Rectifyq publishes a lot. You don’t need all of it. Find your role below and click your tile to follow that lane.
Which one are you?
🧭 CISO / Security Manager
- Rectifyq Radar — one read a month keeps you current.
- Breach Watch — local ransomware claims and leaks by sector, since 2018. Nothing justifies budget like local numbers. Victims always masked.
- Vulnerability Watch — is Malaysia (and your sector) actually exposed to the CVE in the news?
🏢 Business Owner
- Rectifyq Radar — plain-language monthly summary of what’s hitting Malaysian organizations.
- Tanya Rectifyq — ask anything, anonymously. “Kena ransomware, siapa nak call dulu?” is a perfectly good question.
Reporting an incident?
Rectifyq is a private CTI initiative, not an official channel. For incidents, contact NACSA or MyCERT Cyber999 — and note that NCII entities have mandatory reporting obligations under the Cyber Security Act 2024. Details in Contact.
🔎 CTI Analyst
- Threat Actor Profiles — 47+ groups clustered by suspected origin (heavily China-nexus among APTs), mapped to MITRE ATT&CK and the Diamond Model.
- Intelligence Program — our open PIR/GIR. Map them against your org’s requirements to know which tags to watch.
- Style Guide — relevancy 🔴🟡🟢, severity, category, sub-category, threat actor category, target scope — filter with precision.
- MISP-MY — every entry links to its MISP event for structured pivoting. See Feeds.
On attribution
Actor clustering and naming are interpretations by specific researchers and vendors. For most organizations, generic detection of TTPs offers higher defensive value than definitive attribution — formal attribution is the domain of law enforcement and government.
🖥️ SOC / IR Analyst
- Threat Watch — every entry ships defanged IoCs ready for your SIEM or TIP, linked to its MISP event. Filter 🔴 Highly Relevant first.
- Feeds — pull continuously instead of copy-pasting:
MISP-MY,MISP-ICS-OT, and yearly instances at feeds.rectifyq.com, plus t.me/rectifyq for real-time local IoC alerts. - Vulnerability Watch — CVEs with confirmed Malaysian exposure. Listed here = check your attack surface today.
Integrating with your SIEM/TIP?
Email us at [email protected].
🏭 OT / Plant Engineer
- OT Watch — global scoped OT/ICS threats, flagged where they touch equipment common in Malaysian CNII.
- OT Threat Landscape — Overall Global Scoped ICS/OT Threat Landscape in one page.
- MISP-ICS-OT feed — structured OT indicators:
https://feeds.rectifyq.com/MISP-ICS-OT.
🌱 Student / Newcomer
- Events Calendar — CTFs (Wargames.my, iCTF, and more), meetups, and conferences across Malaysia. Turun padang; most careers here start at a meetup.
- Tanya Rectifyq — no question is too basic.
- Certification Comparison and Subscription Comparison — spend your ringgit wisely.
- PhishHuntMY — hunt a real phishing campaign targeting Malaysians, write it up. Best portfolio piece you can build.
How to read a threat entry
| Tag | Meaning |
|---|---|
| 🔴 Highly Relevant | Direct or confirmed Malaysian targeting/impact — act on it |
| 🟡 Somewhat Relevant | Regional (ASEAN/SEA) relevance or plausible MY exposure |
| 🟢 Informational | Global threat, indirect relevance — awareness only |
targeted / broad-based | Specific MY org/sector vs. global campaign with MY exposure |
| ⚔Threat / 🔰Defense / 📰News | Entry category |
Full reference: Rectifyq’s Style Guide.
Semua orang boleh contribute — see Contribute.