About
I’m a DFIR Specialist at SABIC, where I lead digital forensics and incident response work across IT and OT environments — forensic acquisition, investigation, containment, and turning what we learn from each case into playbooks that make the next one faster to handle. Before that, I spent a few years as a Cyber Security Sr. Analyst running SOC and incident response operations, and served for a stretch as SABIC’s regional cybersecurity SME for Greater China.
My path here started in software, not security: a software engineering degree from KFUPM, a stint as an Azure App Developer at Microsoft, and freelance web development work before I moved fully into cybersecurity. That background still shows up in how I approach this field — I like understanding systems well enough to build them, which turns out to be useful for taking them apart during an investigation too.
This blog is my technical notebook. Some of the earliest posts here are from when I was deep in Azure, DevOps, and .NET; more recent writing leans toward DFIR, SOC operations, and whatever I’m currently digging into. I write mostly for future-me, but if something here saves you time, that’s a bonus.
I’m based in Saudi Arabia and fluent in English and Arabic. You can find my full background on my portfolio site, or reach me directly through the links below.