Cyber Threat Intelligence Platform
MISP · TheHive · Cortex — regional APT simulation
- Tuwaiq Academy — DFIR Capstone
- MISP 10.10.10.136 · TheHive · Cortex
- 4 APT campaigns + 2 tasks (Ryuk, Emotet)
- April 2026
Overview
Deployed an integrated CTI + IR environment simulating intelligence sharing between four Gulf national CERTs (Kuwait, Saudi Arabia, UAE, Qatar). Created events for real-world APT campaigns — Shamoon 3, APT34 OilRig, MuddyWater, Bahamut — plus dedicated tasks for Ryuk ransomware and Emotet macro-malware. IOCs were tagged, enriched, and delegated between organisations to demonstrate cross-border intelligence workflows.
My Role
CTI analyst and platform engineer — org creation, tagging schema, event modelling, IOC enrichment, delegation workflow, and MITRE ATT&CK mapping across every event.
Tools & Frameworks
Event 1 · Shamoon 3 (Kuwait)
Destructive wiper campaign attributed to APT actors targeting Kuwait's oil and gas sector. Initial access via spear-phishing, SMB-based lateral movement, ending in MBR overwrite. Delegated from Kuwait National Cybersecurity Center to the Saudi National Cybersecurity Authority for regional awareness.
- IOC — SHA1: 8d7524941991fb5c962b32b504620f4c194b301c2
- IOC — IP: 45.227.253.20
- ATT&CK — T1566 Phishing, T1021.002 SMB Admin Shares, T1485 Data Destruction, T1561 Disk Wipe
Event 2 · APT34 / OilRig (Saudi Arabia)
Long-running Iranian espionage cluster targeting energy and government entities. Event created under the Saudi org with associated IPs and enrichment run through Cortex analyzers.
- IOC — IP: 185.161.200.155
- Threat type — APT, credential-theft, DNS tunnelling
Event 3 · MuddyWater (UAE)
Iranian threat cluster leveraging living-off-the-land techniques against telecom and government. Event scoped under the UAE Cybersecurity Council with focus on detection patterns for malicious PowerShell and script behaviours.
Event 4 · Bahamut Campaign (Qatar)
Sophisticated hack-for-hire spyware campaign targeting Qatari financial institutions with fake banking portals and credential harvesters. Delegated to Qatar National Information Assurance.
- IOC — URL: https://secure-login-portal.net/bank-verify
- Threat type — Spyware, credential-theft, hack-for-hire
Task 2 · Ryuk Ransomware Intel
Analysis of a Ryuk campaign targeting healthcare and public-health entities. Observables catalogued with TLP:GREEN / PAP:GREEN sharing constraints; file hashes and behavioural indicators recorded for downstream detection.
Task 3 · Emotet Incident Simulation
Simulated Emotet macro-malware incident (Event #1833) from initial phishing document through payload retrieval. Discussion thread concluded Confirmed Malicious → Contained → Block as the final IR decision.
Outcome
Fully functional CTI + IR stack with four APT events, two incident tasks, delegated cross-org publishing, and MITRE-mapped attack patterns. Demonstrates real-world Gulf intelligence-sharing workflows suitable for a national CERT context.
Supporting File
MISP / TheHive / Cortex Report
PDF · 22 pages