INVESTIGATION HOMEWORK ·Digital Forensics Analyst (Digital Intelligence & Investigations), Forward Defense, Kuala Lumpur
ⓘ Independent job-application page. Not affiliated with, endorsed by, or operated by Forward Defense. Public information as of 7 October 2026.

Homework for my application to Forward Defense Digital Forensics Analyst.

The Malaysian digital-risk picture an analyst in Kuala Lumpur works against, a live brand-impersonation investigation built from public sources, and the method and boundaries I would bring. The demo runs the investigation end to end.

RM5.37bn
lost to online scams in Malaysia, 2024 to May 2026; half through fake investments
683
requests in one demo run, each logged with UTC time and SHA-256
18
"Maybank" domains a naive run would flag that do not exist (.ph wildcard DNS)
0
suspect sites visited: page content comes only from scans others already made
00

Summary

The work

A new KL analysis cell takes alerts and client questions, investigates them in open sources, and writes intelligence a leader can act on. The posting asks for independent judgement and for spotting when an isolated incident is part of something larger.

The demonstration

A working investigation of brand impersonation against Malaysian banks, wallets and agencies: certificate logs, recent scans, lookalike domains and phishing feeds, enriched with DNS, routing and registry data, linked by shared infrastructure, graded and reported, then worked as cases through to takedown and STIX export.

The habit

Challenge the data before reporting it. The first run looked like an 11-domain campaign; a random-name probe showed the registry answers every name. What survives gets a source grade, a confidence level and an open-questions list.

The one line: connect the dots, then test whether the dots are real.

01

The KL cell in context

From Forward Defense's own website and company page.

ItemPublic recordWhat it means for the analyst
The firmCybersecurity consultancy headquartered in Abu Dhabi, with offices in Dubai and Kuala Lumpur. Services: telecom security, government services (OSINT, cyber threat intelligence, forensics and media exploitation), active cyber defence.Intelligence work sits inside a security practice with lab forensics and offensive testing next door.
The KL teamHiring in KL since Jan 2026: a Threat Hunter for digital risk and impersonation monitoring, this analyst role, and a Lead Intelligence Analyst (Sep 2026).A young team: the analyst helps set report formats, coverage and process.
Partner platformsRecorded Future, Intel 471, Cyabra, Fivecast, Cyware; forensics vendors Magnet, MSAB, OpenText EnCase, ADF.Alert triage likely starts in a commercial platform; the analyst adds the open-source work and the judgement.
The posting"Own investigations end-to-end", "confidence levels and open questions", "when isolated incidents signal a broader or coordinated threat".Structured analysis and calibrated writing are the job.

Sources: forwarddefense.com (services, partners, careers) and the Forward Defense company page on LinkedIn, read 7 Oct 2026.

02

Malaysian digital risk

The threats a KL digital-risk analyst would see most, with the dated public figure behind each.

ThreatPublic recordCollection angle
Fake investment schemesRM5.37bn lost to online scams from 2024 to May 2026; non-existent investments were 49.9% of it (Home Minister, parliamentary reply, Jul 2026). RM830m lost Jan to May 2026.Lookalike domains and landing pages named after banks and investment arms; ad and social promotion.
Deepfaked leadersPolice flagged deepfake investment videos of the Prime Minister, PETRONAS management and others (Mar 2025).Video verification, account and page clustering, takedown routes under the Online Safety Act 2025.
Phishing channels movingSMS links are blocked, so phishing moved to RCS, iMessage, WhatsApp and Telegram (MCMC via Bernama, Aug 2026).Domains still need certificates and DNS: infrastructure is where campaigns show.
Data exposureA dark-web portal sold over 400 million Malaysian records (police, Oct 2024); a telco billing leak under PDPA investigation (Jul 2026).Track exposure through reporting and lawful sources; never buy or handle leaked sets.
HacktivismNACSA advisories on Middle East-linked campaigns; the Ministry of Health website was defaced in Jun 2026.Channel monitoring and claim verification before escalation.

Sources: The Vibes (15 Jul 2026), Business Today (24 Jun 2026), Malay Mail (12 Mar 2025, 22 Jul 2026), Bernama (20 Aug 2026), FMT (17 Oct 2024). Links in §07.

★

A live investigation

One run of the demo against Maybank, 7 Oct 2026. Every number below is reproducible in the demo; results change as the internet does.

