DFIR
Evidence-led digital forensics and incident response across complex environments.
forensic_analysis.exeField research portfolio
Ahmed Elessaway / xElessaway
DFIR, OSINT, and threat intelligence research - turning scattered evidence into practical analysis.
Core competencies
Evidence-led digital forensics and incident response across complex environments.
forensic_analysis.exeOpen-source investigation, infrastructure pivots, and identity research.
sources to contextActionable reporting on campaigns, adversary tradecraft, and defensive signals.
research in progressField notes
Passive acquisition review + offline static analysis of an exposed QuickDAV malware repository and Remcos RAT delivery infrastructure.
A real story about mobile forensics, FRP bypass, chipset research, and passive OSINT, all in service of getting a phone back to its owner.
OSINT investigation mapping a fake crypto exchange fraud network from one Facebook lure to DNS, backend, certificate, and WebSocket infrastructure.
Practice lab
Explore structured OSINT and DFIR practice collections, with repeatable scenarios and clear solving paths.
Open practice lab