Digital Forensics | Automation | Investigative Engineering

Turning difficult investigative work into repeatable, defensible workflows.

I identify inefficient investigative processes, design better methods, and build tools that automate collection, analysis, correlation, geolocation, and reporting.

Supporting Digital Forensics, SOC, CIRT, Enterprise Insider Threat, DLP, Legal, Human Resources, Employee Relations, and enterprise investigative teams.

20+Years in investigations
13+Years in digital forensics
End to endCollection through reporting

Professional profile

Investigator first. Engineer when the investigation requires it.

I specialize in complex digital investigations where evidence is distributed across endpoints, cloud platforms, security telemetry, identity systems, network infrastructure, physical-access systems, and business records.

When existing tools cannot answer the question efficiently, I design a controlled workflow, collect the relevant artifacts, normalize the data, preserve traceability to the source, automate repetitive steps, and produce output that investigators and decision-makers can use.

This portfolio presents selected projects at a public-safe level. Sensitive employer details, operational identifiers, and reproducible instructions for undocumented services have been intentionally omitted.

Automation and AI-assisted development

The point is not merely to build a tool. It is to remove unnecessary work.

Many investigative processes are technically possible but operationally inefficient. They require repeated exports, manual normalization, multiple searches, cross-system comparisons, and time-consuming report preparation.

01

Investigative automation

I convert repeatable investigative steps into controlled workflows that collect, normalize, correlate, validate, and report evidence consistently.

02

AI-assisted engineering

I use AI-assisted development to accelerate prototyping, troubleshooting, code review, documentation, and iterative design while retaining control of investigative logic and validation.

03

Operational outcomes

The resulting tools reduce repetitive work, improve consistency, preserve traceability, and allow investigators to spend more time evaluating evidence and testing conclusions.

Investigative AutomationAI-Assisted DevelopmentWorkflow EngineeringDigital ForensicsData CorrelationRemote Evidence CollectionForensic Tool DevelopmentTechnical Reporting

Selected work

Major projects

Tools and workflows developed to solve recurring investigative and forensic problems, with automation designed into the final operational process.

04

Endpoint geolocation

Remote Endpoint Geolocation Toolkit

Automates remote evidence collection, wireless artifact correlation, directory enrichment, mapping, and HTML reporting for Windows endpoints.

  • Remote evidence collection
  • WLAN history and event correlation
  • Directory and account enrichment
  • Map and timeline reporting
05

Cellular analysis

Cell Tower and Search-Warrant Analysis

Transforms carrier records and cell-site data into structured timelines, location comparisons, investigative maps, and repeatable case output.

  • Carrier-record normalization
  • Temporal and geographic correlation
  • Investigative mapping
  • Repeatable reporting workflow
06

Data reconciliation

Case and Evidence Inventory Program

Automates reconciliation between case-management exports and evidence holdings to identify gaps, duplicates, inconsistencies, and records requiring review.

  • Large CSV reconciliation
  • Exception identification
  • Repeatable review logic
  • Management-ready output
07

Investigator automation

Specialized Scripts and Reporting Tools

A continuing collection of utilities that normalize exports, correlate records, validate evidence, and convert raw technical data into usable reports.

  • CSV and log normalization
  • Automated validation
  • HTML report generation
  • Reusable investigative workflows

How I work

Evidence-driven engineering

01

Start with the investigative question

Define what must be proven, disproven, located, or reconstructed before selecting artifacts or writing code.

02

Preserve source traceability

Normalized output remains linked to raw evidence so findings can be validated and explained.

03

Automate the repeatable work

Collection, normalization, correlation, and reporting are automated where doing so improves consistency without weakening forensic control.

04

Report for the audience

The same evidence may require a technical appendix, an investigator timeline, and a concise executive summary.

Experience

Investigation, forensics, automation, and technical leadership

Enterprise digital forensics

VP, Principal Digital Forensics Investigator

Lead and support complex digital investigations, forensic collections, artifact analysis, cross-platform correlation, reporting, process improvement, and development of new investigative capabilities.

