Preserve & verify.
Source → verified copy → artifacts
Digital forensics & incident research
Reconstruct the incident.
Understand what happened.
Digital evidence. Device artifacts. Incident timelines.
Research at the intersection of forensics, privacy and defense.
THE LATEST PUBLISHED STORIES
Cloud securityMicrosoft's new Azure investigation highlights compromised service principals, credential exposure and the importance of protecting recovery resources.
READ ARTICLE ↗
RansomwareNew Microsoft research connects recurring behavior across incidents involving different ransomware families.
READ ARTICLE ↗
Malware analysisKaspersky documents a September MacSync infection chain with Objective-C and Swift components, a backdoor module and delivery through disk images.
READ ARTICLE ↗Evidence first.
What happened. When it happened. What the evidence can actually support.
01 / HDD
HDD, SATA SSD, M.2 NVMe and managed flash: different storage architectures, one principle. Preserve the original source.
01 — The signal
Trace relationships between endpoints, network records and infrastructure. Map what is known, record uncertainty, and preserve context before drawing conclusions.
02 — The acquisition
Use documented acquisition, verified hashes and a recorded chain of custody. Keep source media separate from analysis and account for the limits of each method.
03 — The reconstruction
Correlate timestamps, filesystem artifacts and network evidence. Separate observations from interpretation and build a timeline another analyst can examine.
FOLLOW THE INVESTIGATION ↓
LOOK BEYOND THE SURFACE
The device is the beginning. A defensible finding connects the source, its artifacts and the limits of what they can tell us.
Document the source and the collection boundary.
Keep integrity checks and the handling record together.
Correlate artifacts. Test alternative explanations.
Understand the artifact.
Understand the system that produced it.
Acquisition, device artifacts, evidence integrity and incident reconstruction. Trace the facts and document the limits.
DIGITAL FORENSICS ↗Hardened operating systems. Intentional permissions. Better habits for the device that knows you best.
MOBILE SECURITY ↗End-to-end encryption, on-prem infrastructure and the endpoint realities behind secure messaging.
SECURE COMMUNICATIONS ↗THE DEFENSE PLAYBOOK
Prioritise the defenses that fit your reality.
LEARN HOW TO LOOK CLOSER
Six selected videos. Five new field guides. Mobile evidence, computer timelines and a careful first look at suspicious files.
Enter the viewing room ↗ASK BETTER QUESTIONS OF THE EVIDENCE.