Digital Forensics & Analysis

Memory Analysis & Incident Response

Specialized in digital forensics with practical experience in memory dump analysis, disk imaging, and incident response procedures. Proficient in the complete forensic methodology from preservation to reporting.

Memory Analysis

  • Volatility Framework 2.6 (Linux & Windows)
  • Memory dump creation with winpmem.exe
  • Process analysis and hash extraction
  • Registry analysis and credential recovery
  • Timeline reconstruction

Disk Forensics

  • Disk imaging with dd.exe
  • File carving with PhotoRec
  • Partition recovery with TestDisk
  • MFT analysis and deleted file recovery
  • Hex analysis with HexEdit

Incident Response

  • 13-step ransomware response procedure
  • Evidence preservation and chain of custody
  • Network isolation and containment
  • Hash verification (MD5/SHA256)
  • LSASS memory extraction

Secure Data Destruction

  • Advanced forensic wiping with shred utility
  • Low-level disk sanitization protocols
  • Multi-pass overwriting techniques
  • Hardware disposal security compliance
  • Anti-forensic data recovery prevention

Operating Systems Expertise

Exegol (Advanced Cybersec) Tsurugi OS (Forensics) Kali Linux Parrot OS Windows/AD

Forensic Pricing Knowledge

Understanding of digital forensics market: is très cher ...