The Malaysian digital-risk picture an analyst in Kuala Lumpur works against, a live brand-impersonation investigation built from public sources, and the method and boundaries I would bring. The demo runs the investigation end to end.
A new KL analysis cell takes alerts and client questions, investigates them in open sources, and writes intelligence a leader can act on. The posting asks for independent judgement and for spotting when an isolated incident is part of something larger.
A working investigation of brand impersonation against Malaysian banks, wallets and agencies: certificate logs, recent scans, lookalike domains and phishing feeds, enriched with DNS, routing and registry data, linked by shared infrastructure, graded and reported, then worked as cases through to takedown and STIX export.
Challenge the data before reporting it. The first run looked like an 11-domain campaign; a random-name probe showed the registry answers every name. What survives gets a source grade, a confidence level and an open-questions list.
The one line: connect the dots, then test whether the dots are real.
From Forward Defense's own website and company page.
| Item | Public record | What it means for the analyst |
|---|---|---|
| The firm | Cybersecurity consultancy headquartered in Abu Dhabi, with offices in Dubai and Kuala Lumpur. Services: telecom security, government services (OSINT, cyber threat intelligence, forensics and media exploitation), active cyber defence. | Intelligence work sits inside a security practice with lab forensics and offensive testing next door. |
| The KL team | Hiring in KL since Jan 2026: a Threat Hunter for digital risk and impersonation monitoring, this analyst role, and a Lead Intelligence Analyst (Sep 2026). | A young team: the analyst helps set report formats, coverage and process. |
| Partner platforms | Recorded Future, Intel 471, Cyabra, Fivecast, Cyware; forensics vendors Magnet, MSAB, OpenText EnCase, ADF. | Alert triage likely starts in a commercial platform; the analyst adds the open-source work and the judgement. |
| The posting | "Own investigations end-to-end", "confidence levels and open questions", "when isolated incidents signal a broader or coordinated threat". | Structured analysis and calibrated writing are the job. |
Sources: forwarddefense.com (services, partners, careers) and the Forward Defense company page on LinkedIn, read 7 Oct 2026.
The threats a KL digital-risk analyst would see most, with the dated public figure behind each.
| Threat | Public record | Collection angle |
|---|---|---|
| Fake investment schemes | RM5.37bn lost to online scams from 2024 to May 2026; non-existent investments were 49.9% of it (Home Minister, parliamentary reply, Jul 2026). RM830m lost Jan to May 2026. | Lookalike domains and landing pages named after banks and investment arms; ad and social promotion. |
| Deepfaked leaders | Police flagged deepfake investment videos of the Prime Minister, PETRONAS management and others (Mar 2025). | Video verification, account and page clustering, takedown routes under the Online Safety Act 2025. |
| Phishing channels moving | SMS links are blocked, so phishing moved to RCS, iMessage, WhatsApp and Telegram (MCMC via Bernama, Aug 2026). | Domains still need certificates and DNS: infrastructure is where campaigns show. |
| Data exposure | A dark-web portal sold over 400 million Malaysian records (police, Oct 2024); a telco billing leak under PDPA investigation (Jul 2026). | Track exposure through reporting and lawful sources; never buy or handle leaked sets. |
| Hacktivism | NACSA advisories on Middle East-linked campaigns; the Ministry of Health website was defaced in Jun 2026. | Channel monitoring and claim verification before escalation. |
Sources: The Vibes (15 Jul 2026), Business Today (24 Jun 2026), Malay Mail (12 Mar 2025, 22 Jul 2026), Bernama (20 Aug 2026), FMT (17 Oct 2024). Links in §07.
One run of the demo against Maybank, 7 Oct 2026. Every number below is reproducible in the demo; results change as the internet does.
