Muhammad Abdullah

~/blog

Ship Log.

SOC case writeups and the occasional build note — summarized here, written in full on Hashnode.

~/featured

Featured posts

Ship Log2026-08-05

SOC176 | RDP Brute Force Detected

A brute force RDP incident where failed login attempts were followed by a successful compromise, confirmed by authentication logs and contained.

read on Ship Log
Ship Log2026-08-05

SOC205 | Malicious Macro Has Been Executed

A malicious macro-enabled Word document executed PowerShell to download and run malware, confirmed as a true positive and contained.

read on Ship Log
Ship Log2026-08-05

SOC338 | Lumma Stealer, DLL Side-Loading via ClickFix Phishing

A ClickFix phishing case that delivered Lumma Stealer through DLL side-loading and user-driven execution, with endpoint containment after confirmation.

read on Ship Log
Ship Log2026-07-19

SOC104 | Malware Detected

A malware investigation that connects hash reputation, execution behavior, and network activity for a clean true positive.

read on Ship Log
Ship Log2026-07-19

SOC137 | Malicious File/Script Download Attempt

Investigation notes from a malicious file download alert, tracing the case from detection through C2 analysis and containment.

read on Ship Log
Ship Log2026-07-19

SOC138 | Detected Suspicious Xls File

Notes from a suspicious Excel attachment case, showing how persistence and malicious macros were identified and contained.

read on Ship Log
Ship Log2026-07-19

SOC145 | Ransomware Detected

A ransomware case where detection occurred but prevention did not, highlighting why containment matters before encryption spreads.

read on Ship Log
Ship Log2026-07-19

SOC146 | Phishing Mail Detected: Excel 4.0 Macros (Real Attack)

A real phishing case involving legacy Excel 4.0 macros, live C2, and signed binary proxy execution.

read on Ship Log
Ship Log2026-07-19

SOC168 | Whoami Command Detected in Request Body

Investigation details from a command injection alert, confirming execution through endpoint command history.

read on Ship Log
Ship Log2026-07-19

SOC169 | Possible IDOR Attack Detected

A web application security writeup on sequential ID enumeration and how response behavior can reveal broken access control.

read on Ship Log
Ship Log2026-07-19

SOC325 | Unauthorized Cloud Region Access Attempt Detected

A cloud security writeup on a brute force access attempt through an unused AWS region and the visibility gaps that make it possible.

read on Ship Log
Ship Log2026-07-19

SOC336 | Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298)

A zero-click RTF exploit case study, with details on phishing delivery, execution, and post-compromise detection.

read on Ship Log
Ship Log2026-06-07

SOC335 — CVE-2024-49138 Exploitation Detected: Full Walkthrough

A step-by-step walkthrough of a privilege escalation alert, from CLFS exploit detection to incident response.

read on Ship Log
Ship Log2026-04-20

Ship Log #3 | I shipped SoloDesk: A full Freelancer OS built for Pakistani freelancers

A product update on shipping SoloDesk, a freelancer OS with client portals, project workflows, and AI-assisted communication.

read on Ship Log
Ship Log2026-04-12

I built a GitHub analytics dashboard inside a 3D solar system

A launch post about Stack Universe's 3D GitHub analytics dashboard and the product lessons learned along the way.

read on Ship Log
Ship Log2026-04-08

Why I'm Building in Public?

A personal post about the motivation for building in public and why documenting product progress matters.

read on Ship Log