DFIR
Evidence-led digital forensics and incident response across complex environments.
forensic_analysis.exeField research portfolio
Ahmed Elessaway / xElessaway
DFIR, OSINT, and threat intelligence research - turning scattered evidence into practical analysis.
Core competencies
Evidence-led digital forensics and incident response across complex environments.
forensic_analysis.exeOpen-source investigation, infrastructure pivots, and identity research.
sources to contextActionable reporting on campaigns, adversary tradecraft, and defensive signals.
research in progressField notes
A practical walkthrough of dPhish Final Phase CTF, tracing a phishing campaign from a compromised internal mailbox through attacker infrastructure, malicious PowerShell attachment analysis, and the final flag.
In-depth forensic review of an exposed threat staging server running AdaptixC2, Cobalt Strike 4.9.1, and weaponized Rogue MySQL arbitrary file read attacks.
Technical teardown of a sophisticated C-based malware development pipeline featuring GitHub Contents API and Google Sheets C2 channels, BYOVD EDR blinding, and process hollowing.
Practice lab
Explore structured OSINT and DFIR practice collections, with repeatable scenarios and clear solving paths.
Open practice lab