Skip to content
View ryandus's full-sized avatar
  • Greater Orlando / Space Coast, FL • Open to Remote
  • LinkedIn in/ryan-c-hanks

Block or report ryandus

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ryandus/README.md

Hi, I'm Ryan C. Hanks 👋

Digital Forensics Examiner and eDiscovery Professional specializing in complex digital investigations, litigation support, and defensible evidence preservation. I build tools and frameworks that bridge the gap between technical artifact analysis, incident response, and legal workflows (FRE 702/901, ISO/IEC 27037).

Engineering Philosophy: The repositories below are independent proof-of-concepts built to demonstrate a first-principles understanding of digital evidence mechanics. While active litigation strictly requires court-tested enterprise platforms (e.g., Relativity, Magnet, Cellebrite), engineering custom forensic tooling ensures I possess the technical depth to validate raw data, understand artifacts at the hex level, and expertly troubleshoot commercial software deficits.


🛠️ Featured Projects

  • EDRM Litigation Forensics Showcase – Bridge between technical digital forensics, e-discovery, and legal workflows.
  • TriageFlow-DFIR – Enterprise API triage and incident response telemetry for complex environments.
  • TraceFlow – Client-side digital forensics evidence hash manifest generator and ISO/IEC 27037 chain-of-custody ledger.
  • SyncFlow – Forensic DVR clock-drift calibrator and timeline synchronizer engineered for LEVA/SWGDE compliance.
  • DFIR Investigation Framework – Standardized forensic framework aligned with NIST SP 800-61, ISO/IEC 27037/27042, and FRE 702.
  • Police Report Generator – Standardized operational narrative reporting interface.

🔍 Focus Areas & Tooling

  • Domains: Digital Forensics & Incident Response (DFIR) • Multimedia & Video Forensics • Evidence Preservation • API Triage • Litigation Support • Workflow Automation

  • Standards & Compliance: NIST SP 800-61/86 • ISO/IEC 27037 & 27042 • LEVA / SWGDE Protocols • RFC 3227 • FRE 702/901 (Defensible Chain of Custody)

  • Core Tech: Python TypeScript Bash Linux Docker Git

  • Certifications: RelativityOne Cellebrite

📩 Feel free to explore the repos, check out the code, or open an issue.


For inquiries or opportunities, connect with me directly via LinkedIn.

Pinned Loading

  1. edrm-litigation-forensics-showcase edrm-litigation-forensics-showcase Public

    High-Stakes Digital Forensics to E-Discovery & Litigation Support Technical Showcase

    HTML 1

  2. TriageFlow-DFIR TriageFlow-DFIR Public

    Enterprise API Triage & Demarcation Universal Telemetry.

    TypeScript 1

  3. TraceFlow TraceFlow Public

    Client-side digital forensics & incident response (DFIR) evidence hash manifest generator and ISO/IEC 27037 chain-of-custody ledger. Zero server uploads; 100% Web Crypto API.

    TypeScript 1

  4. SyncFlow SyncFlow Public

    A client-side, air-gapped web application for digital forensic examiners to calculate CCTV temporal variance and synchronize video timelines.

    TypeScript 1

  5. DFIR-Investigation-Framework DFIR-Investigation-Framework Public

    Standardized DFIR framework aligned with NIST SP 800-61, ISO/IEC 27037/27042, and FRE 702. Production forensic templates, incident playbooks, and triage guides.

    1

  6. Police-Report-Generator- Police-Report-Generator- Public

    A browser-based, standardized narrative reporting and documentation utility for law enforcement operations.

    HTML 1