Reverse Engineering, Malware & Digital Forensics

I have substantial experience with reverse engineering, malware analysis, and digital forensics across desktop and laptop computers, mobile phones, and embedded devices. My work has involved examining compiled software, firmware, and digital artifacts to reconstruct system behavior, development history, and technical provenance. I have conducted these investigations in research, commercial consulting, and litigation, including circumstances where source code was incomplete, lost, or unavailable.

My malware-related development work began early in my career. In 2007, I developed a Linux distribution and associated LiveCD build system intended to support identification and removal of malware from Windows computers. At Independent Security Evaluators, I subsequently designed and built an automated system capable of testing antivirus products against thousands of malware samples for Consumer Reports’ annual antivirus analysis. The system operated on a VMware ESXi server that I managed and automated the creation and restoration of Windows virtual-machine snapshots and the testing of antivirus software against actual malware samples, enabling large-scale, repeatable evaluation of antivirus products.

During my research at Johns Hopkins University, I developed an emulator for analyzing malware code segments as part of a project with the National Security Agency. The emulator was integrated into an IDA Pro plugin and allowed observation of how binary instruction sequences taken from malware samples modified their computing environment. I also worked on generating virtualized computer networks for malware-education environments. These projects involved developing tools and controlled environments for investigating executable behavior at the instruction and system levels.

My commercial reverse-engineering experience includes examining digital-rights-management implementations in iOS and Android applications at the request of the application developer and identifying multiple independent methods of circumventing those protections. I have also reverse engineered binary file formats in connection with fuzz testing. In litigation, my work has included binary analysis of software runtime environments, libraries, and compilers, as well as reverse engineering and product testing involving computer anti-theft technology.

I served as the technical and development lead for Firmware IQ, a commercial platform for automated security analysis of firmware images. The platform unpacked images into their constituent components and performed more than one hundred automated checks for vulnerabilities, security weaknesses, and indicators of compromise. It supported two distinct types of investigation: examining firmware updates for security issues before deployment, and examining firmware extracted from devices for evidence that they had been compromised. As part of Firmware IQ, I developed a patented technique for identifying software components and their versions from binaries and cross-referencing that information with a vulnerability database. I wrote the patent specification and am the named inventor on the resulting patent.

My expert-witness work has included malware analysis, reverse engineering, cyber-attribution, and computer forensics in an engagement involving nation-state threat actors and alleged trade-secret misappropriation. That work also included evaluating the reasonableness of security measures, and I testified at deposition and trial. Other engagements have involved forensic examination of computer systems, mobile-device behavior, software-update processes, device performance, and service outages.

I have extensive hands-on experience examining desktop and laptop computers and mobile phones for forensic investigations and reverse-engineering projects. This includes analyzing numerous phones belonging to class representatives in litigation, as well as examining computers and phones for other purposes. These investigations have involved studying software implementations, system behavior, and the digital artifacts available to explain how a device operated.

I have also evaluated the reliability of software used to produce forensic evidence. In criminal proceedings involving computerized DNA analysis, I reviewed source code, prepared expert reports, and testified at evidentiary hearings concerning the software. More generally, I design and conduct experiments to evaluate technical assertions and determine how software actually behaves. I serve as Secretary of the IEEE 7024 Working Group, which is developing the Standard for the Procurement, Verification and Validation, and Life Cycle Management of Forensic Technologies.

I have extracted and reverse engineered firmware from dozens of devices as part of my commercial firmware-security work, including the development of Firmware IQ. I maintain a hardware-analysis laboratory equipped with oscilloscopes, logic analyzers, microscopes, soldering and rework stations, and diagnostic equipment supporting firmware extraction, signal capture, protocol decoding, and component-level investigation. My experience spans a wide range of CPU architectures, from small microcontrollers to server-class processors. I also developed and launched Technicomp Benchtop Linux, a Linux distribution designed to support forensic-analysis workflows among its technical applications.

I have taught binary analysis and modification, device-firmware modification, network-traffic analysis, and vulnerability assessment at Johns Hopkins University. My teaching uses emulation and virtualization to support hands-on investigation of software and hardware behavior. I have also peer reviewed research concerning memory forensics and hardware security as a member of the program committee for the IEEE Symposium on Security and Privacy.


← Expert witness experience · Testimony record · Download CV (PDF)