R.M.A
Report 02
02Case study

Cyber Threat Intelligence Platform

MISP · TheHive · Cortex — regional APT simulation

Program
Tuwaiq Academy — DFIR Capstone
Environment
MISP 10.10.10.136 · TheHive · Cortex
Events
4 APT campaigns + 2 tasks (Ryuk, Emotet)
Date
April 2026

Overview

Deployed an integrated CTI + IR environment simulating intelligence sharing between four Gulf national CERTs (Kuwait, Saudi Arabia, UAE, Qatar). Created events for real-world APT campaigns — Shamoon 3, APT34 OilRig, MuddyWater, Bahamut — plus dedicated tasks for Ryuk ransomware and Emotet macro-malware. IOCs were tagged, enriched, and delegated between organisations to demonstrate cross-border intelligence workflows.

My Role

CTI analyst and platform engineer — org creation, tagging schema, event modelling, IOC enrichment, delegation workflow, and MITRE ATT&CK mapping across every event.

Tools & Frameworks

MISPTheHiveCortexVirusTotalAlienVault OTXCensysMITRE ATT&CK
§Methodology & Findings
01

Event 1 · Shamoon 3 (Kuwait)

Destructive wiper campaign attributed to APT actors targeting Kuwait's oil and gas sector. Initial access via spear-phishing, SMB-based lateral movement, ending in MBR overwrite. Delegated from Kuwait National Cybersecurity Center to the Saudi National Cybersecurity Authority for regional awareness.

  • IOC — SHA1: 8d7524941991fb5c962b32b504620f4c194b301c2
  • IOC — IP: 45.227.253.20
  • ATT&CK — T1566 Phishing, T1021.002 SMB Admin Shares, T1485 Data Destruction, T1561 Disk Wipe
02

Event 2 · APT34 / OilRig (Saudi Arabia)

Long-running Iranian espionage cluster targeting energy and government entities. Event created under the Saudi org with associated IPs and enrichment run through Cortex analyzers.

  • IOC — IP: 185.161.200.155
  • Threat type — APT, credential-theft, DNS tunnelling
03

Event 3 · MuddyWater (UAE)

Iranian threat cluster leveraging living-off-the-land techniques against telecom and government. Event scoped under the UAE Cybersecurity Council with focus on detection patterns for malicious PowerShell and script behaviours.

04

Event 4 · Bahamut Campaign (Qatar)

Sophisticated hack-for-hire spyware campaign targeting Qatari financial institutions with fake banking portals and credential harvesters. Delegated to Qatar National Information Assurance.

  • IOC — URL: https://secure-login-portal.net/bank-verify
  • Threat type — Spyware, credential-theft, hack-for-hire
05

Task 2 · Ryuk Ransomware Intel

Analysis of a Ryuk campaign targeting healthcare and public-health entities. Observables catalogued with TLP:GREEN / PAP:GREEN sharing constraints; file hashes and behavioural indicators recorded for downstream detection.

06

Task 3 · Emotet Incident Simulation

Simulated Emotet macro-malware incident (Event #1833) from initial phishing document through payload retrieval. Discussion thread concluded Confirmed Malicious → Contained → Block as the final IR decision.

Outcome

Fully functional CTI + IR stack with four APT events, two incident tasks, delegated cross-org publishing, and MITRE-mapped attack patterns. Demonstrates real-world Gulf intelligence-sharing workflows suitable for a national CERT context.

Supporting File

MISP / TheHive / Cortex Report

PDF · 22 pages

Open →