Back to selected work

DFIR platform

Forensis

Investigation tooling that brings evidence, triage, and response into one workspace.

Focus
DFIR platform
Updated
May 2026
Stack
Python, Flask, YARA, Sigma, Docker

Overview

Built for operational clarity.

A threat analysis and digital forensics platform covering logs, network evidence, memory triage, playbooks, Sigma correlation, and secured administration.

This project reflects a product-oriented approach to security engineering: start with a recurring operational problem, reduce unnecessary steps, and make the result usable across real environments.

What it delivers

01Log and PCAP analysis
02Memory triage
03Sigma correlation
04MFA administration

Engineering approach

Portable, inspectable, and ready to operate.

The implementation emphasizes explicit workflows, deployable packaging, and technology choices that remain understandable to the teams running them.

PythonFlaskYARASigmaDocker
Continue exploring View all projects