ABOUT THE WORK

Security research for the investigation layer.

Timestomp is my public research portfolio—a place to examine how operating systems are abused, reconstruct what happened, and turn those findings into practical defensive knowledge.

Built from the SOC. Moving closer to the operating system.

The work begins with real investigative pressure: incomplete evidence, noisy telemetry, and decisions that cannot wait for perfect certainty. Timestomp pushes deeper—into internals, malware behavior, and forensic reconstruction—without losing sight of what an analyst can operationalize.

The technical center of gravity

01

Windows internals

Execution, loaders, persistence, kernel boundaries, and security telemetry.

02

Digital forensics

Artifact interpretation, timeline reconstruction, and endpoint triage.

03

Malware behavior

How code interacts with the operating system and evades defensive control.

04

Detection engineering

Behavioral hypotheses, telemetry selection, validation, and tuning.

Let's compare notes.

For research conversations, technical collaboration, or opportunities involving DFIR, detection engineering, and Windows security.

jlewter@timestomp.io