Windows internals
Execution, loaders, persistence, kernel boundaries, and security telemetry.
ABOUT THE WORK
WHY TIMESTOMP EXISTS
Timestomp is my public research portfolio—a place to examine how operating systems are abused, reconstruct what happened, and turn those findings into practical defensive knowledge.
THE PERSPECTIVE
The work begins with real investigative pressure: incomplete evidence, noisy telemetry, and decisions that cannot wait for perfect certainty. Timestomp pushes deeper—into internals, malware behavior, and forensic reconstruction—without losing sight of what an analyst can operationalize.
CURRENT FOCUS
Execution, loaders, persistence, kernel boundaries, and security telemetry.
Artifact interpretation, timeline reconstruction, and endpoint triage.
How code interacts with the operating system and evades defensive control.
Behavioral hypotheses, telemetry selection, validation, and tuning.
CONTACT
For research conversations, technical collaboration, or opportunities involving DFIR, detection engineering, and Windows security.
jlewter@timestomp.io