Qualifications

Professional Qualifications

I provide independent digital forensic examination, consultation, reporting, and testimony support for matters involving devices, accounts, communications, files, and disputed forensic conclusions.

Professional background

Qualifications relevant to forensic opinion

I am a digital forensic examiner and the founder of Rune Forensics. I provide independent forensic analysis for attorneys, businesses, insurers, agencies, and individuals represented by counsel.

I have performed forensic work in government and private consulting contexts involving law enforcement investigations, digital evidence examinations, forensic report writing, testimony, litigation consultation, and digital forensics instruction.

That experience is relevant because forensic opinions are evaluated through records, methods, documentation, and limits. My work is organized so the evidence reviewed, the process followed, and the basis for any opinion can be understood and challenged.

Independent opinion

The opinion must stay within the evidence

A forensic opinion should be traceable to the records reviewed. I separate observed artifacts, technical interpretation, and opinion so the basis for the conclusion is clear.

When records are incomplete, inconsistent, inaccessible, or insufficient to answer the question, that limitation is part of the analysis. The goal is not to make the evidence stronger than it is. The goal is to report what it supports.

Areas of professional experience

Forensic work commonly involved in legal and investigative matters

These areas describe the types of records and technical questions I am regularly asked to evaluate.

Mobile devices

Review of phone extractions, messages, application data, media, location related records, notifications, account artifacts, and device activity.

Computers

Review of file activity, user activity, internet history, deleted data questions, external storage records, operating system artifacts, and logs.

Cloud and account evidence

Review of provider exports, cloud storage activity, login events, audit logs, synced data, account records, and activity that may need to be compared with device artifacts.

Email and BEC analysis

Review of mailbox access, message handling, forwarding rules, suspicious sign ins, authentication records, payment diversion timelines, and related account activity.

Business investigations

Review of account access, email activity, file movement, cloud sync, employee device activity, external storage use, and business system records.

Independent forensic review

Evaluation of prior reports, extractions, timelines, methods, assumptions, omitted artifacts, and conclusions when a second forensic opinion is needed.

Report writing

Preparation of reports that identify what was reviewed, how the work was performed, what was found, what remains unknown, and the basis for any opinion.

Consultation and testimony

Support for attorneys through consultation, report review, deposition preparation, testimony support, and explanation of technical findings.

Representative matters

Types of matters supported

Client names, outcomes, and confidential facts are not listed. The categories below describe the types of legal and investigative matters where I have reviewed digital evidence.

Criminal defense review

Review of device, account, communication, location, and forensic report evidence for defense teams evaluating digital conclusions.

Civil litigation

Analysis of messages, files, account records, metadata, document activity, device activity, and timelines relevant to claims or defenses.

Business and employment disputes

Review of file access, cloud sync, external storage activity, email records, business systems, account use, and device activity.

Internal investigations

Support for counsel, businesses, insurers, and investigators reviewing account compromise, data access, user activity, communications, or suspected misuse of systems.

Family law and individual matters

Review of phones, computers, messages, photos, cloud accounts, location related records, and disputed digital materials.

Government investigations

Forensic work in government and law enforcement settings where evidence handling, documentation, reporting, and testimony considerations are central.

Teaching and testimony

Explaining technical findings clearly

Digital forensic work often has to be explained to people who did not perform the examination. I have experience communicating technical findings through reports, consultation, testimony, and instruction.

That communication requires more than simplifying terminology. The source of the artifact, the reliability of the record, the limits of the data, and the basis for the opinion all have to remain clear.

Certifications

Forensic credentials and continuing education

Certifications reflect training, testing, and continuing education. They support competence, but the opinion still has to be based on the evidence reviewed.

ISC2 CISSP certification logo

CISSP

Certified Information Systems Security Professional

ISC2
IACIS CFCE certification logo

CFCE

Certified Forensic Computer Examiner

IACIS
Cellebrite CCME certification logo

CCME

Cellebrite Certified Mobile Examiner

Cellebrite
Magnet Forensics MCFE certification logo

MCFE

Magnet Certified Forensics Examiner

Magnet Forensics
IACIS CMDE certification logo

CMDE

Certified Mobile Device Examiner

IACIS
IACIS CAWFE certification logo

CAWFE

Certified Advanced Windows Forensic Examiner

IACIS
EC Council CHFI certification logo

CHFI

Computer Hacking Forensic Investigator

EC Council
EC Council CEH certification logo

CEH

Certified Ethical Hacker

EC Council

Professional principles

Standards I apply to forensic review

Evidence before conclusions

The analysis begins with the records, not the allegation. Conclusions are limited to what the available evidence can support.

Independent analysis

The work is not written to satisfy a preferred outcome. Findings may support, weaken, contradict, or fail to answer the question presented.

Source artifact validation

Important findings are checked against source artifacts, databases, metadata, logs, timestamps, account records, or documented exports when those records are available.

Documentation

The work product should identify what was reviewed, what process was followed, what was found, and what remains unknown.

Reproducibility

A reviewer should be able to understand how a finding was reached through records, artifact paths, exports, logs, screenshots, or documented methods.

Clearly stated limitations

Missing data, tool limits, incomplete records, attribution limits, and alternate explanations are identified when they affect the strength of an opinion.

Independent review

Need an independent forensic examiner?

If a matter involves devices, account records, reports, extractions, timelines, metadata, deleted data questions, or disputed digital evidence, Rune Forensics can review the record and explain what the evidence supports.

Request consultation