Investigations
Investigations Leadership · Financial Crime & Crypto · Digital Forensics
Take information and drive it to a real-world outcome that holds up in court.
Ten years as a detective in cybercrime and financial crimes, running complex cases end to end: scams, investment fraud, money laundering, and cryptocurrency. On-chain tracing, OSINT, financial records, live interviews, and digital forensics, driven to charges, prosecution, or referral.
I built the department's digital forensics program with no prior capability and no budget, and secured grant funding for the cryptocurrency-tracing tooling that went with it. Then I spent a year directing incident response at a global scale, which is the same problem from the other side of the timeline.
The through-line is credibility under cross-examination. Evidence handled so it survives, conclusions stated no further than the evidence supports, and a record of saying so under oath.
Financial Crime & Cryptocurrency
- Complex financial-crime cases, end to end. Scams, investment fraud, money laundering, and crypto. On-chain tracing, OSINT, financial records, live interviews, and forensics, driven to charges, prosecution, or referral.
- Million-dollar fraud matters worked using digital forensics, OSINT, and blockchain analysis.
- Grant-funded cryptocurrency tracing. Identified the capability gap, secured the funding, integrated the tooling into investigative workflows, and trained the team. Zero cost to the department.
- A digital forensics program built from nothing. No prior capability and no budget. Procedures, tooling, and training, so detectives could work digital evidence independently rather than waiting on an outside lab.
- Fraud prevention for local businesses. Designed and ran an awareness program: assessment, detection tooling, and workshops that reduced fraud exposure across the community.
- Federal and county referral. Provided case intelligence and referral packages to county and federal partners.
- A cold case closed after fifty years. A 1970s missing-persons investigation. Kept the family engaged over years and coordinated with NamUs to secure the DNA match.
Legal Process & Expert Testimony
- Court-qualified expert witness. Completed the Drug Recognition Expert certification school and maintained it through recertification. Qualified by the court as an expert and testified as one. The value carried forward is the credential and the testimony record rather than the subject matter: work that holds up when someone is paid to take it apart.
- Legal process, start to finish. Applied for subpoenas, authored and executed search warrants, held chain of custody, and testified in court across financial crime, cybercrime, and digital forensics cases.
- Cross-border and platform evidence. Training in obtaining cross-border electronic evidence, provider returns from major platforms, and unconventional search warrant drafting, plus CJIS and Basic Trial Testimony.
- Breach-side evidence discipline. Running the breach-response coalition of counsel, third-party forensic firms, and the cyber insurance carrier means reading where a matter is heading, whether litigation, regulator, or claim, and preserving the evidence, chain of custody, and privilege each party needs before they ask for it.
Where Investigation Meets Attack Analysis
Ransomware is where the two disciplines stop being separate. The intrusion is an attack. The payment is a financial transaction on a public ledger. Directing the response and tracing the proceeds are the same case approached from two ends, and very few people have done both. The financial-crime certifications and the incident command work are not two careers. They are one skill applied to whichever end of the event you are standing at.
State of the Attack is built the way a case file is built: on first-party observation rather than vendor reporting. A honeypot sensor network feeds Wazuh and OpenCTI with automated blocklist propagation, alongside what surfaces in live incidents. Each piece reconstructs one intrusion step by step. The payload dropped, the commands run, the infrastructure built, and the mistakes made. It is published because we watched it happen, which is the same standard as evidence you can put in front of a court.
You follow adversary infrastructure the way you follow money. Collect what you observed directly. Corroborate it. Establish what the evidence supports, and say nothing beyond that. An investigation that overstates its conclusion falls apart under cross-examination, and threat analysis that overstates its conclusion falls apart the first time someone acts on it. The discipline is identical.
Companion publications: State of the Threat for boards, and State of the Defense on why controls fail.
Experience
A decade of financial crime, cybercrime, and digital forensics inside a caseload that ran from graffiti to homicide. Built the forensics capability, secured the crypto-tracing funding, and drove complex matters through to charges, prosecution, or federal referral.
Directed 200+ P1 and P2 incidents from declaration through restoration, coordinating teams of up to 20 across time zones. Ran the breach-response coalition of breach counsel, third-party forensic firms, and the cyber insurance carrier, and coordinated with the FBI, CISA, and the UK NCSC on multi-jurisdictional matters.
Independent security risk assessment practice for New Jersey businesses, at adsrisk.com.
Credentials
Backed by roughly 60 courses across financial crime, cryptocurrency and on-chain tracing, OSINT and dark web, digital forensics, and legal process. The complete inventory is published at Certifications & Training.