| Stage | What happened | Analytic point |
|---|---|---|
| Collect | 464 certificates naming the brand, 107 recent third-party scans of brand-named domains, 420 lookalike names checked in DNS (8 registered), two phishing feeds. | Four independent collection paths; each graded on its own. |
| Challenge | A first pass linked 11 odd .ph domains on one IP into a "campaign". A random made-up .ph name resolved to the same IP: the registry answers every name. 18 such names were set aside as non-existent. | The pattern that looks most like a campaign was an artefact. Test the data before reporting it. |
| Exclude | 28 domains set aside as probably brand-owned: same IPs or name servers as official domains, the bank's own network, or only organisation-grade certificates. | Unflagging the client's own subsidiaries is part of the job. |
| Challenge again | Two dynamic-DNS hosts named after Maybank share one IP and sit on a phishing list. The registry record for that IP range names HYAS, a threat-intelligence firm, so both are probably sinkholed already. The tool now flags this and keeps sinkhole IPs out of clustering. | A shared IP can mean a defender seized both names. Check who holds the range before calling it one operator. |
| Connect | Several domains pairing "maybank" with "investment" appeared within five weeks, one registered two days before the run. Pivoting on the lead domain's IP shows it hosted beside a batch of throwaway .sbs domains scanned the same week. | Matches the largest Malaysian loss category, fake investments. Lead for a campaign, pending page evidence. |
| Act | Each domain opens as a case: triage state and notes, certificate history, the last public screenshot, registrar and hosting abuse contacts from RDAP, and a defanged takedown notice copied to MyCERT. Re-runs list what is new, a re-check marks takedowns offline, and indicators export as CSV or STIX 2.1 with a TLP marking. | The job continues after the report: takedown, tracking and sharing with the client's tools. |
| Report | A drafted assessment: bottom line, key judgements in estimative language, recommended actions, gaps, Admiralty grades per source, an evidence list, and a log of 683 requests with SHA-256. | Findings a reader can act on and audit. |
Domains are named in the demo's own output with their evidence. Flagged means "uses the brand name and is not on the brand's list"; ownership stays unconfirmed until checked.
| JD duty | How I would do it | Shown in |
|---|---|---|
| Triage alerts for relevance, credibility, significance | Grade the source and the claim separately (Admiralty), check the alert against a second independent source before spending time on it, and log why each alert was closed. | Demo: source grades |
| Independent OSINT research | Pivot from the first indicator to infrastructure, accounts and people; record every query with time and hash. | Demo: evidence log |
| Correlate across sources and history | Link by shared IPs, name servers, registrars, certificates and timing; compare against earlier cases. | Demo: clusters |
| Structured analytic techniques | Analysis of competing hypotheses for attribution questions, a key-assumptions check before every judgement, devil's advocacy on the strongest finding. | §04 |
| Clear, evidence-based reports | Bottom line first, key judgements with estimative language and confidence, gaps and open questions, recommended actions. | Demo: report |
| Escalate promptly | Escalate live, high-confidence findings the same hour with what is known and unknown; follow with the full product. | §04 |
| Own investigations and improve the process | Case log per investigation, reusable pivots and templates, a monthly review of misses. | §06 |
Admiralty: source reliability A to F, information credibility 1 to 6. A reliable source can carry an unconfirmed claim, and the report should show both.
"Almost certainly", "likely", "roughly even chance", "unlikely", each tied to a probability range, with a separate confidence level for the evidence base.
For "one operator or many?": list the hypotheses, score each piece of evidence against all of them, and keep the one with the least evidence against it.
Every request logged with UTC time, status and a hash of the response, so a finding can be re-checked later and a changed source detected.
| Line | Malaysian rule | In practice |
|---|---|---|
| No unauthorised access | Computer Crimes Act 1997 s.3 | No logins with found credentials, no bypassing access controls |
| No leaked data sets | PDPA 2010 s.130; the Oct 2024 400-million-record case | Exposure is assessed from reporting and lawful services |
| No published dossiers | Penal Code ss.507B to 507G (in force 11 Jul 2025), incl. doxxing | Products are confidential and need-to-know |
| Data minimised and secured | PDPA as amended 2024 (DPO and breach notification from 1 Jun 2025) | Collect what the question needs; retention rules per case |
| Analyst stays unseen | Operational security | No direct visits to suspect sites; managed research environments |
| Window | Work | Done when |
|---|---|---|
| Days 1 to 30 | Learn the platforms, client requirements and report formats; shadow triage; build a pivot checklist per alert type. | Own a triage queue with logged decisions |
| Days 31 to 60 | Run investigations end to end; first periodic summary; propose one coverage gap to close. | Reports delivered on time with confidence and gaps stated |
| Days 61 to 90 | Monthly trend product; reusable templates and case log; review of misses with the lead. | The team uses one improvement I built |
Outside-in, from public data only (public job posting, 2026). The demo uses crt.sh, urlscan.io search, Cloudflare DNS over HTTPS, RIPEstat, domain and IP RDAP (registries and regional internet registries via the IANA bootstrap files), OpenPhish and Phishing.Database.
Company: forwarddefense.com · partners · careers · company page
Scams: RM5.37bn reply · Jan to May 2026 · channel shift
Deepfakes and data: deepfake warning · 400m records case · PDPA probe
Law: Penal Code 2025 · Online Safety Act
Independent homework by Edward Tay for the Forward Defense analyst application in Kuala Lumpur. Public data only, no confidential Forward Defense information. The demo is my own prototype.