Cybersecurity Analyst — Kuala Lumpur, MY

Muhammad
Imaduddin

Threat Intelligence · Red Team Operations · SOC & Incident Response

I build threat-intelligence pipelines, emulate adversaries for client cyber drills, and turn noisy telemetry into decisions a SOC can act on.

01

About

I'm a cybersecurity analyst with hands-on experience across threat intelligence, red-team adversary emulation, and SOC operations. At Kaiju Cybrsec I engineer an end-to-end threat-intelligence pipeline on OpenCTI, Wazuh and SIEM tooling, run red-team engagements for client cyber drills, and help build an in-house agentic-AI platform for automated vulnerability discovery.

Previously I worked as a SOC Analyst at CyberProof (Spain, remote) and a Cybersecurity Intern at Telekom Malaysia's Group Information Security. I hold multiple industry certifications and graduated on the Dean's List with a B.Sc. in Computer Science — Artificial Intelligence (Honours).

  • Based in Kuala Lumpur, Malaysia
  • Degree B.Sc. Computer Science — AI (Honours), Dean's List
  • Certifications 6 industry certifications
  • Domains Threat Intel · Red Team · SOC & IR
  • Languages English (native/bilingual) · Malay (native)
02

Experience

  1. Jun 2025 — Present

    Cybersecurity Analyst — Threat Intelligence & Red Team

    Kaiju Cybrsec Sdn Bhd · Kuala Lumpur, Malaysia

    • Engineered and operate an end-to-end threat-intelligence pipeline on OpenCTI, n8n and AWS ECS that automates IOC collection, enrichment and analysis — eliminating near-daily manual data gathering for the SOC.
    • Integrated five external intel feeds (AlienVault OTX, AbuseIPDB, CISA KEV, URLHaus, Maltiverse), automated connector lifecycle and feed ingestion with Python and AWS Lambda, and correlated Wazuh/SIEM alerts against enriched intelligence to validate IOCs and tune detections.
    • Run red-team adversary emulation for client cyber drills — developing custom payloads and PoC exploits and testing EDR/WAF/IDS evasion with Metasploit, Cobalt Strike, Sliver and bespoke Python tooling.
    • Produce technical assessment reports for cyber-drill engagements, documenting attack paths, CVSS-rated findings, PoC demonstrations and prioritised remediation guidance.
    • Build an in-house agentic AI security agent for automated vulnerability discovery — integrating LLMs, agentic workflows and API-based data ingestion, with coverage targets spanning web, API, cloud, internal and wireless.
  2. Feb 2025 — May 2025

    SOC Analyst

    CyberProof · Spain (Remote)

    • Monitored and triaged SIEM alerts for phishing, malware and unauthorised access; investigated incidents and documented root cause and resolution.
    • Analysed firewall, antivirus and network logs to surface anomalies and map emerging TTPs to the MITRE ATT&CK framework.
    • Refined detection rules and produced compliance reports, reducing false-positive volume across monitored client environments.
  3. Sep 2024 — Jan 2025

    Cybersecurity Intern

    Telekom Malaysia Berhad (TM) — Group Information Security · Cyberjaya, Malaysia

    • Ran penetration testing and ethical-hacking simulations with Kali Linux; assisted network security monitoring and incident escalation.
    • Evaluated VPN configurations and tested antivirus and endpoint solutions against known threat signatures.
    • Built hands-on experience in vulnerability assessment, intrusion detection and security compliance within a national telco environment.
03

Selected Work

A broad cross-section — offensive tooling, SOC/IR resources, full-stack products and research. Public repositories link to code; private, client and employer work is described at a high level only.

// Offensive Security, Threat Intel & IR

GhostScan

Public

Red-team recon CLI: subdomain enumeration, HTTP security-header auditing and concurrent TCP port scanning, in a Rich terminal UI.

  • Python
  • Click
  • Rich
  • dnspython
2026 Code

Red Team Cheatsheets

Public

Curated pentest command references: enumeration, Linux/Windows privilege escalation, Active Directory, web exploitation and post-exploitation.

  • Markdown
  • Nmap
  • Metasploit
  • MITRE ATT&CK
2026 Code

CTF Writeups

Public

Seven TryHackMe walkthroughs documenting a repeatable methodology across Linux and Windows boxes — enumeration, exploitation, privilege escalation.

  • Markdown
  • Metasploit
  • Linux
  • Windows
2026 Code

IR Playbook Library

Internal

Ten incident-response playbooks (ransomware, DDoS, APT, data theft, privilege escalation and more) structured on the NIST SP 800-61 lifecycle and mapped to MITRE ATT&CK.

  • NIST SP 800-61
  • MITRE ATT&CK
  • PICERL
2026 Employer work

Cyber TTX Platform

Internal

Full-stack platform for running live cyber-incident tabletop exercises — scenario authoring, real-time injects, decision scoring and after-action reporting.

  • Next.js
  • TypeScript
  • Prisma
  • PostgreSQL
2026 Employer work

Incident Captain

Private

Game-master co-pilot for running Backdoors & Breaches IR tabletops — composes turn-by-turn narrative and automates the rules, with optional AI-generated prose. A personal learning tool built on BHIS / Antisyphon's game.

  • JavaScript
  • Cloudflare Workers
  • Claude API
2026 Personal tool

// AI, Data & Automation

Project Almanac

Private

Experimental AI red-team assistant: an LLM agent that helps plan and organise offensive-security tooling across the MITRE ATT&CK lifecycle, to speed up authorised adversary-emulation work.

  • LLM Agents
  • Kali Linux
  • MITRE ATT&CK
2026 Concept / research

AdVision

Private

A modernised revision of an earlier computer-vision advertising project: estimates viewer age, gender and style (InsightFace, YOLO11, CLIP) to serve targeted ads — consent-first, with a hardened Flask API.

