Mohamed Atef
Cyber Defense Lead
& Consultant
I lead Resident SOC and Managed SOC teams, design defense architectures, and conduct DFIR investigations and compromise assessments.
My approach is ThreatOps: connecting intelligence, hunting, detection engineering and incident response across defensive operations.
Explore my experience Get in touch
Leadership & architecture
Resident and Managed SOC operations, team development, SOC maturity and defense architecture.
Investigations & detection
DFIR, threat hunting, compromise assessments and detections informed by adversary behavior.
ThreatOps & automation
Connected defensive operations, security platform integrations and Python, API and n8n workflows.
7 MAD20 certifications · eCTHPv2 · Group-IB CTI & Cyber Investigator · Belkasoft
View credentials
Selected work
Compromise assessment & Cordon
Assessment methodology and forensic collection for OpenShift environments.
Multi-tenant Elastic architecture
Separating client data through explicit tenant identity, routing and quarantine.
ThreatOps-CTI & MISP
Connecting intelligence collection with hunting, detection and SOC workflows.
From the notebook
| Published | Article |
|---|---|
| 26 Apr 2025 | Argus CTI: RSS threat-feed pipeline for MISP |
| 24 Apr 2025 | MISP deployment |
| 07 Sep 2024 | API to QRadar through syslog middleware |