Heartbeat
Internal threat operations platform for news aggregation, geolocation mapping, ransomware tracking, and LLM-assisted monthly TI review workflows.
Internal ToolTools Iβve built for threat intelligence, detection engineering, and incident response, from internal CTI workflows to public investigation utilities.
Internal threat operations platform for news aggregation, geolocation mapping, ransomware tracking, and LLM-assisted monthly TI review workflows.
Agentic threat intelligence and hunting workspace using RAG over live sources and uploaded reports to build executable Sentinel/XDR hunt packages.
Unified IP, domain, and hash investigation across VirusTotal, Shodan, GreyNoise, and AbuseIPDB.
EY
Support incident response engagements across triage, scoping, containment advisory, evidence coordination, and forensic artifact analysis. Manage CTI workflows, mentor analysts, and build internal tooling for threat operations and detection engineering.
LandingPad
Improved UI/UX resulting in 25% increase in user engagement. Redesigned frontend components using Tailwind CSS, Liquid (Shopify), and JavaScript. Integrated Shopify with QuickBooks.
Ensign InfoSecurity
Triaged 300+ security alerts using SIEM and CrowdStrike EDR, produced threat intelligence reports, and identified 50+ client-specific vulnerabilities from underground forums and feeds.
Digital Intelligence Service Β· Seconded to Cyber Security Agency of Singapore
Pioneer batch of Cyber Specialists conducting threat hunting, SOC monitoring, and digital forensics for government cyber operations and Critical Information Infrastructure environments.
Henderson Security Services Pte Ltd
Completed various full-stack development tasks during internship.
Triage, containment, root cause analysis, X-Ways, Magnet AXIOM, FTK Imager, Arsenal Image Mounter
OSINT, underground forum analysis, CVE analysis, threat actor profiling, detection engineering
Splunk SPL, Microsoft Sentinel KQL, QRadar, CrowdStrike, OpenCTI
Python, JavaScript, FastAPI, Claude, Gemini, OpenAI, RAG workflows, LLM integration
Cyber Defenders Discovery Camp - National cybersecurity competition
NUS Greyhats annual CTF competition
Annual cybersecurity conference and CTF
GovTech national CTF competition
Security Blue Team certification for junior Security Analysts
EC-Council certification for ethical hackers
Internal platform for weekly threat operations, automated security news aggregation, ransomware tracking, geolocation mapping, and monthly TI review workflows.
Uses RAG over live sources and uploaded reports to extract IOCs/TTPs, generate and validate behavior-led KQL, and guide analysts through Sentinel/XDR investigations.
Merge, splice, and rotate PDFs directly in your browser. 100% client-side - files never leave your device
Investigate IPs, domains, and file hashes in one place. Aggregates intel from VirusTotal, Shodan, GreyNoise, and AbuseIPDB
PowerShell automation for Windows Defender control in malware analysis environments
AI-powered script and voiceover generation for PowerPoint presentations
Automated threat intelligence report summarization using OpenAI
Telegram bot for budget tracking and expense management
Web scraper for validating licenses in Singapore's Energy Market Authority database
Dependency installer for Volatility 2 on Kali Linux ARM architecture
A CS443 write-up on process memory modification, entity traversal, and safe game-state visualization in an offline lab
How I built a privacy-first PDF merger with cross-file page management
Analysis of a new hybrid infostealer targeting gaming platforms
Uncovering a RAT masquerading as a popular credential stealer
Ask Ashraff