I will perform digital forensic investigation and malware analysis on windows and linux
Cyber Security And Development
About this Gig
I provide professional digital forensic investigation and malware analysis services for Windows and Linux systems. I analyze disk images, memory dumps, and system logs to reconstruct timelines, recover deleted evidence, and identify malicious activity. Using industry-standard tools like Autopsy, Volatility, and YARA, I deliver clear, well-documented findings with actionable recommendations not just raw data.
Whether you're investigating a suspected breach, need artifacts examined from a compromised system, or want malware behavior analyzed safely, I bring a structured, security-first approach to every case.
Note: I work with provided disk images, logs, or memory dumps please ensure you have legal authorization for any data submitted.
FAQ
What do you need from me to start the investigation?
A disk image, memory dump, log files, or the suspicious file/binary — depending on what you need analyzed. I'll confirm the exact format and any collection steps before you send anything.
Do you need access to my live/production system?
No. I work only with provided images, exports, or files — I don't remotely access live systems. This keeps the process safe and avoids disrupting your environment.
Can you confirm whether a file is malware?
Yes — I perform static and behavioral analysis to determine if a file is malicious, what it does, and how it behaves, without executing it in a way that risks your systems.
Is this admissible in court?
My reports document findings clearly but are not a substitute for formal legal chain-of-custody procedures unless explicitly scoped in advance. Message me if you need that level of documentation.
How do you handle sensitive/confidential data?
All submitted data is handled confidentially and used only for the scope of the engagement. I don't retain data beyond what's needed to complete and review the delivery.
What's included in revisions?
Revisions cover clarifying or reformatting the existing report. Analyzing additional artifacts or expanding scope beyond the original request will be quoted separately.
