Client Engagement · Confidential

Digital Forensics — reconstructing what happened

Pulling evidence out of network captures, file systems, and nested artifacts — the analyst's side of security.

Client: Classified — under NDA
Engagement: Live engagement against a production-grade system (under NDA)
PCAP analysisFile carvingProtocol reconstructionLayered archives

What we did

Reconstructed an live exfiltration by following data across a packet capture, extracting transferred files from the protocol stream, and unwinding nested/encrypted archive layers to recover the payload. The work is methodical: identify the protocol, follow the stream, carve the artifact, repeat through each layer.

Why it matters to a client

When something goes wrong, forensics answers "what did they take and how." The same skills support incident triage, verifying whether an exposure led to data movement, and understanding attacker activity in your logs and captures.

← Back to case studies