Tracepoint

$ echo "Welcome"

Tracepoint is my space for DFIR and Detection Engineering notes, investigations, and tools. Expect concise case studies, reproducible steps, and artifacts you can reuse.

$ whoami

Itamar Hällström — MDR Analyst @ Unit 42

$ ls -la /interests/

DFIR Memory Forensics Detection Engineering Malware Analysis Threat Hunting Windows Internals

$

_

Quick Stats

0
Case Studies
0
Open Source Tools
0
Years Experience

Latest Posts

Dissecting Process Hollowing - Rogue LSASS with Injected Shellcode
DFIR · Memory Forensics · Aug 2025
EDR-Freeze – Forensic Analysis of an EDR Coma Attack
DFIR · Memory Forensics · Sep 2025