<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Projects on Talal Ahmed</title><link>https://ta1al.com/projects/</link><description>Recent content in Projects on Talal Ahmed</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Tue, 21 Jul 2026 00:00:00 +0500</lastBuildDate><atom:link href="https://ta1al.com/projects/index.xml" rel="self" type="application/rss+xml"/><item><title>Home SOC Lab: Detection, Firewall Telemetry, and Alert Automation</title><link>https://ta1al.com/projects/home-soc-lab/</link><pubDate>Wed, 15 Apr 2026 00:00:00 +0500</pubDate><guid>https://ta1al.com/projects/home-soc-lab/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;This lab brings endpoint telemetry, firewall events, and alert delivery into one practical SOC workflow. Wazuh provides centralized monitoring, pfSense adds network-level visibility and control, Sysmon enriches Windows process data, and n8n forwards higher-priority alerts to Discord.&lt;/p&gt;
&lt;p&gt;The environment was validated with file-integrity tests and a controlled malware exercise. The malware report describes the sample as Zeus while recording a Windows Defender identification of &lt;code&gt;TrojanDropper:Win32/Sirefef.gen!B&lt;/code&gt;; this case study preserves that distinction rather than treating the family attribution as independently confirmed.&lt;/p&gt;</description></item><item><title>WannaCry Malware Analysis</title><link>https://ta1al.com/projects/wannacry-malware-analysis/</link><pubDate>Fri, 13 Mar 2026 00:00:00 +0500</pubDate><guid>https://ta1al.com/projects/wannacry-malware-analysis/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;This analysis examined a WannaCry sample with static inspection and interactive sandbox observation. The work focused on what the binary appeared capable of, which behaviors were observed at runtime, and how those findings translate into defensible detection and response actions.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;SHA-256: ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Target: Windows 10 Professional, build 19044, 64-bit
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="objectives"&gt;Objectives&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Identify meaningful strings, imports, and other static indicators.&lt;/li&gt;
&lt;li&gt;Observe the process tree, filesystem changes, registry activity, and network behavior.&lt;/li&gt;
&lt;li&gt;Correlate static capabilities with runtime evidence.&lt;/li&gt;
&lt;li&gt;Produce detection, containment, eradication, and recovery actions grounded in the observed sample.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="environment-and-architecture"&gt;Environment and architecture&lt;/h2&gt;
&lt;p&gt;The local target was a Windows 10 guest in VirtualBox with a host-only adapter to prevent access to the physical host or external network. A clean snapshot and Regshot baseline were created before execution.&lt;/p&gt;</description></item><item><title>Automated SRS Generator</title><link/><pubDate>Tue, 21 Jul 2026 00:00:00 +0500</pubDate><guid/><description/></item><item><title>Timetable Parser</title><link/><pubDate>Tue, 21 Jul 2026 00:00:00 +0500</pubDate><guid/><description/></item><item><title>University Department Website</title><link/><pubDate>Tue, 21 Jul 2026 00:00:00 +0500</pubDate><guid/><description/></item><item><title>Countr</title><link/><pubDate>Tue, 21 Jul 2026 00:00:00 +0500</pubDate><guid/><description/></item><item><title>Tickets</title><link/><pubDate>Tue, 21 Jul 2026 00:00:00 +0500</pubDate><guid/><description/></item><item><title>Portfolio Website</title><link/><pubDate>Tue, 21 Jul 2026 00:00:00 +0500</pubDate><guid/><description/></item><item><title>Malware Detection with ML</title><link/><pubDate>Tue, 21 Jul 2026 00:00:00 +0500</pubDate><guid/><description/></item></channel></rss>