Photo of Muhammad Abdullah

Muhammad Abdullah

Security Operations Analyst in Islamabad, PK

I work in security operations for North American enterprise clients, from alert triage and threat hunting to ransomware containment.

About

muhammad abdullah · soc analyst · islamabad, pk

I'm a security operations analyst at Ninpo Inc., working remotely in the SOC for North American enterprise clients. For the past two years I've triaged alerts, hunted threats and helped contain incidents, including an active, threat actor-led ransomware attack, where I helped isolate compromised domain controllers and ESXi hosts before large-scale encryption.

Each week I investigate 100+ alerts in Elastic SIEM and Microsoft 365 Defender, and I use Python and Pandas to automate log analysis so triage stays fast. I also keep Canadian client environments running: Microsoft 365 tenant administration, firewall and VPN configuration, and endpoint provisioning.

I also design and build websites. I use AI coding tools for the build and put my own time into layout, accessibility and user experience. This site is one example.

Experience

Oct 2024 to present

Security Operations Analyst

Ninpo Inc.

Ottawa, Canada · Remote

SOC analyst for a Canadian cybersecurity firm. I handle threat detection, incident response and IT operations across several North American enterprise client environments.

alerts investigated each week in Elastic SIEM
100+
phishing classification accuracy
95%+
fewer false positives after rule tuning
20%
EDR telemetry coverage
100%
Visit website

Jul 2026 to Aug 2026

Product Growth & Strategy

AfterDesk · Independent Product

Remote

Built the product and growth groundwork for AfterDesk, an after-sales case manager for small online sellers that keeps the evidence with every case.

linked notes on product, architecture, security, API and ethics
37

Jul 2026

Product Growth Auditor

FitSmart AI · Project Contribution

Remote

Ran an evidence-based UX and growth review of an AI fitness and nutrition app, then turned the risks I found into a remediation plan the team could implement.

product areas audited
9
icon controls audited
37
Worker tests passing
18/18

Case studies

Real investigations from my SOC work, with client details removed.

False positive · Elastic Defend

A malware alert that was really a compiler

Elastic's machine-learning model flagged a new DLL on a client's web server. Tracing the process chain showed it was ASP.NET compiling its own pages.

Elastic Defend · Kibana · Windows process telemetry

Email investigation · Microsoft 365

Bank security codes that "never arrived"

A client said a bank's security-code emails weren't reaching two mailboxes. The logs showed they had been delivered, then deleted.

Exchange Online · Message Trace · Mailbox audit logs · Perception Point

Malware analysis · Endpoint

Unpacking a malicious USB drive

A suspicious USB drive carried a script chain that tried to drop a DLL. Elastic blocked it, and I got the payload out for analysis when the usual route failed.

Elastic Defend · Elastic Fleet · Isolated endpoint

Phishing analysis · Sandbox

A phishing link that asked for a device code

A suspicious link turned out to be an adversary-in-the-middle device code phishing chain running through Cloudflare Workers.

Elastic (KQL) · ANY.RUN · Microsoft Entra ID sign-in logs

Projects

Browser extension

GitLab Triage Accelerator

Speeds up high-volume security triage in GitLab for L1 and L2 analysts by removing the repetitive manual work: entering common findings, assigning leads and closing issues.

  • Custom quick actions for your own triage categories and slash commands
  • Alt + key hotkeys that trigger an action instantly
  • A floating action bar that stays in reach while you scroll
  • Works with GitLab's single-page app by watching for page changes

JavaScript · Chrome, Brave, Edge and Kiwi on Android

Browser extension

VT Extension

Right-click any selected IP address, URL, file hash or domain and check it on VirusTotal straight away.

  • One right-click opens the VirusTotal result in a new tab
  • Manifest V3 with a lightweight background service worker
  • No data collection: lookups go straight to VirusTotal

JavaScript · Manifest V3 · Chrome, Brave and Edge · MIT licence

Android app

VT Checker for Android

Adds "Check on VirusTotal" to the Android text-selection menu, so an IP address, domain or URL can be checked from any app.

  • Works system-wide through Android's text-selection menu
  • No API key needed: it opens a VirusTotal search in the browser
  • Runs invisibly and closes as soon as the lookup opens

Android 6.0 or later

Skills and tools

Security operations

  • Elastic Security (SIEM)
  • Incident response
  • Alert triage
  • Phishing analysis with Perception Point
  • IOC hunting
  • OSINT

Threat detection

  • MITRE ATT&CK mapping
  • TTP analysis
  • Sysmon
  • Osquery
  • Anomaly detection
  • Cyber Kill Chain

Infrastructure and admin

  • Microsoft 365 Defender and Admin via Pax8
  • SonicWall and WatchGuard firewall & VPN
  • RDP/SSH forensics
  • VMware ESXi
  • Windows and Linux

Data and programming

  • Python (Pandas, NumPy, OOP)
  • Bash scripting
  • SQL
  • Regex
  • Jupyter
  • Matplotlib

Web design and development

  • Responsive and accessible web design (WCAG 2.2)
  • AI-assisted development (React, TypeScript)
  • UX and growth audits
  • Landing pages and interactive product demos

Certifications and training

  • Google Cybersecurity Professional Certificate

    Google · Professional certificate

  • CompTIA Security+

    CompTIA · Certification exam

    In progress

  • Blue Team Junior Analyst (BTJA)

    Security Blue Team · Training pathway certificate

  • Introduction to Cybersecurity Essentials

    IBM · Course certificate

  • Identity Security Sales Certification

    WatchGuard · Sales certification

    Valid through Sep 2027