forensicate.net

DFIR notes, research, and tools

UTC

About

Andrew Prince

Hi, I'm Andrew Prince. I work in digital forensics, incident response, and threat hunting. Day to day, I handle IR investigations, SIEM and log analysis, and writing automation to scale detection and response.

Outside of that, I enjoy spending time researching Windows forensic artifacts, malware samples, and defensive tradecraft that holds up against how adversaries actually behave.

My career spans over a decade, starting in software development and moving through systems administration before settling into DFIR. Alongside the practitioner work, I build forensic tools, usually to scratch my own investigation itches. Some of it ends up on this site.

I also build cyber ranges and teach. Over the years I've trained thousands of analysts worldwide and supported major MDR teams preparing their responders for real adversary operations.

I stood up this blog to share research, investigation notes, lessons learned, and the occasional half-baked idea with the community.

Teaching schedule

Course author and instructor at TCM Security:

One of the best hands-on courses I have seen. It is now the standard for me to recommend to anyone looking to break into T1/T2. I've even put in a training request for some of my employees.

Manager, Cybersecurity Operations, Arctic Wolf

It's not often that a course leaves me this impressed. Security Operations (SOC) 101 by Andrew Prince is one of the most comprehensive courses I've taken in a long time, and that's saying a lot. It's hard to put into words just how complete this course is.

Roger Bergling, INVID Gruppen

Credentials

Education

Certifications

Affiliations

Connect with me

Find me at any of these links, or drop a line by email.