focus area
Digital Forensics & Incident Response
A real incident is decided in the first hours. That is when a cool head, a clear plan and the ability to read the right story from a few traces make the difference. I combine deep technical forensics with the experience of leading an incident as its incident manager.
What this covers
- Incident response: ransomware, BEC, insider threats
- Windows host & memory forensics, malware reversing
- Threat hunting & honeypot/alerting systems (incl. APT)
- Incident management & leading the crisis
- Court-ready evidence handling & documentation
- Proven under time pressure (CTF, NetWars)
My DFIR experience comes from real engagements, from ransomware and business email compromise to insider threats. For a long time I was the main person responsible for extensive honeypot and alerting systems that also surfaced APT activity.
Some incidents begin unexpectedly. More than once, during a red team engagement, I realized we were not alone in the network but running alongside a genuine second party. The assessment turned into an incident response operation in real time.
Technically my focus is Windows host and memory forensics and the reverse engineering of malware, complemented by log and network analysis, and backed by the GIAC certifications GCFA, GCFE and GREM. That it holds up under serious time pressure is something I have shown across many Capture the Flag events and NetWars competitions.
Because I know how attackers think and operate, I find artifacts that are easy to miss in the rush of an incident. The difference comes exactly from that intersection of offensive experience and forensic diligence.
Beyond the technical side I bring incident management, the ability to lead a crisis. That composure comes from my years as an officer in the German military, where decisions had to be made under pressure and with real responsibility.
An engagement follows a clear order: contain the incident, durably remove the attacker and restore operations safely, without destroying evidence and without panic. Where it matters, I secure traces to a forensic standard, so the analysis also holds up in court.
Selected engagements
A red team turns into incident response, defense company
During a red team engagement it became clear that we were not the only active party in the network. Rather than acting immediately, we observed the real attacker’s activity, built a picture of the situation, and then durably removed them from the network in one targeted move.
An insider threat caught through a honeypot
A honeypot reported an interaction that should not have happened. The analysis led to an insider threat: further logs tied the activity to one person beyond doubt, that individual was confronted in a targeted way, the host system was examined forensically, and every trace was documented to a court-ready standard.
Ransomware with damaged backups
A ransomware incident hit partly destroyed backups. In parallel to negotiating with the attacker group, a partial recovery succeeded from the remaining backups. The result was clear damage limitation, with no ransom paid.