LFLAW&FORENSICSDIGITAL FORENSIC EXPERT WITNESSESENGAGE AN EXPERT
FILE // LAW-AND-FORENSICSSTATUS: AVAILABLE FOR ENGAGEMENT

Digital Forensic
Expert Witnesses

Law & Forensics is a global legal-engineering firm specializing in cybersecurity, digital forensics, and eDiscovery. Our experts have testified in hundreds of cases and been appointed as forensic neutrals and special masters worldwide — delivering analysis and testimony built to survive Daubert and cross-examination.

DIRECT → info@lawandforensics.com·855-529-2466

EVIDENCE TAGSEALED
EXHIBIT
LF-001
FIRM
Law & Forensics LLC
DISCIPLINE
Digital Forensics
ROLE
Forensic Neutral
METHOD
Validated / Reproducible
INTEGRITY
Hash-verified
SHA-256 // ACQUISITION
a3f9c1d7e2b08456f1ad9c33b7e0d4a2
1c5e8f0b6d9a2741e3c0bb5f8a14d6e9
2008
Firm Founded by Daniel Garrie
100s
Cases Testified & Appointed
Global
Neutral / Special-Master Roles
8
Expert-Witness Panel Members
02DIGITAL-FORENSICS SERVICE LINES

Forensic services scoped for litigation.

S-01

Computer Forensics

Write-blocked, bit-for-bit acquisition and analysis of laptops, desktops, and removable media with documented chain of custody and hash verification — built to withstand challenge.

WRITE-BLOCKSHA-256E01 / DD
S-02

Mobile Device Forensics

Logical and physical extraction across iOS and Android — messages, location, app data, and deleted artifacts — preserving source and timestamp integrity for litigation.

iOS / ANDROIDEXTRACTIONARTIFACTS
S-03

Server Forensics

Forensic examination of physical and virtual servers, databases, and enterprise logs to reconstruct access, lateral movement, and data handling across complex environments.

VM / BARE-METALLOGSDATABASE
S-04

Cloud Computing Forensics

Authenticated collection and analysis across cloud tenants — Microsoft 365, Google Workspace, AWS, and SaaS platforms — with defensible provenance for every record.

M365AWSAPI COLLECTION
S-05

Internet of Things (IoT) Forensics

Acquisition and interpretation of data from connected devices, industrial controls, and embedded systems where conventional evidence sources do not reach.

EMBEDDEDOT / ICSTELEMETRY
S-06

Social Media Forensics

Defensible preservation and authentication of social-media and messaging content — accounts, metadata, and timelines — established for admissibility.

PRESERVATIONMETADATAAUTHORSHIP
S-07

Deepfake Forensics

Detection and analysis of synthetic and manipulated audio, image, and video media to establish authenticity, provenance, and signs of generative alteration.

SYNTHETIC MEDIAPROVENANCEDETECTION
S-08

Forensic Investigations

End-to-end investigations into intrusion, insider misconduct, fraud, and IP theft — root-cause findings stated in terms a trier of fact can follow.

INCIDENTINSIDERROOT-CAUSE
S-09

Expert Witness Testimony

Rule 26-compliant expert reports, rebuttals, declarations, deposition, and trial testimony — framed for Daubert reliability and clarity under cross-examination.

RULE 26DAUBERTTRIAL
03THE EXPERT BENCH

Featured expert witnesses.

EXAMINER PROFILEDG-001
Daniel B. Garrie, Esq.
FOUNDER & MANAGING PARTNER
NEUTRAL
JAMS · since 2016
FACULTY
Adjunct, Harvard University
EDUCATION
B.A./M.A. CS · J.D.
EXPERIENCE
20+ years · 100+ engagements
PATENTS
Co-inventor, cybersecurity
CREDENTIAL
Certified Forensic Engineer

Daniel B. Garriefounded Law & Forensics in 2008 and serves as its Managing Partner. A JAMS neutral since 2016 and Adjunct Professor at Harvard University, he is an attorney with a B.A. and M.A. in Computer Science from Brandeis and a J.D. from Rutgers — pairing rigorous technical method with the ability to explain it clearly to judges and juries.

Over 20+ years he has handled 100+ expert and court-appointed engagements, served as an eDiscovery Special Master in In re: Facebook, Inc. Consumer Privacy User Profile Litigation (N.D. Cal., Judge Chhabria), and worked on matters including United States v. Joseph Sullivan (N.D. Cal.).

He is a co-inventor of cybersecurity patents (U.S. Pat. Nos. 10,546,129; 10,528,738; 9,990,498; 9,990,497), author of 400+ publications, and has been recognized by U.S. Supreme Court Justices.

