Skip to content
Nouman Ahmed
Threat Intelligence · Malware AnalysisPakistan

I take apart malware and the infrastructure behind it.

Current focus //Threat Intelligence, Malware Analysis, SOC Operations, GRC & Compliance

I work on the analysis side of threat intelligence: pulling apart samples, mapping the infrastructure they call home, and turning that into something a SOC can actually act on. Most of my time goes to malware triage, C2 infrastructure tracking, and detection engineering.

Certifications held
6+
SOC coverage led
24/7
ATT&CK aligned reporting
MITRE

01 /Capability matrix

What I actually do

Four working groups, twenty-four cells. Fill depth is self-assessed against the work I have shipped, not against a syllabus.

TI/Threat Intelligence

06
  • C2 infrastructure trackingDeep — level 3 of 3
  • Actor profilingDeep — level 3 of 3
  • IOC extraction & enrichmentDeep — level 3 of 3
  • OSINT collectionDeep — level 3 of 3
  • MITRE ATT&CK mappingDeep — level 3 of 3
  • Intel reportingDeep — level 3 of 3

MA/Malware Analysis

06
  • Static analysisDeep — level 3 of 3
  • Dynamic / sandbox triageDeep — level 3 of 3
  • Unpacking & deobfuscationPractised — level 2 of 3
  • YARA rule authoringDeep — level 3 of 3
  • PE / ELF internalsPractised — level 2 of 3
  • Implant developmentPractised — level 2 of 3

DR/Detection & Response

06
  • SIEM engineeringDeep — level 3 of 3
  • Detection rule writingDeep — level 3 of 3
  • Alert triageDeep — level 3 of 3
  • Incident responsePractised — level 2 of 3
  • Threat huntingDeep — level 3 of 3
  • Log pipeline designPractised — level 2 of 3

GR/Governance & Risk

06
  • SOC 2 implementationDeep — level 3 of 3
  • Control mappingDeep — level 3 of 3
  • Risk assessmentPractised — level 2 of 3
  • Policy authoringPractised — level 2 of 3
  • Audit readinessDeep — level 3 of 3
  • Vendor reviewPractised — level 2 of 3
Fill = depth
  • 1 Working
  • 2 Practised
  • 3 Deep

02 /Track record

Where the work happened

Front-line triage first, then infrastructure tracking, then running the function. The through-line is the same: take the sample apart, write down what it means.

  1. Present

    Team Lead — Threat Intelligence

    Lead the threat intelligence function: collection strategy, analyst tasking, and the reporting that goes out to stakeholders. Own the escalation path from raw sample to published finding.

    • Run infrastructure-tracking pipelines that surface staging servers before they are used
    • Set the standard for how findings are written, reviewed and released
    • Mentor analysts through triage, reverse engineering and report writing
  2. Dates not published

    Threat Intelligence Analyst

    Tracked adversary infrastructure and malware families end to end, from first sighting through to detection content and a published write-up.

    • Profiled command-and-control infrastructure across multiple campaigns
    • Converted findings into YARA and SIEM detection content
    • Mapped every finding to MITRE ATT&CK for downstream consumption
  3. Dates not published

    SOC Analyst

    Front-line detection and response — alert triage, investigation, and the escalations that turned into real incidents.

    • Triaged and investigated alerts across endpoint, network and identity
    • Tuned detection rules to cut false positives without losing coverage
    • Wrote the runbooks the rest of the shift worked from

03 /Credentials

Certifications held

Six, all current. Each one was taken because the work needed it, not to lengthen a list.

  • SOC 2

    01

    Certified Master SOC 2 Implementer

    Scytale — SOC 2 Academy

  • CBP

    02

    Certified Blockchain Practitioner

    The SecOps Group

  • C3SA

    03

    Certified Cyber Security Analyst

    CyberWarFare Labs

  • CAP

    04

    Certified AppSec Practitioner

    The SecOps Group

  • PMAT

    05

    Practical Malware Analysis & Triage

    TCM Security

  • ETH

    06

    Ethical Hacker

    Cisco Networking Academy

04 /Toolchain

What the work runs on

Disassemblers, sandboxes, packet captures and the platforms the findings end up in.

  • IDA Pro
  • Ghidra
  • x64dbg
  • YARA
  • Volatility
  • Wireshark
  • Suricata
  • Zeek
  • Splunk
  • Elastic
  • Microsoft Sentinel
  • MISP
  • OpenCTI
  • VirusTotal
  • Shodan
  • Censys
  • CyberChef
  • Sysinternals
  • Cuckoo
  • ATT&CK Navigator

Hover to hold a row

05 /Published

Latest research

Write-ups from real investigations, indicators included.

All posts
Threat ResearchTLP:CLEARTLP:CLEAR — Disclosure is not limited. This material may be shared publicly without restriction.

Halfmast Loader: Eleven Days Inside an Exposed Staging Directory

An exposed staging host left a loader toolkit, an operator log and a target list readable for eleven days. A walk through what was on the box, how the loader stages its payload, and what to detect.

  • Asia
  • Loader
  • Command & Control
  • Exposed Directory
  • Detection Engineering
9 minutes to read

06 /Contact

Have something worth taking apart?

A sample, a piece of infrastructure, an alert nobody can explain, or a control set heading into audit. Send the details and I will tell you plainly whether I can help.

Threat Intelligence AnalystPakistanLinkedIn is the fastest route