Technical profile and qualifications

Who is Xabier Durruti

Training and applied knowledge in digital privacy, OSINT, cyberintelligence, computer forensics, forensic analysis, cryptography, networks and information recovery.

OSINTHUMINTCybersecurityComputer forensicsForensic analysisCryptographyNetworksData recovery

Summary

A profile focused on privacy, investigation and technical analysis

My work is based on combining technical knowledge with investigation and documentation skills. These are the areas on which I have built my professional profile.

Main areas of knowledge

I work especially on problems where digital identity, public exposure, account security, technical evidence, metadata, open sources and information protection intersect.

Digital privacy and exposure reduction
OSINT, cyberintelligence and verification
Digital forensic analysis and information recovery
Cryptography, networks and risk management
Information recovery on devices

Specialisation in locating information, protecting data, analysing technical indicators and explaining results clearly.

Investigation: OSINT, cyberintelligence, open sources, verification, context and information traceability.

Security and privacy: account protection, exposure reduction, networks, risk management, encryption and operational good practices.

Technical analysis: computer forensics, digital forensic analysis, metadata, integrity, devices and information recovery.

Qualifications and training

Specialised training

These qualifications are the foundation I apply to digital privacy, OSINT, cyberintelligence, computer forensics, forensic analysis, networks, cryptography and information recovery.

Cyberintelligence specialist technicianOSINTOSINT Open-source intelligence - Hack by Security
Human-source intelligenceHUMINTHUMINT - LISA Institute
Advanced Cybersecurity ProgramSecurityStanford University
CryptographyEncryptionStanford University
University expert in computer forensics and forensic analysisForensicsUNIR University
Play It Safe: Manage Security RisksRiskGoogle
Connect and Protect: Networks and Network SecurityNetworksGoogle
Foundations of CybersecurityBasicsGoogle

Knowledge

What I know and apply

Not every case needs the same thing. These are the skills I usually combine depending on the problem: investigation, protection, technical analysis, documentation and communication.

Digital investigation and OSINT

  • Search and comparison in open sources.
  • Analysis of public exposure, profiles, domains and relationships.
  • Verification of information, context, dates and traceability.
  • Careful reading of indicators without turning hypotheses into facts.

Privacy and security

  • Reduction of personal and professional digital exposure.
  • Protection of accounts, passwords and two-factor authentication.
  • Good practices for browsing, communication and storage.
  • Risk assessment without promising absolute security.

Computer forensics and forensic analysis

  • Technical review of devices, files, traces and metadata.
  • Clear documentation of findings and analysis limits.
  • Careful preservation and explanation of evidence.
  • Reports understandable for non-technical people.

Networks and systems

  • Understanding of browsing, traffic, connections and exposure surface.
  • Review of basic security configurations.
  • Identification of risks in personal and professional environments.
  • Technical reading of anomalous behaviour.

Cryptography and encryption

  • Concepts of encryption, keys, hashes and integrity verification.
  • Prudent use of information-protection tools.
  • Clear explanation of limits, risks and appropriate uses.
  • Development of privacy-oriented tools.

Information recovery

  • Initial assessment of devices and storage media.
  • Information recovery with risk criteria.
  • Prioritisation of data with operational or evidential value.
  • Avoiding actions that could worsen recovery.

How I use that knowledge

Working method

Technique only helps if it leads to better decisions. That is why I separate facts, hypotheses, limits and next steps.

1

Define

Define what needs to be known, what information exists, what risk is present and what must not be touched.

2

Analyse

Review sources, accounts, devices, files or traces with order, dates, context and traceability.

3

Explain

Turn the result into a useful explanation: what is known, what is not known and what should be done next.

Need to review a case discreetly?

Tell me the context, urgency and what you need to protect, verify or recover. We start by organising the situation.