01 /Analyst profile
Muhammad Nouman Ahmed
I take apart malware and the infrastructure behind it, then write down what I find.
- Role
- Threat Intelligence Analyst
- Location
- Pakistan
- Focus
- Threat Intelligence · Malware Analysis · SOC Operations · GRC & Compliance
02 /Background
I work on the analysis side of threat intelligence: pulling apart samples, mapping the infrastructure they call home, and turning that into something a SOC can actually act on. Most of my time goes to malware triage, C2 infrastructure tracking, and detection engineering.
I lead a small analyst team, which means the work runs from raw reverse engineering through to the governance side — control mapping, SOC 2 readiness, and the audit trail that has to exist when a finding leaves the lab.
This site is where the research gets published. Every post is written from a real investigation, with the indicators included so you can check the work yourself.
03 /Capabilities
What the work actually covers
Four disciplines, graded by depth. Deep means day-to-day work; working means enough to handle it when a case calls for it.
Threat Intelligence
TI- C2 infrastructure trackingDeep
- Actor profilingDeep
- IOC extraction & enrichmentDeep
- OSINT collectionDeep
- MITRE ATT&CK mappingDeep
- Intel reportingDeep
Malware Analysis
MA- Static analysisDeep
- Dynamic / sandbox triageDeep
- Unpacking & deobfuscationPractised
- YARA rule authoringDeep
- PE / ELF internalsPractised
- Implant developmentPractised
Detection & Response
DR- SIEM engineeringDeep
- Detection rule writingDeep
- Alert triageDeep
- Incident responsePractised
- Threat huntingDeep
- Log pipeline designPractised
Governance & Risk
GR- SOC 2 implementationDeep
- Control mappingDeep
- Risk assessmentPractised
- Policy authoringPractised
- Audit readinessDeep
- Vendor reviewPractised
02 /Track record
Where the work happened
Front-line triage first, then infrastructure tracking, then running the function. The through-line is the same: take the sample apart, write down what it means.
Present
Team Lead — Threat Intelligence
Lead the threat intelligence function: collection strategy, analyst tasking, and the reporting that goes out to stakeholders. Own the escalation path from raw sample to published finding.
- Run infrastructure-tracking pipelines that surface staging servers before they are used
- Set the standard for how findings are written, reviewed and released
- Mentor analysts through triage, reverse engineering and report writing
Dates not published
Threat Intelligence Analyst
Tracked adversary infrastructure and malware families end to end, from first sighting through to detection content and a published write-up.
- Profiled command-and-control infrastructure across multiple campaigns
- Converted findings into YARA and SIEM detection content
- Mapped every finding to MITRE ATT&CK for downstream consumption
Dates not published
SOC Analyst
Front-line detection and response — alert triage, investigation, and the escalations that turned into real incidents.
- Triaged and investigated alerts across endpoint, network and identity
- Tuned detection rules to cut false positives without losing coverage
- Wrote the runbooks the rest of the shift worked from
03 /Credentials
Certifications held
Six, all current. Each one was taken because the work needed it, not to lengthen a list.
SOC 2
01Certified Master SOC 2 Implementer
Scytale — SOC 2 Academy
CBP
02Certified Blockchain Practitioner
The SecOps Group
C3SA
03Certified Cyber Security Analyst
CyberWarFare Labs
CAP
04Certified AppSec Practitioner
The SecOps Group
PMAT
05Practical Malware Analysis & Triage
TCM Security
ETH
06Ethical Hacker
Cisco Networking Academy
06 /Toolchain
Tools in regular use
The bench, not a keyword list. Everything here is used on real cases.
- IDA Pro
- Ghidra
- x64dbg
- YARA
- Volatility
- Wireshark
- Suricata
- Zeek
- Splunk
- Elastic
- Microsoft Sentinel
- MISP
- OpenCTI
- VirusTotal
- Shodan
- Censys
- CyberChef
- Sysinternals
- Cuckoo
- ATT&CK Navigator