IN DEVELOPMENT
Windows Persistence: Mechanism to Evidence
Studying persistence as an operating-system behavior, then translating its artifacts into practical triage and detection logic.
Independent security research
Timestomp documents how adversaries abuse operating systems, how investigators reconstruct their activity, and how defenders turn that evidence into detections.
THE TIMESTOMP METHOD
Every investigation begins with a question and ends with something a defender can use. The work moves from mechanism, to evidence, to action.
SELECTED WORK
Deep technical work, built in public from reproducible labs, investigative notes, and defender-focused analysis.
IN DEVELOPMENT
Studying persistence as an operating-system behavior, then translating its artifacts into practical triage and detection logic.
AREAS OF INQUIRY
Internals, execution, persistence, and the evidence Windows leaves behind.
Artifact-first investigation built around timelines, provenance, and reconstruction.
Turning technical behavior into durable hypotheses, telemetry, and detections.
Reproducing techniques to understand the boundary between action and evidence.
ABOUT TIMESTOMP
Timestomp is an independent cybersecurity research portfolio built by a SOC analyst pursuing deeper mastery of Windows security, digital forensics, malware behavior, and detection engineering.