<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Pages on Mohammad Al Sayegh</title>
        <link>https://malsayegh.ae/page/</link>
        <description>Recent content in Pages on Mohammad Al Sayegh</description>
        <generator>Hugo -- gohugo.io</generator>
        <language>en-us</language>
        <lastBuildDate>Sun, 06 Mar 2022 00:00:00 +0000</lastBuildDate><atom:link href="https://malsayegh.ae/page/index.xml" rel="self" type="application/rss+xml" /><item>
        <title>Archives</title>
        <link>https://malsayegh.ae/archives/</link>
        <pubDate>Sun, 06 Mar 2022 00:00:00 +0000</pubDate>
        
        <guid>https://malsayegh.ae/archives/</guid>
        <description></description>
        </item>
        <item>
        <title>About Me</title>
        <link>https://malsayegh.ae/about-me/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://malsayegh.ae/about-me/</guid>
        <description>&lt;img src="https://malsayegh.ae/about-me/cover.jpg" alt="Featured image of post About Me" /&gt;&lt;h3 id=&#34;intro&#34;&gt;&lt;strong&gt;Intro&lt;/strong&gt;
&lt;/h3&gt;&lt;p&gt;Hi, my name is Mohammad Abdulla AlSayegh. A proactive and results-driven cybersecurity professional with extensive expertise in threat intelligence, automation, and security operations. Adept at leveraging cutting-edge technologies and automation to enhance threat detection, response, and mitigation strategies. Experienced in developing and integrating advanced security playbooks, scripts, and automated processes to streamline security operations and minimize risks.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;em&gt;Proven track record in:&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Threat Intelligence &amp;amp; Incident Response:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Collecting, analyzing, and disseminating actionable intelligence to mitigate emerging threats.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Security Automation &amp;amp; Orchestration:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Designing and implementing automated security workflows to enhance response times and efficiency.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Dark Web &amp;amp; Threat Hunting:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Monitoring and investigating leaked credentials, compromised data, and malicious activities.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Malware &amp;amp; Phishing Defense:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Developing automated sandbox analysis, phishing detection, and domain monitoring solutions.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Cybersecurity Strategy &amp;amp; Innovation:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Implementing custom security integrations and improving cybersecurity frameworks.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;br&gt;
Committed to staying ahead of evolving cyber threats and continuously enhancing security postures through innovation and automation.
&lt;br&gt;&lt;br&gt;
&lt;p&gt;&lt;code&gt;malsayegh.ae&lt;/code&gt; is a personal blog of my projects, discoveries and experiences in my world.&lt;/p&gt;
&lt;h3 id=&#34;certification&#34;&gt;&lt;strong&gt;Certification&lt;/strong&gt;
&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;&lt;code&gt;09-May-2023&lt;/code&gt; - &lt;a class=&#34;link&#34; href=&#34;https://www.linkedin.com/posts/mohammad-alsayegh_itil-foundation-certification-in-it-service-activity-7063755379255484417-TSp0/?utm_source=share&amp;amp;utm_medium=member_ios&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;ITIL 4 Foundation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;24-Aug-2023&lt;/code&gt; - &lt;a class=&#34;link&#34; href=&#34;https://www.isc2.org/certifications/cc&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Certified in Cybersecurity (CC)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;18-Nov-2024&lt;/code&gt; - &lt;a class=&#34;link&#34; href=&#34;https://www.sans.org/cyber-security-courses/network-monitoring-threat-detection/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Network Monitoring and Threat Detection In-Depth (SEC503)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;16-Oct-2025&lt;/code&gt; - &lt;a class=&#34;link&#34; href=&#34;https://www.sans.org/cyber-security-courses/cyber-threat-intelligence&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Cyber Threat Intelligence (FOR578)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&#34;contact-me&#34;&gt;&lt;strong&gt;Contact me&lt;/strong&gt;
&lt;/h3&gt;&lt;p&gt;If you want to get in contact with me, feel free to send an e-mail to: &lt;a class=&#34;link&#34; href=&#34;mailto:contact@malsayegh.ae&#34; &gt;contact@malsayegh.ae&lt;/a&gt;&lt;/p&gt;
</description>
        </item>
        <item>
        <title>Projects</title>
        <link>https://malsayegh.ae/projects/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://malsayegh.ae/projects/</guid>
        <description>&lt;p&gt;This page has moved. Browse all projects at &lt;a class=&#34;link&#34; href=&#34;https://malsayegh.ae/project/&#34; &gt;/project/&lt;/a&gt;.&lt;/p&gt;