EXAMINER PROFILEJR-002
J-Michael Roberts
SENIOR DIRECTOR · HEAD OF NEW YORK OFFICE
DISCIPLINE
Forensic Examiner / Expert
CERTS
CCE (ISFCE) · GREM (SANS)
MEMBER
ISFCE · HTCIA · SANS
PRIOR
VP IR, Stroz Friedberg (Aon)
BUILT
VirusShare · Black Harrier Linux
VENUES
U.S. District · State · Intl.

J-Michael Robertsleads Law & Forensics' New York office as Senior Director. A forensic examiner and expert witness, his work spans digital forensics, software-architecture analysis, incident response, and malware reverse engineering. He previously served as VP of Incident Response at Stroz Friedberg (an Aon company) and as Principal Consultant at Corvus Forensics.

He is the creator of the VirusShare malware repository and the Black Harrier Linux distribution, and holds the Certified Computer Examiner (CCE, ISFCE) and GIAC Reverse-Engineering Malware (GREM, SANS Institute) certifications. He has testified in U.S. District Court, State Superior Court, and international arbitrations — including as forensic expert in United States v. Klyushin et al. (D. Mass.) and Criteo S.A. v. SteelHouse, Inc. (C.D. Cal.).

His specialties include trade-secret misappropriation, proprietary software architecture, state-sponsored breaches, digital fraud, insider trading, and OT / industrial & manufacturing systems.

04EXPERT-WITNESS PANEL

An eight-member expert bench.

Beyond our featured experts, Law & Forensics fields a deep panel of subject-matter authorities across cybersecurity, digital forensics, and legal engineering — available for retention as examiners, rebuttal experts, and forensic neutrals.// MATCHED TO MATTER, JURISDICTION & SUBJECT MATTER

  1. 01David Cass
  2. 02Roland Cloutier
  3. 03Gary Corn
  4. 04Jeremy Desor
  5. 05Morgan B. Ward Doran
  6. 06Daniel Garrie
  7. 07George Pierce
  8. 08J-Michael Roberts
05METHODOLOGY / FORENSIC NEUTRAL

Why the analysis is defensible.

Our experts serve as forensic neutrals — unbiased third-party subject-matter experts who protect data integrity and the reliability of findings. Reliability is engineered in from the first byte: a repeatable, documented chain, from preservation to opinion, means findings stand up when opposing counsel pushes back.// EVERY ASSERTION TRACES TO AN ARTIFACT

  1. 01

    Preserve

    Defensible collection first. Forensically sound acquisition with hashing and documented chain of custody before any analysis begins.

  2. 02

    Analyze

    Validated tools and reproducible procedures. Every finding is traceable to an artifact and independently verifiable by an opposing expert.

  3. 03

    Correlate

    Cross-source corroboration — disk, cloud, mobile, and logs reconciled into one coherent, defensible timeline.

  4. 04

    Report

    Conclusions stated plainly, tied to the record, and scoped to survive Daubert scrutiny and cross-examination.

06REPRESENTATIVE ENGAGEMENTS

Matters under seal & sample.

// ANONYMIZED BY SECTOR — NAMED PARTIES OMITTED FOR CONFIDENTIALITY

FORENSIC ANALYSIS
DIGITAL ASSETS / EXCHANGE
Retained Expert

$650M+ cryptocurrency phishing theft

Forensic analysis proving a phishing theft of more than $650M from a custodial wallet; findings led the exchange to fully restore the customer's funds.

INCIDENT RESPONSE
CREDIT-RATING AGENCY
Investigative Team

State-sponsored theft of IP & MNPI

Incident response into the state-sponsored theft of intellectual property and material non-public data at a credit-rating agency.

FORENSIC INVESTIGATION
AUTOMOTIVE-PARTS MANUFACTURER
Retained Expert

Destructive insider cyberattack

Destructive cyberattack on a multinational automotive-parts manufacturer traced to a disgruntled former IT employee via remote-access software.

FORENSIC INVESTIGATION
SMART-APPLIANCE FACILITY
Retained Expert

Production-line malware outbreak

Malware outbreak on the production lines of a smart-appliance manufacturing facility — contained, scoped, and root-caused across OT systems.

FORENSIC INVESTIGATION
HEALTHCARE / MULTI-FACILITY
Retained Expert

PHI data breach

Healthcare data breach from a system misconfiguration exposing protected health information across multiple regional facilities.

COORDINATED RESPONSE
LAW ENFORCEMENT / BOTNET
Forensic Support

Command-and-control takedown

Coordinated forensic collection with law enforcement in a botnet (C&C) takedown.

INITIATE ENGAGEMENT

Engage a forensic expert
before the evidence moves_

Early engagement preserves chain of custody and protects against spoliation. Send the matter, venue, and key dates — a conflicts check and scoping call follow.

DIRECT → info@lawandforensics.com·855-529-2466