I will do digital forensics, incident response and cyber crime investigation
About this Gig
I provide professional digital forensics and incident response services, covering disk forensics, memory forensics, and cyber crime investigation. I use FTK Imager, EnCase, Autopsy and Volatility to examine evidence, reconstruct the timeline, and deliver a defensible DFIR report you can act on.
What I do
- Disk & file system forensics deleted file recovery, registry, browser, email and user artifacts
- Memory forensics Volatility RAM analysis, process and injection detection
- Incident response triage, scoping, containment, root cause and IOC analysis
- Network & log forensics Wireshark, PCAP and log correlation
- Malware triage and intrusion analysis
- CTF and forensics challenge walkthroughs
- Full forensic reports with methodology, findings and evidence exhibits
Tools: FTK Imager, EnCase, Autopsy, Volatility, Wireshark, Sleuth Kit, KAPE, Kali Linux
You get documented methodology, hash verification, screenshots and a written report not raw tool output.
Device:
Desktop
•
Laptop
•
Server
•
Mobile
•
Tablet
Operating system:
Windows
•
Linux
•
IOS
•
Android
•
Ubuntu
FAQ
Can you recover deleted files?
Often yes, depending on the file system and whether the data has been overwritten. Send me details and I'll tell you honestly what's recoverable before you order.
Do I need to send you my actual device?
No. I work from forensic images (E01, DD, AFF), memory dumps, PCAPs, or logs. I can walk you through capturing an image with FTK Imager if you don't have one.
Will the report hold up legally?
I document methodology, hashes and chain of custody so findings are defensible. Whether it's admissible depends on your jurisdiction and how the evidence was originally collected — discuss with your attorney.
Is this confidential?
Yes. Everything you send stays private and I delete case data after delivery on request.
Do you work with students?
Yes — coursework, lab reports, CTF challenges and dissertation projects.
