Malware Analysis Β· Reverse Engineering Β· Digital Forensics
Binary analysis, digital forensics, and threat research. I focus on understanding the behavior and intent behind code, reconstructing execution chains, correlating digital evidence, and documenting technical findings with enough precision to support investigations.
I document technical analyses of public malware samples, combining static and dynamic analysis with behavioral reconstruction, IOC extraction, MITRE ATT&CK mapping, and YARA development.
π malware-analysis-writeups β technical malware analysis write-ups
π yara-rules β detection rules derived from malware research
An open-source engine for explainable behavioral reconstruction from heterogeneous security events.
The project explores how fragmented events can be correlated to reconstruct what happened during an execution chain and make the resulting analysis easier to understand.
π behavior-reconstruction-engine
An open-source framework for identifying, explaining, and prioritizing potential gaps in malware analysis.
The goal is to make analysis more systematic by identifying where evidence is missing or where additional investigation may be necessary.
π TraceGap
My work is centered around malware analysis and reverse engineering, with a growing focus on digital forensics and investigation.
I work with binary behavior, Windows internals, execution chains, process and DLL activity, injection techniques, obfuscation, C2 communication, and the reconstruction of events from technical evidence.
On the forensic side, I am developing experience with Windows artifacts, memory analysis, timeline reconstruction, evidence correlation, and incident investigation.
The common thread between these areas is understanding what happened, how it happened, and what evidence supports that conclusion.
Ghidra Β· x64dbg Β· REMnux Β· FLARE VM Β· Volatility
C/C++ Β· Python Β· Java Β· Assembly (x86/x64)
My current development path is moving from low-level technical analysis toward broader digital investigation:
Malware Analysis β Reverse Engineering β Digital Forensics β DFIR β Cybercrime Investigation
I am building projects that allow me to practice this progression through real technical problems rather than only theoretical study.
I am also developing fictional investigation scenarios to practice the process of turning technical evidence into professional investigative reports.
These cases will combine malware analysis, digital forensics, network evidence, threat intelligence, and evidence correlation where appropriate.
The objective is to develop a consistent workflow from evidence collection to technical findings and final reporting.
Some of the projects I am working toward include a Windows forensic timeline, a memory forensics lab, a digital evidence correlation engine, and complete fictional cybercrime investigation case studies.
These projects will be added as they become sufficiently developed to document publicly.
terminal-hacker-portfolio β interactive terminal-style portfolio built with TypeScript.
I want to build the technical ability to investigate real-world cyber threats through malware analysis, reverse engineering, digital forensics, and cybercrime investigation.
Long term, I want to apply these capabilities to investigations where technology can help reconstruct events, preserve evidence, identify threats, and contribute to protecting people online.
Open to conversations with security teams, forensic investigators, researchers, and organizations interested in malware analysis, digital forensics, reverse engineering, and threat research.