Investigations

Investigations Leadership · Financial Crime & Crypto · Digital Forensics

Take information and drive it to a real-world outcome that holds up in court.

For ten years I worked cybercrime and financial crime cases as a detective. Fraud, scams, money laundering, cryptocurrency, cyberstalking and online harassment. I ran them start to finish: tracing crypto on the blockchain, OSINT, financial records, interviews, and digital forensics, then took them through to charges, prosecution, or a referral to federal partners.

I built the department's digital forensics capability from nothing, with no budget, and secured grant access to the crypto-tracing tools to go with it. Then I spent a year running incident response for a global client base, which is the same work with the clock running.

Any one of those cases could end up in a courtroom with me on the stand, testifying to what I did, how I did it, and why the method holds. That changes how you work from the first day of a case. You handle evidence so it survives, you document the method as you go, and you never claim more than you can prove.

Financial Crime, Crypto & Cybercrime

  • Complex financial-crime cases, end to end. Scams, investment fraud, money laundering, and crypto. On-chain tracing, OSINT, financial records, live interviews, and forensics, driven to charges, prosecution, or referral.
  • Million-dollar fraud matters worked using digital forensics, OSINT, and blockchain analysis.
  • Finding people from historical cell site data. FBI-trained in historical cell site analysis: using call detail records and tower data to place a phone geographically after the fact. It found several missing people, including cases where the phone was already powered off and there was no live signal to follow.
  • Cyberstalking and online harassment. Cases where the damage was to a person rather than a balance sheet. Working out who was actually behind an account, tying it to a real identity, and building that into something a prosecutor could charge. Usually against the clock, because account records and platform data do not stay available forever.
  • Cryptocurrency tracing, secured by grant. Identified the capability gap and secured grant access to the tooling, then integrated it into investigative workflows and trained the team. Zero cost to the department.
  • A digital forensics program built from nothing. No prior capability and no budget. Procedures, tooling, and training, so detectives could work digital evidence independently rather than waiting on an outside lab.
  • Fraud prevention for local businesses. Designed and ran an awareness program: assessment, detection tooling, and workshops that reduced fraud exposure across the community.
  • Federal and county referral. Provided case intelligence and referral packages to county and federal partners.
  • A cold case closed after fifty years. A 1970s missing-persons investigation. Kept the family engaged over years and coordinated with NamUs to secure the DNA match.

Legal Process & Expert Testimony

  • Court-qualified expert witness. Completed the Drug Recognition Expert certification school and maintained it through recertification. Qualified by the court as an expert and testified as one. The value carried forward is the credential and the testimony record rather than the subject matter: work that holds up when someone is paid to take it apart.
  • Legal process, start to finish. Applied for subpoenas, authored and executed search warrants, held chain of custody, and testified in court across financial crime, cybercrime, and digital forensics cases.
  • Getting evidence out of platforms, including overseas. In a cybercrime case most of the proof sits with a company rather than the suspect: the account records, the login history, the messages. When that company is in another country a normal search warrant does not reach it, and you go through a Mutual Legal Assistance Treaty request instead, an MLAT, which is the formal channel between two governments for handing over evidence. It is slow and it has to be drafted correctly or it comes back empty. Trained in MLAT process, in provider returns from the major platforms, and in drafting the warrant requests that do not fit a standard template.
  • Evidence discipline on the breach side. On a breach, counsel, the outside forensic firm, and the insurance carrier all need something different out of the same event. Ran the incident so each of them got what they needed and the client stayed protected. That means working out early whether this ends in litigation, with a regulator, or as an insurance claim, and preserving the evidence and chain of custody for that outcome before anyone thinks to ask.

Ransomware: Both Ends of the Same Case

A ransomware attack is two crimes at once. Someone breaks in, and someone gets paid.

I have worked both ends. I directed the response on live ransomware events, and before that I traced cryptocurrency in fraud cases as a detective, using tooling I secured grant access to and taught the team to use.

The payment leaves a permanent record on a public ledger. Most people who handle the incident cannot follow the money, and most people who follow the money have never run the incident.

The same instinct runs through what I publish. State of the Attack is a case file rather than a news post: every piece starts from something we observed directly, and it walks the intrusion from initial access to objective with the actual artifacts. Detection rules and IOCs go out with it, on the site and pushed to third-party registries including URLhaus and the other abuse.ch trackers, AlienVault OTX, and Open Source Malware, so other teams can act on it.

Also publishing State of the Threat for boards, and State of the Defense on why controls fail.

Credentials

Certified Financial Crimes Investigator (CFCI)
IAFCI
Certified Cyber Crimes Investigator (CCCI)
IAFCI
Certified Information Systems Security Professional (CISSP)
ISC2
Court-qualified expert witness
Drug Recognition Expert certification, qualified and testified as an expert

Backed by roughly 60 courses across financial crime, cryptocurrency and on-chain tracing, OSINT and dark web, digital forensics, and legal process. The complete inventory is published at Certifications & Training.