Skip to content
View DFIRDominican's full-sized avatar
๐Ÿ 
Working from home
๐Ÿ 
Working from home

Block or report DFIRDominican

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
DFIRDominican/README.md

Fabian Mendoza

Senior Incident Response Analyst at Elastic
DFIR ยท Threat Hunting ยท Threat Intelligence ยท Detection Engineering

7+ years across digital forensics and incident response (DFIR) from delivering breach investigations at Kroll, CrowdStrike, KPMG, and Unit 42 to serving as incident commander at Elastic. I've responded to 200+ enterprise-scale engagements involving ransomware, nation-state APT activity, and zero-day attacks for Fortune 500 organizations, and I build community resources to help other practitioners sharpen their craft.

๐Ÿ› ๏ธ Core Toolbox


  • Forensic Platforms: Cellebrite, Magnet AXIOM, X-Ways Forensics, KAPE, EZ Tools, Velociraptor, Binalyze AIR, MemProcFS, Volatility, SIFT Workstation
  • Detection & Telemetry: CrowdStrike Falcon, Microsoft Defender XDR, Cortex XDR/XSIAM, SentinelOne, Elastic, Splunk, Microsoft Sentinel, Google SecOps
  • Detection Engineering: KQL, Sigma, YARA
  • AI & DFIR: MCP (Model Context Protocol)

๐Ÿ›ก๏ธ What I Work On


  • Incident Response: Leading complex, multi-host investigations across Windows, Linux, macOS, cloud (AWS, Azure, GCP), SaaS, and CI/CD environments from initial triage through containment and remediation.
  • Forensic Analysis: Deep artifact work across various Windows, Linux, and macOS artifacts to reconstruct attacker timelines with precision.
  • Threat Hunting: Developing IOC extraction workflows and hunting techniques across large EDR datasets to surface ransomware operators, C2 frameworks, and credential theft activity.
  • Applied AI for DFIR: Leveraging local and cloud LLMs to accelerate investigation workflows, automate artifact parsing, and reduce time-to-finding on complex engagements.

๐Ÿš€ Community Contributions


  • ๐ŸŒ Personal Blog: DFIRDominican.com - A DFIR technical blog, resource hub, and global jobs board built to give back to the practitioner community.
  • ๐Ÿ“ Independent Research: How to Break Into DFIR (5-part series), Anti-Forensics: Timestomping (5-part series), GX-FE & GX-FA Exam Guides, PsExec key identification, and more.
  • ๐ŸŽ™๏ธ Guest Speaker: University of Arkansas at Little Rock - A Day In The Life: Incident Response (Apr 2025)
  • ๐Ÿ‘จโ€๐Ÿซ SANS Institute Virtual Teaching Assistant: FOR500: Windows Forensic Analysis & FOR608: Enterprise-Class Incident Response & Threat Hunting (Nov 2024 - Feb 2026)
  • ๐Ÿ›๏ธ GIAC Advisory Board Member: Subject-matter expertise on exam content, curriculum development, and certification standards (Jan 2021 - Present)

๐Ÿ… Certifications


  • GIAC: GSP, GX-FE, GX-FA, GEIR, GCFR, GCFA, GCIH, GCFE, FOR563: Applied AI for DFIR
  • 13Cubed: Gold 3x (Linux, Windows Endpoints, Windows Memory)
  • AZ-900
  • SentinelOne SIREN
  • KAPE Proficiency
  • CCNA Routing and Switching

๐Ÿ”— Connect With Me


  • LinkedIn - DM me to talk on all things DFIR.

Popular repositories Loading

  1. sof-elk sof-elk Public

    Forked from philhagen/sof-elk

    Configuration files for the SOF-ELK VM, used in SANS FOR572

    Shell

  2. PWF PWF Public

    Forked from bluecapesecurity/PWF

    Practical Windows Forensics Training

    PowerShell

  3. irflow-timeline irflow-timeline Public

    Forked from r3nzsec/irflow-timeline

    DFIR Timeline Analysis for macOS โ€” SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt, process inspection, lateral movement tracking, persistโ€ฆ

    JavaScript

  4. DFIRDominican DFIRDominican Public

    GitHub Profile README