Portfolio
Malware Research Specialist and Cyber Threat Intelligence Analyst with over 7 years of experience. Expert in reverse engineering complex malware, specifically analyzing kernel-level rootkits and evasion techniques. Deep expertise in tracking and profiling APTs such as MuddyWater and APT34. Proven track record of publishing high-impact intelligence reports that translate advanced technical findings into actionable strategic defense. Combines hands-on technical research with direct customer engagement, supporting enterprise clients through active incidents and fulfilling their malware analysis and threat intelligence requests.
Expertise
Topics and skills associated with this portfolio.
Experience
-
Malware Research & Threat Intelligence Analyst
- Customer threat support: technical point of contact for malware analysis and threat intelligence requests, delivering tailored sample analysis, IOCs, and written findings to client security teams.
- Malware analysis & detection engineering: in-depth static/dynamic analysis with detailed reports, IOCs, mitigations, and production-grade YARA rules that improved detection coverage.
- Strategic intelligence & APT profiling: tracked MENA-focused APTs (MuddyWater, APT34) via TTPs, OSINT, and telemetry, identifying a new activity cluster and delivering actionable briefings.
- Intelligence reporting: authored comprehensive threat assessments that informed strategic CTI operations and cross-functional teams.
- Automation & intel enrichment: built malware triage and IOC extraction workflows; integrated malware datasets, actor profiles, and external feeds into the internal TI portal.
- Incident response support: provided malware insights, IOCs, reverse engineering, and threat intelligence during active investigations.
-
DFIR and CTI Analyst
- Customer incident support: frontline threat support for enterprise customers—triaging samples and alerts, answering threat queries, and advising on containment and remediation.
- Client communication: translated malware and forensic findings into actionable guidance for SOC analysts through executive stakeholders.
- Malware & IOC analysis: static/dynamic analysis with IOC extraction for detection and client protection; mapped TTPs to MITRE ATT&CK for APT tracking and profiling.
- Product detection improvement: turned IR malware scenarios into engineering requirements that strengthened detection logic; partnered on vulnerability disclosure and permanent fixes.
- Technical documentation: authored and reviewed threat reports aligned with CTI and IR standards.
- Digital forensics & IR: led triage, evidence acquisition, and remediation; reconstructed attack chains from logs to find persistence and lateral movement.
-
Malware Analyst and Security R&D
- Lead malware analyst: triage and technical/non-technical reports for national incident response; published malware and threat intel reports with IOCs and YARA for internal and public use.
- Windows internals & tooling: built kernel mini-filter drivers to simulate rootkit behaviors and validate monitoring against sophisticated evasion.
- Attack surface analysis: designed secure user-kernel communication channels to find privilege-escalation issues and harden data exchange paths.
- Tamper protection & kernel R&D: protected monitoring components from unauthorized modification; researched kernel-level issues to strengthen defenses.
- Training & knowledge sharing: trained analysts on malware analysis and Windows internals; authored SOPs and technical documentation.
-
Security Engineer
- Designed and deployed enterprise security infrastructure, with end-to-end configuration and support for network defense technologies.
-
Datacom Engineering
- Managed large-scale network deployments and troubleshooting for enterprise routing and switching environments.
Skills
Reverse engineering
- Advanced code dissection & de-obfuscation (IDA Pro, Ghidra, x64dbg)
- Static & dynamic analysis of x86/x64, ARM, Linux, Java & .NET (anti-VM / anti-debug bypass)
- Windows kernel internals & rootkit analysis (SSDT hooking, DKOM, object callbacks)
- Kernel Development (WDM, KMDF, mini-filters)
- Android malware analysis & native library reversing (JEB, Jadx, Frida, adb, .so)
Threat intelligence
- Adversary profiling & campaign attribution (MITRE ATT&CK)
- Threat intelligence enrichment (Maltego, STIX, MISP, OpenCTI)
- Underground economy monitoring (Intel471, dark web forums)
- Technical blogging & intelligence dissemination (reports, whitepapers)
- Customer-facing threat support & technical escalation handling
- Cross-functional collaboration across CTI, IR, and Development Teams
Detection & forensics
- High-fidelity detection engineering (YARA, Sigma, Snort)
- Enterprise forensics & triage (memory, network, disk)
- Analysis automation & tooling (Python, IDAPython, WinDbg scripts)
Education
-
Bachelor of Engineering
Electronics and Communication
Languages
English · Arabic
Selected publications
A sample of published research. Full lists live under Blog and External writing.
- A Look into PlugX Kernel driver
- Loaded Drivers Enumeration
- Asynchronous Procedure Calls (APC) Enumeration
- HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack
- HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
- Operation Olalampo: Inside MuddyWater’s Latest Campaign
- Unmasking MuddyWater’s New Malware Toolkit Driving International Espionage
- Mapping the Infrastructure and Malware Ecosystem of MuddyWater
- Exploiting Trust: How Signed Drivers Fuel Modern Kernel Level Attacks on Windows