I am a digital forensics professional and malware reverse engineer. I have been in the field since 2011.

This blog is a notebook of lab work and findings from that practice: forensic artifacts, reverse engineering, detection, and the occasional cloud investigation. Tools I build for research and tests live in dfir-tools.

I am also on LinkedIn.

Opinions and views here are my own.