DFIR
Evidence-led digital forensics and incident response across complex environments.
forensic_analysis.exeField research portfolio
Ahmed Elessaway / xElessaway
DFIR, OSINT, and threat intelligence research - turning scattered evidence into practical analysis.
Core competencies
Evidence-led digital forensics and incident response across complex environments.
forensic_analysis.exeOpen-source investigation, infrastructure pivots, and identity research.
sources to contextActionable reporting on campaigns, adversary tradecraft, and defensive signals.
research in progressField notes
Technical teardown of a sophisticated C-based malware development pipeline featuring GitHub Contents API and Google Sheets C2 channels, BYOVD EDR blinding, and process hollowing.
In-depth forensic review of an exposed threat staging server running AdaptixC2, Cobalt Strike 4.9.1, and weaponized Rogue MySQL arbitrary file read attacks.
Passive acquisition review + offline static analysis of an exposed QuickDAV malware repository and Remcos RAT delivery infrastructure.
Practice lab
Explore structured OSINT and DFIR practice collections, with repeatable scenarios and clear solving paths.
Open practice lab