Law enforcement and public service

Investigator and Digital Forensics Examiner

Approximately two decades of investigative experience, including more than thirteen years applying digital forensics to criminal investigations, search warrants, cellular records, computers, mobile devices, and evidentiary reporting.

Credentials

Forensic certifications

AccessData Certified Examiner and Magnet Certified Forensics Examiner, supported by extensive practical examination and investigative experience.

Contact

Discuss an investigative, forensic, insider-risk, or automation role.

This public portfolio intentionally excludes employer-sensitive details and operational source material. Additional technical depth can be discussed in an appropriate interview setting.

Enterprise investigation engineering

Investigation Data Correlation Workflows

This is the largest and most extensive investigative engineering effort in my portfolio. It is not one application or one query. It is an evolving set of methods, scripts, search strategies, validation procedures, and reporting workflows used to reconstruct activity across a large enterprise environment.

The investigative problem

Enterprise investigations rarely have one authoritative source of evidence. Relevant activity may be distributed across endpoint telemetry, authentication systems, VPN infrastructure, proxies, email platforms, cloud services, directory systems, physical-access controls, and case records. Each system records only part of the event and may use different identities, host formats, IP fields, time zones, session identifiers, retention periods, and event definitions.

Correlation approach

I developed repeatable methods that begin with an investigative question and identify the systems most likely to contain independent, mutually supporting evidence. Records are normalized and connected using usernames, email addresses, employee identifiers, hostnames, endpoint identifiers, sensor identifiers, private and public IP addresses, authentication sessions, message identifiers, physical-access events, locations, and normalized timestamps.

Evidence sources

Automation and workflow engineering

Repeating searches, exports, field conversions, joins, validation, and report preparation manually is slow and introduces inconsistency. I developed reusable queries, scripts, parsers, and reporting processes to automate the repeatable portions of the work. This allows investigators to spend more time evaluating evidence and testing conclusions.

Location and travel analysis

A major component involves determining whether enterprise evidence supports or contradicts a claimed location. This may require correlating endpoint wireless artifacts, VPN records, proxy logs, public IP geolocation, hotspot or mobile-provider activity, Windows location data, and authentication events while accounting for VPN gateways, proxies, mobile hotspots, satellite internet, corporate egress points, and stale wireless-location records.

Email correlation

I developed methods for reconstructing email movement across multiple mail-security and Microsoft platforms by connecting message identifiers, timestamps, senders, recipients, routing hops, and security-processing events.

Validation and reporting

No single telemetry source is automatically treated as authoritative. Findings are tested against independent evidence whenever possible, and conflicting records are preserved and explained. Technical reports retain source fields, timestamps, queries, limitations, and validation details. Executive summaries explain the relevant activity, confidence, and investigative significance without requiring the reader to understand the underlying platforms.

What this project demonstrates

Connected forensic workflow

CrowdStrike RTR User Activity Collector and Forensic Parser

This project addresses a recurring forensic problem: remotely collecting meaningful evidence of direct user activity from Windows endpoints and converting diverse artifacts into a timeline that can be reviewed by investigators and non-technical stakeholders.

Collector

Parser

Operational engineering

The workflow was refined around contained systems, locked files, absent artifacts, RTR script-size limits, endpoint security detections, large event logs, and the need to preserve traceability from normalized findings back to source evidence.

Protocol analysis and geolocation

BSSID Geolocation Lookup Tool

This desktop application resolves wireless access-point identifiers using multiple location-data providers, then presents the results in a common comparison table and interactive map.

Problem

Wireless artifacts often contain a BSSID but no immediately useful geographic information. Provider interfaces and response formats vary, and conventional public APIs do not consistently expose the required data.

Technical contribution

I analyzed undocumented provider behavior, worked with binary serialization formats and partially documented schemas, created provider-specific integration modules, and normalized successful and failed responses into one application workflow. Reproducible service details are intentionally excluded from this public portfolio.

Capabilities

Interactive BSSID geolocation map with provider-specific markers
Interactive mapping output comparing provider results for multiple access points. Demonstration identifiers are unrelated to the author's home or employer.
Expanded project screenshot