>.<\/span><\/p>\n<p> <a class=\"interruption-link c-glyph\" href=\"https:\/\/securityunlockedpodcast.com\/episodes\/identity-threats-tokens-and-tacos\">Listen now<\/a> <\/div>\n<p><!-- .interruption-content-wrap --> <\/div>\n<p><!-- .interruption --> READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/03\/24\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Data science is an increasingly popular field of study that\u2019s relevant to every industry. When Maria Puertas Calvo was a student, she never imagined that one day she would pioneer data science techniques to detect security threats.<br \/>\nThe post How one data scientist is pioneering techniques to detect security threats appeared first on Microsoft Security. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":40148,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[347,6696],"class_list":["post-40147","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-cybersecurity","tag-identity-and-access-management"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How one data scientist is pioneering techniques to detect security threats 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How one data scientist is pioneering techniques to detect security threats 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-03-24T19:00:23+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"900\" \/>\n\t<meta property=\"og:image:height\" content=\"1200\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"How one data scientist is pioneering techniques to detect security threats\",\"datePublished\":\"2021-03-24T19:00:23+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\\\/\"},\"wordCount\":1837,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats.jpg\",\"keywords\":[\"Cybersecurity\",\"Identity and access management\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\\\/\",\"name\":\"How one data scientist is pioneering techniques to detect security threats 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats.jpg\",\"datePublished\":\"2021-03-24T19:00:23+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats.jpg\",\"width\":900,\"height\":1200},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/cybersecurity\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"How one data scientist is pioneering techniques to detect security threats\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How one data scientist is pioneering techniques to detect security threats 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/","og_locale":"en_US","og_type":"article","og_title":"How one data scientist is pioneering techniques to detect security threats 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-03-24T19:00:23+00:00","og_image":[{"width":900,"height":1200,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"How one data scientist is pioneering techniques to detect security threats","datePublished":"2021-03-24T19:00:23+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/"},"wordCount":1837,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats.jpg","keywords":["Cybersecurity","Identity and access management"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/","url":"https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/","name":"How one data scientist is pioneering techniques to detect security threats 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats.jpg","datePublished":"2021-03-24T19:00:23+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats.jpg","width":900,"height":1200},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/how-one-data-scientist-is-pioneering-techniques-to-detect-security-threats\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity","item":"https:\/\/www.threatshub.org\/blog\/tag\/cybersecurity\/"},{"@type":"ListItem","position":3,"name":"How one data scientist is pioneering techniques to detect security threats"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/40147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=40147"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/40147\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/40148"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=40147"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=40147"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=40147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}