Independent security research

Investigate.
Reconstruct.
Reveal.

Timestomp documents how adversaries abuse operating systems, how investigators reconstruct their activity, and how defenders turn that evidence into detections.

01
OBSERVEBehavior
EVENT
02
RECONSTRUCTEvidence
ARTIFACT
03
OPERATIONALIZEDefense
DETECTION

Every investigation begins with a question and ends with something a defender can use. The work moves from mechanism, to evidence, to action.

Research in progress

Deep technical work, built in public from reproducible labs, investigative notes, and defender-focused analysis.

01

IN DEVELOPMENT

Windows Persistence: Mechanism to Evidence

Studying persistence as an operating-system behavior, then translating its artifacts into practical triage and detection logic.

DFIRINTERNALSTRADECRAFT

Where the work lives

01

Windows Security

Internals, execution, persistence, and the evidence Windows leaves behind.

02

Digital Forensics

Artifact-first investigation built around timelines, provenance, and reconstruction.

03

Detection Engineering

Turning technical behavior into durable hypotheses, telemetry, and detections.

04

Adversary Tradecraft

Reproducing techniques to understand the boundary between action and evidence.

Evidence over assumption.

Timestomp is an independent cybersecurity research portfolio built by a SOC analyst pursuing deeper mastery of Windows security, digital forensics, malware behavior, and detection engineering.

Start a conversation