Insider Data Theft DFIR Support

Job ID: 39945026

Budget: $80 – $200 USD

I’m building a full Digital Forensics & Incident Response package that simulates an insider data-theft scenario, and I’d like an experienced DFIR professional to work side-by-side with me from scoping right through to the final briefing materials.

The core of the investigation will revolve around a supplied hard-drive image. FTK will be our primary analysis platform, but if you have a fast workflow that occasionally pulls in Autopsy, Volatility, Wireshark, or MITRE ATT&CK mapping, I’m happy to incorporate it. What matters most is that every artefact is examined methodically, every inference is defensible, and every word is written by a human—absolutely no AI-generated text.

Deliverables
• Investigative report: 15–20 pages, clearly documenting acquisition, examination, timeline of malicious activity, findings mapped to ATT&CK techniques, and actionable recommendations.
• Slide deck: 15–20 slides distilling the investigation for executives, complete with figures, flow-charts, and evidentiary screenshots.

Acceptance Criteria
• All content authored manually, free of plagiarism, with proper citations where required.
• Screenshots and log excerpts traceable back to the provided disk image.
• FTK case file and any supporting scripts or notes included so results can be reproduced.
• Drafts reviewed iteratively with me until we both agree they are presentation-ready.

We have until 15 Nov 2025, so there’s time for thoughtful analysis rather than rush work. If you’ve handled insider-theft or similar DFIR cases before, please point me to a redacted sample or summary so I can gauge your approach. Let’s create a report and presentation that read like a courtroom-ready narrative and look polished enough for an executive board.