Areas of professional experience
Forensic work commonly involved in legal and investigative matters
These areas describe the types of records and technical questions I am regularly asked to evaluate.
Mobile devices
Review of phone extractions, messages, application data, media, location related records, notifications, account artifacts, and device activity.
Computers
Review of file activity, user activity, internet history, deleted data questions, external storage records, operating system artifacts, and logs.
Cloud and account evidence
Review of provider exports, cloud storage activity, login events, audit logs, synced data, account records, and activity that may need to be compared with device artifacts.
Email and BEC analysis
Review of mailbox access, message handling, forwarding rules, suspicious sign ins, authentication records, payment diversion timelines, and related account activity.
Business investigations
Review of account access, email activity, file movement, cloud sync, employee device activity, external storage use, and business system records.
Independent forensic review
Evaluation of prior reports, extractions, timelines, methods, assumptions, omitted artifacts, and conclusions when a second forensic opinion is needed.
Report writing
Preparation of reports that identify what was reviewed, how the work was performed, what was found, what remains unknown, and the basis for any opinion.
Consultation and testimony
Support for attorneys through consultation, report review, deposition preparation, testimony support, and explanation of technical findings.