</description>
        </item>
        <item>
        <title>Search</title>
        <link>https://malsayegh.ae/search/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://malsayegh.ae/search/</guid>
        <description></description>
        </item>
        <item>
        <title>Tools &amp; Resources</title>
        <link>https://malsayegh.ae/tools-resources/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://malsayegh.ae/tools-resources/</guid>
        <description>&lt;img src="https://malsayegh.ae/tools-resources/cover.jpg" alt="Featured image of post Tools &amp; Resources" /&gt;&lt;p&gt;A curated list of tools I use across threat intelligence, security operations, detection engineering, and automation. Each entry includes a note on how I use it in practice.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;threat-intelligence-platforms&#34;&gt;Threat Intelligence Platforms
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://www.misp-project.org/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;MISP&lt;/a&gt;&lt;/strong&gt;
Open-source threat intelligence sharing platform. I use MISP as the central IOC repository — ingesting feeds, tagging events with ATT&amp;amp;CK techniques, and pushing enriched indicators to SIEM and EDR via the API.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://www.opencti.io/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;OpenCTI&lt;/a&gt;&lt;/strong&gt;
A knowledge graph for threat intelligence with native STIX 2.1 support. Useful for building actor profiles, tracking campaign relationships, and visualising the connections between TTPs, malware, and infrastructure.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://otx.alienvault.com/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;AlienVault OTX&lt;/a&gt;&lt;/strong&gt;
Community-driven threat intel feed. I pull OTX pulses into the IOC enrichment pipeline for additional context on IPs, domains, and hashes — particularly useful for regional threat campaigns.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;malware-analysis--sandboxes&#34;&gt;Malware Analysis &amp;amp; Sandboxes
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://any.run/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Any.run&lt;/a&gt;&lt;/strong&gt;
Interactive sandbox for detonating suspicious files and URLs. The real-time process tree and network activity views make it invaluable for phishing analysis automation — behaviour results feed directly into verdict scoring.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://www.virustotal.com/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;VirusTotal&lt;/a&gt;&lt;/strong&gt;
Multi-engine file, URL, IP, and domain reputation platform. Used extensively in enrichment pipelines via the v3 API. The graph feature is underrated for visualising malware infrastructure.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://cuckoosandbox.org/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Cuckoo Sandbox&lt;/a&gt;&lt;/strong&gt;
Self-hosted malware analysis environment. Useful when files are too sensitive to submit to public sandboxes. Integrates cleanly with SOAR playbooks via the REST API.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://github.com/mandiant/flare-floss&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;FLOSS&lt;/a&gt;&lt;/strong&gt;
FireEye/Mandiant tool for automatically extracting obfuscated strings from malware binaries — far more effective than plain &lt;code&gt;strings&lt;/code&gt; for packed or encoded samples.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;osint--reconnaissance&#34;&gt;OSINT &amp;amp; Reconnaissance
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://www.shodan.io/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Shodan&lt;/a&gt;&lt;/strong&gt;
Search engine for internet-connected devices. I use Shodan in IOC enrichment to check open ports, services, and historical data for suspicious IPs. The API integrates directly into the enrichment pipeline.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://censys.io/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Censys&lt;/a&gt;&lt;/strong&gt;
Similar to Shodan but with stronger TLS certificate search. Useful for tracking threat actor infrastructure — C2 servers often reuse certificates across campaigns.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://urlscan.io/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;URLScan.io&lt;/a&gt;&lt;/strong&gt;
Automated URL scanner that captures screenshots, DOM content, and network requests. Used in phishing analysis for safe URL detonation and visual inspection without visiting the site directly.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://www.domaintools.com/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;WHOIS / DomainTools&lt;/a&gt;&lt;/strong&gt;
Domain registration history and WHOIS data. Checking domain age is a critical step in phishing triage — domains registered less than 30 days ago are heavily weighted in the verdict engine.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;detection--monitoring&#34;&gt;Detection &amp;amp; Monitoring
