top of page

Grow Your Vision

Welcome visitors to your site with a short, engaging introduction. 

Double click to edit and add your own text.

IMG_20200103_132638_2_edited.jpg

Nathan Collier

Malware Analyst

A Bit About Me

Everybody has a story, and your visitors would love to hear yours. This space is a great opportunity to give a full background on who you are and what you have to offer at your next job. Double click on the text box to start editing your content and make sure to add all the relevant details you want site visitors to know.

Use this space to talk about how you started and share your professional journey. Explain your core values, your commitment to the workplace, and how you stand out from the crowd. Add a photo, gallery, or video for even more engagement.

  • White LinkedIn Icon

Hello! I'm Nathan

As a malware researcher with fifteen years of experience, I am a leading expert in assessing cyber threats, identifying vulnerabilities and implementing incident response procedures.  I am highly self-motivated, taking initiative to identify the work that needs to be done and executing.  My natural curiosity and undeniable ambition to continue to improve drives me to learn advanced technical skills rapidly.  I pride myself on producing quality work at a high efficiency level.  I thrive in a fast-paced, dynamic environment.  I am a team player, motivating others to work at their top level; mentoring and training the best malware researchers in industry.  I am both professional and enjoyable to work alongside.  Upon request, I can provide a list of numerous referrals to attest.

EXPERIENCE

EXPERIENCE

Malwarebytes

Senior Malware Intelligence Analyst

June 2014 - February 2024

​

 

Webroot

Senior Threat Research Analyst

October 2009 - June 2014

​

  • Conducting research to discover spyware/malware on PC and Android devices

  • Classifying PC and Android spyware/malware based on unique behavior

  • Creating signatures in order to detect and remove spyware/malware from infected PC and Android devices

  • Identifying new distribution methods and techniques for removal

  • Analyzing information and developing methods of detection and removal of spyware/malware

  • Reverse engineering spyware/malware in order to create signatures off of unique sections of malicious code

  • Writing security blog posts on the company website, Webroot Threat Blog

  • Administrator for the Threat Research domain

  • Extensive testing of new security software

  • Querying SQL database to data mine for Android threats

  • Automating various tasks using scripting

  • Ensuring any issues our customers may have are resolved in a timely manner

  • Managing multiple projects simultaneously while quickly gaining knowledge regarding new concepts and technologies

 

Modern Woodmen of America

Network Analyst

October 2006 - October 2009

​

  • Deploying, configuring, managing, maintaining, and troubleshooting a network with over fifty servers (application, domain controllers, file, mail, web, etc), two sites, and a replicated SAN system

  • Administrating a domain of over five hundred users which includes creating/removing users and groups, assigning permissions, assigning disk quota limits, etc

  • Using scripting to automate various tasks such as file transfers, generating reports, administrative tasks, etc

  • Maintaining the integrity of the company’s email/web system through administration of email/web filters

  • Maintaining the integrity of company’s data through administration of disk and tape based backups/restores

  • Upgrading workstations/servers operating systems, software, etc

  • Administration of the company’s firewall and access control list

  • Research and Implementation of fixes for security vulnerabilities

  • Deploying, managing, and troubleshooting company’s file transfers

  • Creating websites for intranet users to view microfiche images

  • Research, development, and purchasing of required software and hardware

  • Proficiently troubleshooting anything IT related

  • Leading expert in classification of Android malware using complex, high quality signatures to classify large samplesets

    • Creating the highest detections per signature seen on Android customers devices

  • Working diligently with customers to resolve tough issues

    • Beyond being main contact for forum support for all things Android, I also assist with arduous cases submitted via our support staff

  • Creator and maintainer of the Mobile Malware Intel System

    • The Mobile Malware Intel System is the genius behind our high efficiency of classifying malware with a limited number of staff members

      • This system contains millions of Android malware samples

    • An Android malware classification system made by a researcher, for researchers

      • Over half million signatures created in the system to combat Android malware

    • It is a complex system involving Amazon EC2 running Ubuntu server, Amazon RDS running MySQL, and python scripts

    • Being the single contact of the development on the Mobile Malware Intel System creates a space of high agility among the Android protection team

    • Key components

      • Multi-threaded APK Processors

        • Processes thousands of incoming APKs per day

        • Uses androguard and many other tools to analyze Android malware

        • Android malware samples are broken down into data points and sent to Mobile Malware Intel database

      • APK Classifiers

        • Classifies malware in our Mobile Malware Intel database to sort what needs to be worked on or not

