Mohammed — a Cyber Threat Intelligence enthusiast and practitioner.

This blog is my place to share insights, research, and resources related to threat intelligence, cybersecurity trends, and adversary tactics. Whether you're a beginner or a fellow analyst, I hope you find something useful here.

Let's keep the field more fun.

What you'll find here

  • Threat Actors & APTs: Profiles of state-sponsored and financially motivated groups: aliases, attribution, targeting, tooling, and tradecraft.
  • Malware Analysis: Static and dynamic analysis of malicious samples: execution flow, persistence, configuration, and network behavior.
  • Ransomware: Ransomware operations and RaaS ecosystems: affiliates, extortion tactics, and encryptor internals.
  • Campaign Analysis: Investigations of malicious campaigns and intrusion activity, from initial access to impact.
  • Detection Engineering: Detection opportunities, hunting queries, and rules derived from the research.

A note on indicators

Indicators of compromise are defanged (for example hxxps://example[.]com or 203.0.113[.]10) so they can't be opened by accident. They're displayed and copied exactly as written. Re-fang and validate them deliberately before any operational use.

Elsewhere