StageWhat happenedAnalytic point
Collect464 certificates naming the brand, 107 recent third-party scans of brand-named domains, 420 lookalike names checked in DNS (8 registered), two phishing feeds.Four independent collection paths; each graded on its own.
ChallengeA first pass linked 11 odd .ph domains on one IP into a "campaign". A random made-up .ph name resolved to the same IP: the registry answers every name. 18 such names were set aside as non-existent.The pattern that looks most like a campaign was an artefact. Test the data before reporting it.
Exclude28 domains set aside as probably brand-owned: same IPs or name servers as official domains, the bank's own network, or only organisation-grade certificates.Unflagging the client's own subsidiaries is part of the job.
Challenge againTwo dynamic-DNS hosts named after Maybank share one IP and sit on a phishing list. The registry record for that IP range names HYAS, a threat-intelligence firm, so both are probably sinkholed already. The tool now flags this and keeps sinkhole IPs out of clustering.A shared IP can mean a defender seized both names. Check who holds the range before calling it one operator.
ConnectSeveral domains pairing "maybank" with "investment" appeared within five weeks, one registered two days before the run. Pivoting on the lead domain's IP shows it hosted beside a batch of throwaway .sbs domains scanned the same week.Matches the largest Malaysian loss category, fake investments. Lead for a campaign, pending page evidence.
ActEach domain opens as a case: triage state and notes, certificate history, the last public screenshot, registrar and hosting abuse contacts from RDAP, and a defanged takedown notice copied to MyCERT. Re-runs list what is new, a re-check marks takedowns offline, and indicators export as CSV or STIX 2.1 with a TLP marking.The job continues after the report: takedown, tracking and sharing with the client's tools.
ReportA drafted assessment: bottom line, key judgements in estimative language, recommended actions, gaps, Admiralty grades per source, an evidence list, and a log of 683 requests with SHA-256.Findings a reader can act on and audit.

Domains are named in the demo's own output with their evidence. Flagged means "uses the brand name and is not on the brand's list"; ownership stays unconfirmed until checked.

03

JD duties, my approach

JD dutyHow I would do itShown in
Triage alerts for relevance, credibility, significanceGrade the source and the claim separately (Admiralty), check the alert against a second independent source before spending time on it, and log why each alert was closed.Demo: source grades
Independent OSINT researchPivot from the first indicator to infrastructure, accounts and people; record every query with time and hash.Demo: evidence log
Correlate across sources and historyLink by shared IPs, name servers, registrars, certificates and timing; compare against earlier cases.Demo: clusters
Structured analytic techniquesAnalysis of competing hypotheses for attribution questions, a key-assumptions check before every judgement, devil's advocacy on the strongest finding.§04
Clear, evidence-based reportsBottom line first, key judgements with estimative language and confidence, gaps and open questions, recommended actions.Demo: report
Escalate promptlyEscalate live, high-confidence findings the same hour with what is known and unknown; follow with the full product.§04
Own investigations and improve the processCase log per investigation, reusable pivots and templates, a monthly review of misses.§06
04

Analytic method

Source and claim, graded apart

Admiralty: source reliability A to F, information credibility 1 to 6. A reliable source can carry an unconfirmed claim, and the report should show both.

Calibrated words

"Almost certainly", "likely", "roughly even chance", "unlikely", each tied to a probability range, with a separate confidence level for the evidence base.

Competing hypotheses

For "one operator or many?": list the hypotheses, score each piece of evidence against all of them, and keep the one with the least evidence against it.

Evidence that holds up

Every request logged with UTC time, status and a hash of the response, so a finding can be re-checked later and a changed source detected.

05

Boundaries

LineMalaysian ruleIn practice
No unauthorised accessComputer Crimes Act 1997 s.3No logins with found credentials, no bypassing access controls
No leaked data setsPDPA 2010 s.130; the Oct 2024 400-million-record caseExposure is assessed from reporting and lawful services
No published dossiersPenal Code ss.507B to 507G (in force 11 Jul 2025), incl. doxxingProducts are confidential and need-to-know
Data minimised and securedPDPA as amended 2024 (DPO and breach notification from 1 Jun 2025)Collect what the question needs; retention rules per case
Analyst stays unseenOperational securityNo direct visits to suspect sites; managed research environments
06

First 90 days

WindowWorkDone when
Days 1 to 30Learn the platforms, client requirements and report formats; shadow triage; build a pivot checklist per alert type.Own a triage queue with logged decisions
Days 31 to 60Run investigations end to end; first periodic summary; propose one coverage gap to close.Reports delivered on time with confidence and gaps stated
Days 61 to 90Monthly trend product; reusable templates and case log; review of misses with the lead.The team uses one improvement I built
07

Method & sources

Outside-in, from public data only (public job posting, 2026). The demo uses crt.sh, urlscan.io search, Cloudflare DNS over HTTPS, RIPEstat, domain and IP RDAP (registries and regional internet registries via the IANA bootstrap files), OpenPhish and Phishing.Database.

Company: forwarddefense.com · partners · careers · company page

Scams: RM5.37bn reply · Jan to May 2026 · channel shift

Deepfakes and data: deepfake warning · 400m records case · PDPA probe

Law: Penal Code 2025 · Online Safety Act

Independent homework by Edward Tay for the Forward Defense analyst application in Kuala Lumpur. Public data only, no confidential Forward Defense information. The demo is my own prototype.