Skip to content

Mohamed Atef

Cyber Defense Lead
& Consultant

I lead Resident SOC and Managed SOC teams, design defense architectures, and conduct DFIR investigations and compromise assessments.

My approach is ThreatOps: connecting intelligence, hunting, detection engineering and incident response across defensive operations.

Explore my experience Get in touch

Mohamed Atef
Mohamed AtefCyber Defense Lead & Consultant

Leadership & architecture

Resident and Managed SOC operations, team development, SOC maturity and defense architecture.

Investigations & detection

DFIR, threat hunting, compromise assessments and detections informed by adversary behavior.

ThreatOps & automation

Connected defensive operations, security platform integrations and Python, API and n8n workflows.

7 MAD20 certifications · eCTHPv2 · Group-IB CTI & Cyber Investigator · Belkasoft
View credentials

Selected work

Compromise assessment & Cordon
Assessment methodology and forensic collection for OpenShift environments.

Multi-tenant Elastic architecture
Separating client data through explicit tenant identity, routing and quarantine.

ThreatOps-CTI & MISP
Connecting intelligence collection with hunting, detection and SOC workflows.

Projects

From the notebook

Published Article
26 Apr 2025 Argus CTI: RSS threat-feed pipeline for MISP
24 Apr 2025 MISP deployment
07 Sep 2024 API to QRadar through syslog middleware

Writing