  • Python
  • Flask
  • PyTorch
  • YOLO11
2026 Computer vision

Rule-Based Trading Bot

Private

Automated daily equities engine on the Moomoo OpenAPI (paper trading) with a multi-layer risk engine, compliance screening, a news-sentiment gate and a SQLite audit journal, plus a walk-forward backtesting harness.

  • Python
  • pandas
  • Moomoo OpenAPI
  • SQLite
2026 Engineering project

// Apps, Products & Web

scantodo

Public

Zero-config TypeScript CLI that scans codebases for TODO / FIXME / HACK / NOTE comments across 15+ languages, with table, JSON and Markdown reports and CI-ready exit codes.

  • TypeScript
  • Node.js
  • Commander
2026 Code

AED Locator — KL Pilot

Private

Research prototype designed to help bystanders find the nearest defibrillator and alert nearby trained rescuers during cardiac arrest (notification delivery in progress) — a 999/MERS companion, not a certified device. Row-level security on every table, with PostGIS spatial queries.

  • Flutter
  • Supabase
  • PostGIS
  • Deno
2026 Research prototype

MABAR Queue

Private

Multi-tenant SaaS that turns donations into a live play-together queue: webhook ingestion, row-level security, a streamer dashboard, OBS overlay and seat-metered billing. Co-built with a small team.

  • Supabase
  • Deno
  • React
  • TypeScript
2026 Live

Share2Earn — Family Mobility Concept

Private

Mobile-first concept PWA where trusted helpers assist with digital tasks under task-scoped permissions, owner approval, risk-tiered actions, audit logging and step-up identity verification.

  • Next.js
  • React
  • TypeScript
  • PWA
2026 Team concept prototype

Lucky Seven

Private

Co-developed real-time multiplayer card game for 2–8 players: RLS-protected hidden hands, race-safe SECURITY DEFINER RPCs with row locking, and anonymous auth.

  • React
  • Supabase
  • Vite
  • Vitest
2026 Live

Kad Kita

Private

Config-driven platform for digital wedding invitations with swappable themes, RSVP and a wishes wall, and token-gated host dashboards — a shared multi-tenant backend that keeps each event's data isolated behind controlled functions.

  • JavaScript
  • Supabase
  • Node.js
2026 Multi-tenant SaaS

Homestay Booking Site

Private

Bilingual React booking site for a live homestay business: an availability calendar and booking requests for guests, plus an auth-protected admin panel secured with row-level security.

  • React
  • Vite
  • Tailwind
  • Supabase
2026 Live client site

Cybersecurity Firm Website

Private

Responsive marketing site for a cybersecurity services company (SOC, incident response, VAPT, forensics), built with the Next.js App Router, Framer Motion animations and dark/light theming.

  • Next.js
  • TypeScript
  • Tailwind
  • Framer Motion
2026 Employer project

// University & Research

Video Authentication System

University

Built a video authentication system to prevent unauthorised media access; hardened and optimised the code in collaboration with CyberSecurity Malaysia.

  • Security
  • Media Integrity
2023 w/ CyberSecurity Malaysia

AI-Driven Personalised Advertisement Robot System

University

Real-time computer-vision system for age and gender detection using Python, OpenCV, Flask and PyTorch; deployed on edge devices for low-latency inference.

  • Python
  • OpenCV
  • Flask
  • PyTorch
2023–2024 Computer vision

Computer Peripheral Shop Web App

University

Full-stack inventory web application with secure user authentication, built with HTML, CSS, JavaScript, PHP and MySQL.

  • PHP
  • MySQL
  • JavaScript
2022 Full-stack
04

Skills

Threat Intelligence & SOC

  • Threat Intelligence
  • OpenCTI
  • IOC Enrichment & Validation
  • Threat Hunting
  • SOC Operations
  • SIEM
  • Incident Response
  • Log Analysis
  • MITRE ATT&CK
  • Phishing Analysis
  • Malware Analysis
  • Wazuh

Red Teaming & Offensive Security

  • Adversary Emulation
  • Payload & Exploit Development
  • Proof-of-Concept Exploitation
  • EDR/WAF/IDS Evasion
  • Penetration Testing
  • Vulnerability Assessment
  • CVSS Severity Rating
  • Metasploit
  • Cobalt Strike
  • Sliver (C2)
  • Kali Linux

Threat-Intel Feeds & Tools

  • AlienVault OTX
  • AbuseIPDB
  • CISA KEV
  • URLHaus
  • Maltiverse
  • Wireshark
  • Nmap
  • Splunk (familiarity)

Defensive & Network Security

  • Network Security
  • Endpoint Security
  • Intrusion Detection
  • Firewalls
  • VPN Security
  • Risk Assessment
  • SQL Injection
  • XSS
  • DDoS
  • DNS Hijacking
  • Cryptography

Programming, Cloud & AI / Automation

  • Python
  • SQL
  • JavaScript
  • PHP
  • Java
  • AWS (Lambda, ECS, IoT)
  • LLM Integration
  • Agentic AI Workflows
  • n8n
  • Docker
  • Git
  • Flask
  • Pandas
  • Power BI
  • TensorFlow
  • OpenCV
05

Certifications

06

Education

Oct 2021 — Oct 2025

Bachelor of Computer Science — Artificial Intelligence (Honours)

Universiti Kebangsaan Malaysia (UKM)

Dean's List — Semesters 1, 2, 5 & 7

2020 — 2021

Foundation in Computer Science

Penang Matriculation College

07

Awards & Leadership

08

Contact

Happy to connect about threat intelligence, red teaming and SOC / incident response. The fastest way to reach me is email.