At Deloitte Italy’s Cyber Intelligence Center, I led technical analysis and recovery efforts during a ransomware incident. I reverse-engineered the encryption workflow, identified a CryptoAPI weakness that enabled reliable file recovery, and developed a standalone recovery utility.
I reconstruct multi-stage malware chains, recovering payloads, configurations, C2 infrastructure, and execution logic. I turn those findings into IOCs, ATT&CK mappings, and threat-hunting logic for operational defense.
My research includes reverse-engineering ransomware and RATs, and documenting previously unreported malware families and campaigns. My findings have been referenced by CERT-AgID and security vendors, and I’ve delivered technical talks at Politecnico di Milano.