      • Insert Signatures

        • Inserts signatures into our Mobile Malware Intel database to classify malware

      • Update Signatures

        • Updates signatures when modifications is required

      • Create Sig File

        • Creates signature files to be download on customer devices

        • Performs FP check before creation of signature files

        • Signature files are packaged and turned into Malware Database to be released onto Malwarebytes for Android clients

      • Auto Detector

        • Automatically creates signatures to classify malware, leaving only the toughest malware samples to us experts

      • Various other scripts to do a multitude of things, and always scripting to be on the leading edge

  • Contributor to Malwarebytes Labs generating some of the highest viewed blogs on the site

    • In addition, working with PR on requests from leading news outlets

    • Contributor to yearly State of Malware report

  • Going beyond core responsibilities

    • Performing QA work to resolve client issues

      • Detailed steps to reproduce issues

    • Scripting using Windows Batch and WinSCP to assist automation of Malware Database releases onto Malwarebytes for Android clients

      • Use of Jenkins to automate the process

    • Training and mentoring the best Android malware researchers in the industry

      • Creating easy to understand training documentation including efficient workflow chart

    • Documenting incident response procedures such as a simplified method for anyone to follow on how to resolve a Android False Positive (FP)

  • Forefront on the battle against pre-installed malware

  • Founding member of the Coalition Against Stalkerware

    • Fiercely fighting against stalkerware on Android devices

    • Adding over hundred detections created that no other vendors detected

EDUCATION

EDUCATION

2006

Bachelor of Science in Computer Science

University of Illinois at Springfield

  • Overall GPA: 3.85/4.0

  • Graduated with Cum Laude honors

TECHNICAL SKILLS

SKILLS

Programming & Scripting Languages

  • Proficient in python

  • Experienced with C++, HTML, Java, VBScript, PowerShell, Windows Batch, and Linux Shell

  • Familiar with C, CSS, Perl, XML, JScript, JavaScript, etc

Databases

  • Proficient in MySQL Workbench

  • Proficient in MySQL database design

  • Expert in MySQL queries

Cloud/Virtual technologies

  • Proficient in creation/administration of Amazon Web Services (AWS) including EC2, RDS, and S3

  • Proficient in virtual environments including VMWARE, VirtualBox, and GenyMotion Android Emulators

    • Working knowledge of distributions FlareVM and REMnux

Operating Systems

  • Deep knowledge of Windows

    • Registry files, configuration files, file system, etc

  • Deep knowledge of Linux

    • Linux/Unix file system, sudo/root level administration, server maintenance, etc

  •  Deep knowledge of Android

    • Analyzing Manifest files to find relevant information such as receivers, services, and activities

    • Deep analytical understanding of APKs

Networking/Protocols

  • Strong understanding and advanced troubleshooting skills in TCP/IP, DNS, DHCP, FTP, HTTP, SMTP, DFS, FRS, Firewalls, and VPN

Encryption

  • Strong knowledge of PGP

  • Strong knowledge of creation and implementing keypairs

SSH/Proxy/Tunneling

  • Strong knowledge of setting up PuTTY connections

  • Strong knowledge of SSH command line

  • Strong knowledge of implementing Bastion servers to tunnel connections

  • Strong knowledge of FTP servers WinSCP, Filezilla, and more

Regular Expressions

  • High level understanding of Regex

Text Editors

  • High level expertise using Notepad++ to create an efficient workflow

Cybersecurity/Monitoring/Analyzing Tools

  • Virtual Environments

    • Windows with FlareVM installed

    • Linux with REMux

  • Windows malware analysis

    • In depth knowledge of dynamic analysis tools Process Explorer (ProcExp), Process Monitor (Procmon), and others used to monitor the behavior of spyware/malware

    • Working knowledge of static analysis tools IDA Pro, Ghidra, Olly Debug, x64dbg, FLOSS, HxD, CFF Explorer, PEiD, PETools, PEview, and others used to analyze PE files for the creation of signatures to detect spyware/malware

    • Working knowledge of the use of Rootkit Revealer, Gmer, and Rootkit Unhooker used to unhook rootkits

  • Android malware analysis

    • Expertise with analysis tools Apktool, dex2jar, JD-GUI, androguard, Android Device Monitor, Logcat, and many more

  • Network analysis

    • Expertise with analysis tools Fiddler, Wireshark, Network Miner, tcpdump, FakeNet, iNetSim, and many more

    • ​Working knowledge of Intrusion Detection Systems (IDS) and sniffers such as Snort

  • ​Threat Hunting

    • Expertise threat hunting malware on VirusTotal, MalwareBazaar, Hybrid Analysis, and other  repositories

RECOMMODATIONS

bottom of page