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://www.splunk.com/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Splunk&lt;/a&gt;&lt;/strong&gt;
Primary SIEM for alert correlation, threat hunting queries, and detection engineering. SPL (Search Processing Language) is the query language I use most across hunt packages and tuning automation.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://azure.microsoft.com/en-us/products/microsoft-sentinel/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Microsoft Sentinel&lt;/a&gt;&lt;/strong&gt;
Cloud-native SIEM/SOAR with deep Microsoft 365 and Entra ID integration. KQL is expressive and fast — particularly strong for identity-based hunting and the compromised account playbook.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://github.com/SigmaHQ/sigma&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Sigma&lt;/a&gt;&lt;/strong&gt;
Generic detection rule format that compiles to Splunk, Sentinel, Elastic, and others. Writing detections in Sigma first prevents vendor lock-in and makes sharing with the community straightforward.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://virustotal.github.io/yara/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;YARA&lt;/a&gt;&lt;/strong&gt;
Pattern-matching language for malware detection. I use YARA rules in sandbox pipelines, EDR custom detections, and MISP for classifying malware families against collected samples.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;automation--orchestration&#34;&gt;Automation &amp;amp; Orchestration
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://www.paloaltonetworks.com/cortex/xsoar&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Palo Alto XSOAR&lt;/a&gt;&lt;/strong&gt;
The SOAR platform behind most of the playbooks documented in this site. Python-based playbook scripting with a large integration library covering most enterprise security tools.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://n8n.io/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;n8n&lt;/a&gt;&lt;/strong&gt;
Self-hosted workflow automation. Useful for lighter automation tasks — webhook-triggered enrichment, scheduled report delivery, and connecting tools that don&amp;rsquo;t have a native SOAR integration.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://www.python.org/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Python 3&lt;/a&gt;&lt;/strong&gt;
The primary language for all automation projects on this site. Key libraries: &lt;code&gt;pymisp&lt;/code&gt;, &lt;code&gt;vt-py&lt;/code&gt;, &lt;code&gt;requests&lt;/code&gt;, &lt;code&gt;pandas&lt;/code&gt;, &lt;code&gt;jinja2&lt;/code&gt;, &lt;code&gt;telethon&lt;/code&gt;, &lt;code&gt;splunk-sdk&lt;/code&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;threat-intelligence-frameworks--references&#34;&gt;Threat Intelligence Frameworks &amp;amp; References
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://attack.mitre.org/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;MITRE ATT&amp;amp;CK&lt;/a&gt;&lt;/strong&gt;
The universal vocabulary for adversary behaviour. Every hunt package, detection rule, and playbook on this site maps back to ATT&amp;amp;CK techniques. The Navigator tool is essential for visualising coverage gaps.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://d3fend.mitre.org/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;MITRE D3FEND&lt;/a&gt;&lt;/strong&gt;
The defensive counterpart to ATT&amp;amp;CK — maps countermeasures to attack techniques. Useful for prioritising security controls and justifying tooling investments to management.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;CISA KEV Catalog&lt;/a&gt;&lt;/strong&gt;
CISA&amp;rsquo;s list of vulnerabilities with confirmed in-the-wild exploitation. A CVE in this list instantly becomes a P1 remediation priority regardless of CVSS score.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://www.first.org/epss/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;FIRST EPSS&lt;/a&gt;&lt;/strong&gt;
Exploit Prediction Scoring System — daily probability score for whether a CVE will be exploited in the next 30 days. More operationally useful than CVSS alone for prioritising patch tickets.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a class=&#34;link&#34; href=&#34;https://malpedia.caad.fkie.fraunhofer.de/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Malpedia&lt;/a&gt;&lt;/strong&gt;
Curated malware family encyclopedia maintained by Fraunhofer FKIE. My first stop when identifying a new malware sample — family descriptions, YARA rules, and actor associations.&lt;/p&gt;
&lt;hr&gt;
&lt;blockquote&gt;
&lt;p&gt;Missing a tool or want to discuss any of these? Reach out at &lt;a class=&#34;link&#34; href=&#34;mailto:contact@malsayegh.ae&#34; &gt;contact@malsayegh.ae&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        </item>
        
    </channel>
</rss>
