Investigative automation
I convert repeatable investigative steps into controlled workflows that collect, normalize, correlate, validate, and report evidence consistently.
Digital Forensics | Automation | Investigative Engineering
I identify inefficient investigative processes, design better methods, and build tools that automate collection, analysis, correlation, geolocation, and reporting.
Supporting Digital Forensics, SOC, CIRT, Enterprise Insider Threat, DLP, Legal, Human Resources, Employee Relations, and enterprise investigative teams.
Professional profile
I specialize in complex digital investigations where evidence is distributed across endpoints, cloud platforms, security telemetry, identity systems, network infrastructure, physical-access systems, and business records.
When existing tools cannot answer the question efficiently, I design a controlled workflow, collect the relevant artifacts, normalize the data, preserve traceability to the source, automate repetitive steps, and produce output that investigators and decision-makers can use.
This portfolio presents selected projects at a public-safe level. Sensitive employer details, operational identifiers, and reproducible instructions for undocumented services have been intentionally omitted.
Automation and AI-assisted development
Many investigative processes are technically possible but operationally inefficient. They require repeated exports, manual normalization, multiple searches, cross-system comparisons, and time-consuming report preparation.
I convert repeatable investigative steps into controlled workflows that collect, normalize, correlate, validate, and report evidence consistently.
I use AI-assisted development to accelerate prototyping, troubleshooting, code review, documentation, and iterative design while retaining control of investigative logic and validation.
The resulting tools reduce repetitive work, improve consistency, preserve traceability, and allow investigators to spend more time evaluating evidence and testing conclusions.
Selected work
Tools and workflows developed to solve recurring investigative and forensic problems, with automation designed into the final operational process.
01 | Enterprise investigation engineering
This is the largest and most extensive investigative engineering effort in my portfolio. It is an evolving collection of methods, reusable queries, scripts, validation procedures, and reporting workflows used to reconstruct activity across enterprise systems that do not share a common event model.
The work correlates endpoint telemetry, authentication, VPN, network, email, cloud, directory, physical-access, and geolocation evidence to explain who acted, from which device, through which infrastructure, from what apparent location, and at what time.
02 | Remote forensic workflow
A connected two-part workflow that remotely acquires artifacts associated with direct user activity and converts the collection into a normalized, confidence-rated timeline.
The collector preserves raw evidence for offline analysis. The parser automates artifact processing, event normalization, confidence classification, visualization, coverage reporting, and investigator-ready output.
03 | Protocol analysis and geolocation
A PyQt desktop application that automates multi-provider wireless geolocation lookup, result comparison, and investigator-ready export.
The project required analysis of undocumented service behavior, binary serialization formats, provider-specific response handling, SSID-aware BSSID normalization, and resilient batch processing.
Endpoint geolocation
Automates remote evidence collection, wireless artifact correlation, directory enrichment, mapping, and HTML reporting for Windows endpoints.
Cellular analysis
Transforms carrier records and cell-site data into structured timelines, location comparisons, investigative maps, and repeatable case output.
Data reconciliation
Automates reconciliation between case-management exports and evidence holdings to identify gaps, duplicates, inconsistencies, and records requiring review.
Investigator automation
A continuing collection of utilities that normalize exports, correlate records, validate evidence, and convert raw technical data into usable reports.
How I work
Define what must be proven, disproven, located, or reconstructed before selecting artifacts or writing code.
Normalized output remains linked to raw evidence so findings can be validated and explained.
Collection, normalization, correlation, and reporting are automated where doing so improves consistency without weakening forensic control.
The same evidence may require a technical appendix, an investigator timeline, and a concise executive summary.
Experience
Enterprise digital forensics
Lead and support complex digital investigations, forensic collections, artifact analysis, cross-platform correlation, reporting, process improvement, and development of new investigative capabilities.
Law enforcement and public service
Approximately two decades of investigative experience, including more than thirteen years applying digital forensics to criminal investigations, search warrants, cellular records, computers, mobile devices, and evidentiary reporting.
Credentials
AccessData Certified Examiner and Magnet Certified Forensics Examiner, supported by extensive practical examination and investigative experience.