Insights / methods and field notes
Technical guidance that shows its work
Practical notes on evidence, admissibility preparation, cloud preservation, attack paths, New York cyber obligations, and operational technology.
Start with the technical question, then follow the method and cited primary sources.
These articles are written for professionals who need to decide what to preserve, test, change, or ask next. Primary sources are linked where the topic involves rules, guidance, or standards. The material explains technical practice and does not provide legal advice.
Browse technical field notes
Practical guidance on preservation, expert methods, cyber response, security testing, and operational systems.
Frye, Daubert, and the technical record behind the opinion
A technical practitioner's guide to preparing reproducible digital evidence work for New York state and federal court scrutiny.
Read field note02 / eDiscoveryPreserve the collaboration record before ordinary systems change it
A practical technical checklist for preserving Microsoft Teams, Slack, email, cloud files, and identity records under short New York litigation deadlines.
Read field note03 / New York cybersecurityPart 500 evidence: connect the policy to the system
How asset, access, testing, vulnerability, log, incident, and recovery records can support a NYDFS cybersecurity program without replacing legal analysis.
Read field note04 / New York cybersecurityGive counsel facts that can support the notice analysis
A technical response checklist for establishing access, acquisition, affected systems, data types, identities, safeguards, and chronology after a suspected breach.
Read field note05 / OT / ICS / SCADAPassive-first discovery is a coverage discipline
How sensor placement, observation windows, engineering records, owner context, and reconciliation produce a useful OT asset inventory.
Read field note06 / OT / ICS / SCADAThe diagram is intent. Reachability is evidence.
A practical method for testing OT zones, conduits, firewall rules, routes, identity paths, and remote access under operator authority.
Read field note07 / Digital evidenceA location artifact is a measurement with conditions
A technical guide to GPS, Wi-Fi, cell, application, photo, health, vehicle, and account records used in mobile location analysis.
Read field note08 / Incident responseSecure the money path, then reconstruct the mailbox event
A technical first-day plan for business email compromise involving payment fraud, Microsoft 365 or Google Workspace, identity evidence, and mailbox recovery.
Read field note09 / Digital evidencePreservation mistakes that can change the answer
Common evidence-handling errors involving live devices, cloud accounts, screenshots, exports, reimaging, forwarding, and undocumented transfers.
Read field note10 / Digital evidenceQuestions to answer before digital evidence work begins
Plain technical answers about preservation, timing, scope, remote collection, deleted data, mobile devices, reports, expert testimony, and cost drivers.
Read field noteAsk a technical question
Describe the work, the deadline, and the people authorized to act. Do not send evidence through the public form.