Back to Developers
Zohaib Arfi

Zohaib Arfi

Cybersecurity professional

New Delhi 2+ yrs exp 84 · Excellent

About

Cybersecurity professional with hands-on experience in malware analysis, reverse engineering, network threat detection, and mobile security. Skilled in static and dynamic analysis of Windows, macOS, Android, and iOS malware, including PE and Mach-O binary analysis, behavioral analysis, sandboxing, and runtime instrumentation. Experienced in IOC extraction, MITRE ATT&CK mapping, network traffic analysis, and Python-based security automation, with expertise in tools including IDA Pro, x64dbg, Ghidra, radare2, Frida, JADX, APKTool, Wireshark, Zeek, Suricata, and Tshark. Proficient in developing scalable malware-analysis workflows using Python, Celery, and RabbitMQ to improve threat detection, malware triage, and incident-response capabilities.

Skills & Expertise (45)

YARA Intermediate
7.5/10
1
Years Exp
Python Intermediate
7.4/10
1
Years Exp
Suricata Intermediate
7.0/10
1
Years Exp
Snort Intermediate
7.0/10
1
Years Exp
WIRESHARK Intermediate
7.0/10
1
Years Exp
Docker Intermediate
6.5/10
1
Years Exp
Kubernetes Intermediate
6.0/10
1
Years Exp
Git Intermediate
6.0/10
1
Years Exp
JavaScript Intermediate
5.5/10
1
Years Exp
Postgresql Intermediate
5.5/10
1
Years Exp
Flask Intermediate
5.0/10
1
Years Exp
C/C++ Intermediate
5.0/10
1
Years Exp
Bash Intermediate
5.0/10
1
Years Exp
CSS ExifTool Visual Studio Code RabbitMQ Ansible JSON HTML Data Structures & Algorithms Windows macOS IOS LINUX GitHub Object-Oriented Programming Frida Celery Zeek Tcpdump IDA Pro x64dbg PEStudio HXD Radare2 Android Debug Bridge Objection JADX Ghidra apktool AndroGuard Process Monitor Android Studio XCODE

Work Experience

Malware Analyst

Ally Wired Soft Solutions Pvt. Ltd.

Mar 2025 - Present

Performed static and dynamic malware analysis across Windows and macOS environments to identify malicious behavior, persistence mechanisms, execution techniques, system modifications, and command-and-control (C2) activity. Conducted static analysis of Windows PE and macOS Mach-O binaries using IDA Pro, x64dbg, x32dbg, Ghidra, macholibre, PEiD, PEStudio, PEview, CFF Explorer, and YARA, analyzing binary structure, metadata, symbols, imports/exports, API usage, certificates, function relationships, call graphs, and suspicious artifacts. Performed dynamic behavioral analysis of Windows and macOS malware in sandboxed environments by monitoring process execution, file-system activity, network communications, dropped/modified files, registry/system modifications, and persistence mechanisms, and correlated observed behaviors with MITRE ATT&CK techniques to identify malicious activity and extract actionable IOCs. Performed static and dynamic analysis of URLs and PCAPs from Windows, macOS, iOS, Linux and Android environments to detect malicious activity, network anomalies, and command-and-control communications (C2). Extracted, correlated, and enriched network Indicators of Compromise (IOCs) including domains, IPs, TLS fingerprints, user-agents, and payloads using Tshark, Suricata, Zeek, and Wireshark. Developed Python-based automation for URL analysis, IOC extraction, malware triage, and detection-rule generation using YARA and Snort, improving malware-analysis and network-threat-detection workflows.

Mobile OS Expert

Aspirify Enterprises Private Limited

Sep 2024 - Mar 2025

Performed static and dynamic security analysis of Android and iOS applications using Frida, Objection, JADX, APKTool, and Android Studio to identify malicious behaviors and security weaknesses. Performed reverse engineering and runtime instrumentation using Frida and Ghidra to analyze application behavior and security mechanisms. Configured Android emulators, AVDs, and sandbox environments for malware execution, network interception, and dynamic behavioral analysis. Developed asynchronous malware analysis and threat processing workflows using Celery and RabbitMQ, improving scalability and reducing analysis latency for automated security tasks. Documented findings using the MITRE ATT&CK framework, enriching threat intelligence repositories and improving incident response capabilities. Designed and implemented an automated malware analysis framework for Android and iOS (X86 and ARM architecture), boosting process efficiency by 40%. Established and managed a comprehensive malware repository of over 20 Million samples, enhancing research capabilities and contributing to global threat intelligence. Conducted in-depth analysis of Android-based malware to extract Indicators of Compromise (IOCs) and analyze malicious behaviors.

Cybersecurity Intern

Defence Research & Development Laboratory (DRDO)

Jan 2024 - Mar 2024

Skillfully managed emulator devices with Android Studio configured for macOS, ensuring seamless mobile app testing and debugging. Set up emulator kernel settings, including the Goldfish kernel, to enhance compatibility and performance. Developed Python automation scripts for Android emulator management, application deployment, permission handling, SMS/call simulation, and accessibility testing. Captured, intercepted, and analyzed Android application network traffic using Mitmproxy to support mobile security testing and runtime analysis. Utilized Docker containers for smoother project scalability and efficiency on macOS.

Education

Bachelor of Technology in Computer Science Engineering - Maulana Azad College Of Engineering and Technology

2020 - 2024 · Afghanistan

Intermediate - Patna Muslim High School +2

2016 - 2018 · Afghanistan

Matriculation - ST. Mary’s School Patna

2015 - 2016 · Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

📷 Photo 10/10
📄 Resume 10/10
💼 Job Title 10/10
✍️ Bio 10/10
🛠️ Skills 20/20
🎓 Education 10/10
⏱️ Experience 9/15
💰 Rate 0/5
🏆 Certs 0/5
Verified 5/5
Total Score 84/100

Profile Overview

Member sinceAug 2026

Skills (45)

Click a skill to find developers with the same skill