Skip to content
Abdullah

Long-form

Blog

Original writing, separate from dev.to. Longer explorations, working notes, and things that don't fit in a short-form article.

SOC176 | RDP Brute Force Detected

SOC176 | RDP Brute Force Detected

Platform: LetsDefend Date Investigated: March 07, 2024 Severity: Medium Verdict: True Positive ✅ Actions Taken: Endpoint contained Summary On March 7, 2024 at 11:44 AM, an alert fired after multiple f

August 5, 20261 min read
SOC205 | Malicious Macro Has Been Executed

SOC205 | Malicious Macro Has Been Executed

Platform: LetsDefend Date Investigated: February 28, 2024 Severity: Medium Verdict: True Positive ✅ Actions Taken: Endpoint contained Summary A malicious Word document disguised as an invoice was deli

August 5, 20261 min read
SOC338 | Lumma Stealer, DLL Side-Loading via ClickFix Phishing

SOC338 | Lumma Stealer, DLL Side-Loading via ClickFix Phishing

Platform: LetsDefend Date Investigated: March 13, 2025 Severity: Critical Category: Data Leakage Verdict: True Positive ✅ Actions Taken: Email deleted, endpoint contained Summary A phishing email impe

August 5, 20261 min read
Coming Back to Writing = and My First Cybersecurity Project

Coming Back to Writing = and My First Cybersecurity Project

It's been a while since I've written anything publicly. I used to be fairly active documenting what I was building as a developer, and somewhere along the way - between shipping products and then pivo

July 28, 20261 min read
Second Project Back: A Phishing Email Analyzer (Still a Beginner, Still Learning)

Second Project Back: A Phishing Email Analyzer (Still a Beginner, Still Learning)

A little while ago I wrote about coming back to documenting my work after a long quiet stretch, starting with a small IOC enrichment tool. This is the next entry in that same habit — a phishing email

July 28, 20261 min read
SOC104 | Malware Detected

SOC104 | Malware Detected

Platform: LetsDefend Date Investigated: December 01, 2020 Severity: High Verdict: True Positive ✅ Summary A malware detection fired on an endpoint on December 1, 2020 at 10:23 AM. The file hash came b

July 19, 20261 min read
SOC137 | Malicious File/Script Download Attempt

SOC137 | Malicious File/Script Download Attempt

Platform: LetsDefend Date Investigated: March 14, 2021 Severity: Medium Verdict: True Positive ✅ File Quarantined: Yes Summary A malicious file was downloaded onto NicolasPRD on Mar 14, 2021 at 07:15

July 19, 20261 min read
SOC138 | Detected Suspicious Xls File

SOC138 | Detected Suspicious Xls File

Platform: LetsDefend Date Investigated: March 13, 2021 Verdict: True Positive ✅ Contained: Yes Summary A suspicious Excel attachment, ORDER SHEET and SPEC.xlsm, landed on endpoint Sofia (172.16.17.56)

July 19, 20261 min read
SOC145 | Ransomware Detected

SOC145 | Ransomware Detected

Platform: LetsDefend Date Investigated: May 23, 2021 Severity: Critical Verdict: True Positive ✅ Note: This alert was re-investigated Summary EDR/AV flagged ab.exe on host MarkPRD as ransomware at 19:

July 19, 20261 min read
SOC146 | Phishing Mail Detected: Excel 4.0 Macros (Real Attack)

SOC146 | Phishing Mail Detected: Excel 4.0 Macros (Real Attack)

Platform: LetsDefend Severity: High Date Investigated: June 21, 2026 Verdict: True Positive ✅ Flag: ⭐ This alert was generated from a real phishing attack. Summary This case started as a standard phi

July 19, 20261 min read
SOC168 | Whoami Command Detected in Request Body

SOC168 | Whoami Command Detected in Request Body

Platform: LetsDefend Date Investigated: February 28, 2022 Verdict: True Positive ✅ Note: This alert was reinvestigated after the first pass Summary The rule fired because the request body contained th

July 19, 20261 min read
SOC169 | Possible IDOR Attack Detected

SOC169 | Possible IDOR Attack Detected

Platform: LetsDefend Date Investigated: February 28, 2022 Verdict: True Positive ✅ Escalated: Yes, sent to Tier 2 Summary The alert fired because the same external IP sent several requests to the same

July 19, 20261 min read
SOC325 | Unauthorized Cloud Region Access Attempt Detected

SOC325 | Unauthorized Cloud Region Access Attempt Detected

Platform: LetsDefend Date Investigated: September 24, 2024 Severity: Low Verdict: True Positive ✅ Device Isolated: No Summary An external IP launched a brute force attack against AWS services on Sep 2

July 19, 20261 min read
SOC336 | Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298)

SOC336 | Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298)

Platform: LetsDefend Date Investigated: February 04, 2025 Severity: Critical Verdict: True Positive ✅ File Quarantined: No Summary A phishing email carrying a password-protected RTF attachment landed

July 19, 20261 min read
SOC335 — CVE-2024-49138 Exploitation Detected: Full Walkthrough

SOC335 — CVE-2024-49138 Exploitation Detected: Full Walkthrough

Platform: LetsDefendAlert: SOC335 - CVE-2024-49138 Exploitation DetectedEventID: 313Type: Privilege EscalationSeverity: MediumVerdict: True Positive Introduction This is a walkthrough of the SOC335 a

June 7, 20261 min read
Ship Log #3 | I shipped SoloDesk: A full Freelancer OS built for Pakistani freelancers

Ship Log #3 | I shipped SoloDesk: A full Freelancer OS built for Pakistani freelancers

Freelancers are among the most active in the world. But most of them are managing clients on WhatsApp, tracking projects in their head, and writing invoices in chat messages. I built SoloDesk to fix t

April 20, 20261 min read
I built a GitHub analytics dashboard inside a 3D solar system

I built a GitHub analytics dashboard inside a 3D solar system

Seven weeks ago I started Stack Universe as a side project with one question I could not get out of my head. GitHub profiles are boring. What if all that data looked like something alive? Today Phase

April 12, 20261 min read
Why I'm Building in Public?

Why I'm Building in Public?

Right now I'm working on Stack Universe || a web app that turns your GitHub profile into an interactive 3D solar system. Your repos become planets, commits turn into meteor showers, and an AI narrator

April 8, 20261 min read