Skip to content
Nouman Ahmed

01 /Analyst profile

Muhammad Nouman Ahmed

I take apart malware and the infrastructure behind it, then write down what I find.

Role
Threat Intelligence Analyst
Location
Pakistan
Focus
Threat Intelligence · Malware Analysis · SOC Operations · GRC & Compliance

02 /Background

I work on the analysis side of threat intelligence: pulling apart samples, mapping the infrastructure they call home, and turning that into something a SOC can actually act on. Most of my time goes to malware triage, C2 infrastructure tracking, and detection engineering.

I lead a small analyst team, which means the work runs from raw reverse engineering through to the governance side — control mapping, SOC 2 readiness, and the audit trail that has to exist when a finding leaves the lab.

This site is where the research gets published. Every post is written from a real investigation, with the indicators included so you can check the work yourself.


03 /Capabilities

What the work actually covers

Four disciplines, graded by depth. Deep means day-to-day work; working means enough to handle it when a case calls for it.

Threat Intelligence

TI
  • C2 infrastructure trackingDeep
  • Actor profilingDeep
  • IOC extraction & enrichmentDeep
  • OSINT collectionDeep
  • MITRE ATT&CK mappingDeep
  • Intel reportingDeep

Malware Analysis

MA
  • Static analysisDeep
  • Dynamic / sandbox triageDeep
  • Unpacking & deobfuscationPractised
  • YARA rule authoringDeep
  • PE / ELF internalsPractised
  • Implant developmentPractised

Detection & Response

DR
  • SIEM engineeringDeep
  • Detection rule writingDeep
  • Alert triageDeep
  • Incident responsePractised
  • Threat huntingDeep
  • Log pipeline designPractised

Governance & Risk

GR
  • SOC 2 implementationDeep
  • Control mappingDeep
  • Risk assessmentPractised
  • Policy authoringPractised
  • Audit readinessDeep
  • Vendor reviewPractised

02 /Track record

Where the work happened

Front-line triage first, then infrastructure tracking, then running the function. The through-line is the same: take the sample apart, write down what it means.

  1. Present

    Team Lead — Threat Intelligence

    Lead the threat intelligence function: collection strategy, analyst tasking, and the reporting that goes out to stakeholders. Own the escalation path from raw sample to published finding.

    • Run infrastructure-tracking pipelines that surface staging servers before they are used
    • Set the standard for how findings are written, reviewed and released
    • Mentor analysts through triage, reverse engineering and report writing
  2. Dates not published

    Threat Intelligence Analyst

    Tracked adversary infrastructure and malware families end to end, from first sighting through to detection content and a published write-up.

    • Profiled command-and-control infrastructure across multiple campaigns
    • Converted findings into YARA and SIEM detection content
    • Mapped every finding to MITRE ATT&CK for downstream consumption
  3. Dates not published

    SOC Analyst

    Front-line detection and response — alert triage, investigation, and the escalations that turned into real incidents.

    • Triaged and investigated alerts across endpoint, network and identity
    • Tuned detection rules to cut false positives without losing coverage
    • Wrote the runbooks the rest of the shift worked from

03 /Credentials

Certifications held

Six, all current. Each one was taken because the work needed it, not to lengthen a list.

  • SOC 2

    01

    Certified Master SOC 2 Implementer

    Scytale — SOC 2 Academy

  • CBP

    02

    Certified Blockchain Practitioner

    The SecOps Group

  • C3SA

    03

    Certified Cyber Security Analyst

    CyberWarFare Labs

  • CAP

    04

    Certified AppSec Practitioner

    The SecOps Group

  • PMAT

    05

    Practical Malware Analysis & Triage

    TCM Security

  • ETH

    06

    Ethical Hacker

    Cisco Networking Academy

06 /Toolchain

Tools in regular use

The bench, not a keyword list. Everything here is used on real cases.

  • IDA Pro
  • Ghidra
  • x64dbg
  • YARA
  • Volatility
  • Wireshark
  • Suricata
  • Zeek
  • Splunk
  • Elastic
  • Microsoft Sentinel
  • MISP
  • OpenCTI
  • VirusTotal
  • Shodan
  • Censys
  • CyberChef
  • Sysinternals
  • Cuckoo
  • ATT&CK Navigator