m
mahrooshaaltaf

Mahroosha Altaf

@mahrooshaaltaf

Penetration Tester, Malware Analyst

Pakistan
Urdu, Hindi, Inglese, Turco
Alcune informazioni sono riportate in lingua inglese.
Chi sono
Cybersecurity Professional with 5+ years of experience in malware analysis, vulnerability research, VAPT, SOC/SIEM operations, security automation, and GRC. Analyzed 100+ malware samples and researched 1000+ CVEs through exploit validation and IPS/Suricata signature development. Skilled in SIEM monitoring, threat hunting, IOC analysis, incident response, ISO 27001, NIST, PCI DSS, risk assessment, and compliance audits. Proficient in Python, Bash, ML, and Generative AI for security automation and detection engineering. ... Continua a leggere

Competenze

m
mahrooshaaltaf
Mahroosha Altaf
offline • 

Consulta i miei servizi

Programmazione e tecnologia
I will web application security testing and penetration testing

Esperienza lavorativa

Ebryx

Malware Researcher

Ebryx • Full time

Dec 2023 - Present • 2 yrs 9 mos

• Worked on 1000+ CVEs, reproducing PoC exploits and analyzing vulnerability impact, exploit chains, and attacker techniques. • Developed and validated Suricata IDS/IPS signatures across multiple protocols, focusing on high detection accuracy and minimizing false positives and rework. • Performed static, dynamic, code, and network traffic analysis of malware and exploitation activity, extracting IOCs and identifying malicious behavior. • Conducted deep PCAP and protocol analysis across HTTP/HTTPS, SMTP, SSH, FTP, LDAP, NetBIOS, VNC, and other application-layer protocols. • Built Python and Bash automation for IOC extraction, CVE processing, signature generation, log analysis, testing, and security research workflows. • Developed an XML-to-Suricata rule conversion tool and contributed to automated signature/unit-testing workflows, reducing manual effort and improving research efficiency. • Applied Machine Learning and Generative AI to ransomware detection, threat intelligence, vulnerability analysis, and AI-assisted security automation. • Contributed to MITRE ATT&CK mapping, threat intelligence, and detection coverage improvements. • Mentor team members on vulnerability research, exploit analysis, PCAP generation, Metasploit/Python exploitation, and signature development. • Recognized with Best Quarterly Performance and Best Annual Performance awards for technical contribution and performance.

Pakistan_Air Force

Malware Analyst

Pakistan Air Force • Full time

Aug 2021 - Dec 2023 • 2 yrs 4 mos

• Built and ran malware analysis operations from the ground up, from lab infrastructure to live incident response.   • Identified malicious behavior and attack techniques across 100+ real-world malware samples through static, dynamic, code, and automated analysis   • Strengthened PAF Hospital's security posture by leading a full VAPT engagement and delivering prioritized remediation recommendations   • Accelerated incident containment by triaging SIEM alerts, analyzing logs, and correlating IOCs alongside the SOC team during active incidents   • Contributed to red team exercises simulating adversary techniques to pressure-test detection and response readiness

Prescient

Auditor

Prescient • Part time

Dec 2020 - Aug 2021 • 8 mos

• Validated security compliance posture for client organizations ahead of certification. • Validated compliance readiness for multiple client organizations by auditing security controls and evidence using Secureframe and Tugboat Logic.   • Reduced audit remediation turnaround by systematically tracking outstanding control gaps through to completio