DFIR & threat intel.
Research, tools & practical AI.

I’m a cybersecurity professional focused on DFIR, threat intel and research. This site shares my articles, open-source tools and technical findings.

DIGITAL FORENSICSINCIDENT RESPONSETHREAT INTELAPPLIED AI

FROM THE FIELD

Latest articles

All articles

28 Sep 2026

AI Ate My Velociraptor

Introducing velociraptor-skills, reusable AI skills for case setup, collection, hunting and evidence analysis with Velociraptor.

Published at InfoGuard Labs (opens in a new tab)

1 Dec 2025

CLRaptor: Hunting reflected assemblies with Velociraptor

Hunt reflected .NET assemblies at scale with Velociraptor, detect CLR visibility gaps, and dump suspicious in-memory assemblies for analysis.

Published at InfoGuard Labs (opens in a new tab)

1 Nov 2024

Finding the LNK: Techniques and methodology for advanced analysis

Advanced LNK analysis with Velociraptor, covering shortcut structures, suspicious fields, and useful clustering points for DFIR and CTI workflows.

Published at Rapid7 (opens in a new tab)

16 Jul 2024

Kimsuky's Phishing and Payload Tactics

My 2024 Rapid7 research with Natalie Zargarov and Anna Širokova on Kimsuky’s social engineering, delivery methods and payloads.

Report at Rapid7 (PDF) (opens in a new tab) · Read illustrated overview

Working together

I also take on focused consulting work in DFIR, threat intelligence and practical AI. This can include investigation support, independent technical review or developing tools and workflows for your team.

Get in touch