Skip to content

Navigation Menu

Sign in
Sign up
@DFIRDominican
DFIRDominican
Follow
View DFIRDominican's full-sized avatar
🏠
Working from home

Fabian Mendoza DFIRDominican

🏠
Working from home
DFIR @ Elastic, Founder of DFIRDominican.com, Incident Responder, Threat Hunter.

Block or report DFIRDominican

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
DFIRDominican /README.md

Fabian Mendoza

Senior Incident Response Analyst at Elastic
DFIR Β· Threat Hunting Β· Threat Intelligence Β· Detection Engineering

7+ years across digital forensics and incident response (DFIR) from delivering breach investigations at Kroll, CrowdStrike, KPMG, and Unit 42 to serving as incident commander at Elastic. I've responded to 200+ enterprise-scale engagements involving ransomware, nation-state APT activity, and zero-day attacks for Fortune 500 organizations, and I build community resources to help other practitioners sharpen their craft.

πŸ› οΈ Core Toolbox


  • Forensic Platforms: Cellebrite, Magnet AXIOM, X-Ways Forensics, KAPE, EZ Tools, Velociraptor, Binalyze AIR, MemProcFS, Volatility, SIFT Workstation
  • Detection & Telemetry: CrowdStrike Falcon, Microsoft Defender XDR, Cortex XDR/XSIAM, SentinelOne, Elastic, Splunk, Microsoft Sentinel, Google SecOps
  • Detection Engineering: KQL, Sigma, YARA
  • AI & DFIR: MCP (Model Context Protocol)

πŸ›‘οΈ What I Work On


  • Incident Response: Leading complex, multi-host investigations across Windows, Linux, macOS, cloud (AWS, Azure, GCP), SaaS, and CI/CD environments from initial triage through containment and remediation.
  • Forensic Analysis: Deep artifact work across various Windows, Linux, and macOS artifacts to reconstruct attacker timelines with precision.
  • Threat Hunting: Developing IOC extraction workflows and hunting techniques across large EDR datasets to surface ransomware operators, C2 frameworks, and credential theft activity.
  • Applied AI for DFIR: Leveraging local and cloud LLMs to accelerate investigation workflows, automate artifact parsing, and reduce time-to-finding on complex engagements.

πŸš€ Community Contributions


  • 🌐 Personal Blog: DFIRDominican.com - A DFIR technical blog, resource hub, and global jobs board built to give back to the practitioner community.
  • πŸ“ Independent Research: How to Break Into DFIR (5-part series), Anti-Forensics: Timestomping (5-part series), GX-FE & GX-FA Exam Guides, PsExec key identification, and more.
  • πŸŽ™οΈ Guest Speaker: University of Arkansas at Little Rock - A Day In The Life: Incident Response (Apr 2025)
  • πŸ‘¨β€πŸ« SANS Institute Virtual Teaching Assistant: FOR500: Windows Forensic Analysis & FOR608: Enterprise-Class Incident Response & Threat Hunting (Nov 2024 - Feb 2026)
  • πŸ›οΈ GIAC Advisory Board Member: Subject-matter expertise on exam content, curriculum development, and certification standards (Jan 2021 - Present)

πŸ… Certifications


  • GIAC: GSP, GX-FE, GX-FA, GEIR, GCFR, GCFA, GCIH, GCFE, FOR563: Applied AI for DFIR
  • 13Cubed: Gold 3x (Linux, Windows Endpoints, Windows Memory)
  • AZ-900
  • SentinelOne SIREN
  • KAPE Proficiency
  • CCNA Routing and Switching

πŸ”— Connect With Me


  • LinkedIn - DM me to talk on all things DFIR.

Popular repositories Loading

  1. sof-elk sof-elk Public

    Forked from philhagen/sof-elk

    Configuration files for the SOF-ELK VM, used in SANS FOR572

    Shell

  2. PWF PWF Public

    Forked from bluecapesecurity/PWF

    Practical Windows Forensics Training

    PowerShell

  3. irflow-timeline irflow-timeline Public

    Forked from r3nzsec/irflow-timeline

    DFIR Timeline Analysis for macOS β€” SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt, process inspection, lateral movement tracking, persist...

    JavaScript

  4. DFIRDominican DFIRDominican Public

    GitHub Profile README

AltStyle γ«γ‚ˆγ£γ¦ε€‰ζ›γ•γ‚ŒγŸγƒšγƒΌγ‚Έ (->γ‚ͺγƒͺγ‚ΈγƒŠγƒ«) /