Skip to content
View FelipeYorrisoon's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report FelipeYorrisoon

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
FelipeYorrisoon/README.md
banner

Felipe Yorrison

Malware Analysis Β· Reverse Engineering Β· Digital Forensics

Binary analysis, digital forensics, and threat research. I focus on understanding the behavior and intent behind code, reconstructing execution chains, correlating digital evidence, and documenting technical findings with enough precision to support investigations.


πŸ§ͺ Analyses

I document technical analyses of public malware samples, combining static and dynamic analysis with behavioral reconstruction, IOC extraction, MITRE ATT&CK mapping, and YARA development.

πŸ“‚ malware-analysis-writeups β€” technical malware analysis write-ups πŸ“‚ yara-rules β€” detection rules derived from malware research


πŸ”¬ Projects

Behavior Reconstruction Engine

An open-source engine for explainable behavioral reconstruction from heterogeneous security events.

The project explores how fragmented events can be correlated to reconstruct what happened during an execution chain and make the resulting analysis easier to understand.

πŸ“‚ behavior-reconstruction-engine

TraceGap

An open-source framework for identifying, explaining, and prioritizing potential gaps in malware analysis.

The goal is to make analysis more systematic by identifying where evidence is missing or where additional investigation may be necessary.

πŸ“‚ TraceGap


πŸ” What I Work With

My work is centered around malware analysis and reverse engineering, with a growing focus on digital forensics and investigation.

I work with binary behavior, Windows internals, execution chains, process and DLL activity, injection techniques, obfuscation, C2 communication, and the reconstruction of events from technical evidence.

On the forensic side, I am developing experience with Windows artifacts, memory analysis, timeline reconstruction, evidence correlation, and incident investigation.

The common thread between these areas is understanding what happened, how it happened, and what evidence supports that conclusion.


πŸ› οΈ Toolkit

Ghidra Β· x64dbg Β· REMnux Β· FLARE VM Β· Volatility

C/C++ Β· Python Β· Java Β· Assembly (x86/x64)


🧭 Current Direction

My current development path is moving from low-level technical analysis toward broader digital investigation:

Malware Analysis β†’ Reverse Engineering β†’ Digital Forensics β†’ DFIR β†’ Cybercrime Investigation

I am building projects that allow me to practice this progression through real technical problems rather than only theoretical study.


πŸ“ Investigation Case Studies

I am also developing fictional investigation scenarios to practice the process of turning technical evidence into professional investigative reports.

These cases will combine malware analysis, digital forensics, network evidence, threat intelligence, and evidence correlation where appropriate.

The objective is to develop a consistent workflow from evidence collection to technical findings and final reporting.


🚧 In Development

Some of the projects I am working toward include a Windows forensic timeline, a memory forensics lab, a digital evidence correlation engine, and complete fictional cybercrime investigation case studies.

These projects will be added as they become sufficiently developed to document publicly.


πŸ“Œ Other Repository

terminal-hacker-portfolio β€” interactive terminal-style portfolio built with TypeScript.


🎯 Long-Term Direction

I want to build the technical ability to investigate real-world cyber threats through malware analysis, reverse engineering, digital forensics, and cybercrime investigation.

Long term, I want to apply these capabilities to investigations where technology can help reconstruct events, preserve evidence, identify threats, and contribute to protecting people online.


πŸ“« Contact

Open to conversations with security teams, forensic investigators, researchers, and organizations interested in malware analysis, digital forensics, reverse engineering, and threat research.

LinkedIn Β· X/Twitter Β· Instagram Β· Website

Popular repositories Loading

  1. FelipeYorrisoon FelipeYorrisoon Public

  2. behavior-reconstruction-engine behavior-reconstruction-engine Public

    An open-source engine for explainable behavioral reconstruction from heterogeneous security events.

    C

  3. TraceGap TraceGap Public

    An open-source framework for identifying, explaining, and prioritizing potential gaps in malware analysis.