Senior Consultant
Current•Worked with companies across the US and Latin America on forensic and incident response engagements.•Obtained the SIREN certification from SentinelOne, demonstrating expertise in endpoint detection and response.•Handled cases involving malware, ransomware, network intrusion, internal threats, and email analysis.•Conducted host-based forensic artifact analysis on Windows, Linux, and macOS systems and servers with potential indicators of compromise.•Performed forensic triage to assess incident scope, urgency, and impact.•Analyzed firewall, network, web, database, SIEM, and login logs to identify malicious activity.•Correlated forensic findings with network events to develop detailed intrusion narratives.•Independently conducted Business Email Compromise (BEC) analysis, including email log interpretation and compromise detection.•Conducted deep-dive forensic image analysis to support investigations.•Led client and counsel update calls, guiding stakeholders through investigations, incident containment, and remediation planning.•Independently monitored the dark web for client-specific threats and downloaded leaked files from threat actor sites.•Collected and analyzed Microsoft Exchange on-premises IIS logs to assess email compromises.•Analyzed phishing email headers and embedded links to trace origins.•Reviewed digital evidence, including Windows event and registry logs, to detect unauthorized access or data exfiltration.•Used various forensic tools to analyze Windows and macOS systems.•Maintained daily communication with clients to gather evidence, provide updates, and manage projects from start to finish.•Authored forensic reports summarizing findings and providing actionable recommendations.