Cutting SCA Noise: Using Runtime Call Tracing to Triage Vulnerabilities
How to extract vulnerable methods from CVE descriptions and cross-reference runtime call graphs to eliminate false positives and save LLM analysis tokens.
Product Security · Secure Architecture · Security Engineering
I'm Abhishek Pandey, a Product Security Engineer exploring secure architecture, application security, cloud security, and AI security.
01 / Writing
How to extract vulnerable methods from CVE descriptions and cross-reference runtime call graphs to eliminate false positives and save LLM analysis tokens.
02 / Projects
A zero-overhead Python runtime tracer for capturing executed third-party methods to verify SCA reachability.
03 / Video Demonstrations

A practical exploration of application-to-dependency calls.
04 / Background
My security engineering philosophy is rooted in deep systems thinking: understanding how software behaves under real-world constraints, where architectural assumptions decay, and how to build defense mechanisms that empower engineering teams rather than slowing them down.