// recent work
// case files · client details redacted
// CASE-DFIR-01● closed · clean
Business email compromise — ruling out the endpoint
A small creative firm reported a suspected breach: an email account had been taking actions no one recognised. We were brought in to answer two questions — what actually happened, and is anything still inside.
// findingThe compromise was cloud-side: a password-spray attack against a mailbox that had no multi-factor authentication. The attacker logged in from overseas IPs and ran mailbox automation from the cloud — never from a company computer. The “scripts” in the alerts were server-side mail commands, not malware on a laptop.
// the curveballThe disk image we were first handed turned out to be an empty rebuild scaffold — no user data at all. We proved it three independent ways rather than trust the label, then located the actual machine and acquired it properly.
// methodThe endpoint was a modern Apple-Silicon Mac that can’t be imaged the usual way. We triaged it live and read-only over an isolated, air-gapped link — collecting persistence, processes, remote-access config and indicators without altering the scene, then removing every artifact afterward.
// resultThe laptop was clean: no malware, no unauthorised remote access, no rogue admin, every startup item a legitimate vendor. We confirmed the breach lived entirely in the cloud account, closed the endpoint question, and handed over a remediation runbook — starting with MFA everywhere.
// CASE-EDU-01● closed · scoped
Canadian university — breach scoping & data-exposure assessment
A post-secondary institution needed to know whether a confirmed intrusion had reached sensitive data, and how far.
// engagementParticipated in investigating a cyber breach to determine whether protected data had been exposed and to bound the affected systems.
// methodLeveraged forensic tools and techniques to establish the breach’s depth and scope across the environment.
// resultDelivered a containment and exposure report that let the institution act on a clear, evidence-backed picture.
// CASE-FIN-01● closed · reported
Bank — departed-employee data exfiltration review
A financial institution needed assurance about whether former employees had taken data on their way out.
// engagementEvaluated possible data exfiltration from former employees for a banking client.
// methodUsed forensic tools to perform an in-depth analysis of access, movement, and handling of sensitive data.
// resultReported findings that ensured the client’s data protection posture and informed next steps.
// CASE-HEALTH-01● closed · investigated
Hospital — exfiltration investigation after a cyber-attack
A healthcare provider needed to understand whether a cyber-attack had moved data out of its systems.
// engagementInvestigated possible data exfiltration arising from a cyber-attack on a healthcare environment.
// methodApplied forensic tools and techniques to trace attacker activity and assess data movement.
// resultProvided the client with a clear read on what the attack did and did not reach.
// CASE-GOV-01● closed · led
Canadian municipality — incident response & breach investigation
A municipal government faced a suspected breach and needed both response and a defensible investigation.
// engagementChampioned a team providing incident response and investigation into a municipality’s suspected breach.
// methodInvestigated the client’s systems to identify potentially exposed data and information.
// resultGave the municipality a coordinated response and a clear account of exposure.
// CASE-OSINT-01● closed · arrest
Online predator investigation — support to law enforcement outcome
A team effort to identify an online offender, where digital investigation supported a real-world outcome.
// engagementContributed to a team investigation pursuing an online offender in a harassment matter.
// methodApplied digital investigation and correlation techniques to surface and confirm identifying signals.
// resultThe work supported an outcome that resulted in an arrest.
// CASE-OSINT-02● closed · arrest
Public figure — coordinated fake-account harassment unmasked
A high-profile individual was being attacked and slandered through a network of fake social-media accounts.
// engagementInvestigated a coordinated harassment and defamation campaign against a public-figure client run through fake accounts.
// methodCorrelated multiple fake social-media accounts to identify the source of the attack.
// resultIdentified those responsible; the engagement resulted in an arrest.
// CASE-IP-01● closed · settled
Corporate espionage — IP theft identified, large settlement
A client's intellectual property was being stolen by intruders, with significant commercial stakes.
// engagementInvestigated significant corporate espionage targeting a client’s intellectual property.
// methodIdentified the actors who gained access to steal the client’s IP and built the supporting picture.
// resultThe work led to a large settlement and destruction of the stolen IP.
// CASE-LEGAL-01● closed · settled
Canadian law firm — data analysis for a class action
A class-action over overcharged interest and fees turned on validating a large, problematic data set from the opposing party.
// engagementAided a class-action lawsuit over alleged overcharging of interest and processing fees.
// methodLed a team performing validation, analysis, and reporting on a problematic data set provided by the opposing party.
// resultSupported the client’s strategy and analysis through the trial and settlement process.
// Identifying details — client, names, hostnames, addresses and
indicators — are withheld. Engagements are described in shape and outcome only.
// credentials
- ✓ Cellebrite Certified Operator (CCO)
- ✓ Cellebrite Certified Physical Analyst (CCPA)
- ✓ Cellebrite certified — mobile & digital forensic extraction and analysis