06 / EXPERIENCE 2026 · Desktop + Web / Evidence Analysis

Windows Inspection & Evidence Analysis Platform

Connected Windows desktop + web analysis product

Product Definition / Detection Workflow Design / AI-Native Delivery / QA & Release Validation

REQ BUILD QA REL 06
17 COLLECTOR DEFINITIONS
282 INDICATOR RULES
7 EVIDENCE RULE TYPES

A connected Windows desktop and web platform for collecting system activity artifacts, correlating evidence, calculating risk and centrally reviewing completed inspections.

64-bit WPF/.NET client with separated collection, parsing, detection, reporting, licensing, integrity and UI responsibilities, connected to a web control plane.

The product needed repeatable evidence collection, scoring, correlations, licensing controls and reliable transmission of completed inspection results to a central panel.

Product definition, detection workflow, collector/rule model, licensing behavior, QA scenarios, cross-device validation and release acceptance.

Programming implementation is AI-assisted. Product requirements, functional scope, UX decisions, acceptance criteria, manual testing, regression control, deployment and final release validation remain under direct personal ownership.

Configured indicators, severity/confidence, scored evidence and cross-source correlations; parallel scan roots; compressed reporting; central case management, history, notifications, audit logging, roles and permissions; license-gated startup and signed release controls.

Tested by multiple users on different Windows computers; configured triggers were detected and completed results were transmitted to the external panel.

A working connected desktop-to-web inspection flow with licensing, evidence correlation and centralized review.

Cross-device test evidence; desktop → web upload demo; trigger detection demonstration; license gate demonstration; signed/release artifacts where safe to show.

C# .NET WPF PHP MySQL REST APIs HMAC RSA Authenticode

Technologies are listed as part of the delivered system and are not used as a personal developer title.

PRODUCT / VALIDATION OUTCOME

Connected desktop-to-web workflow.

  • Designed as one connected product: Windows endpoint collection, evidence scoring, secure upload, web review and follow-up workflows.
  • Configured triggers were successfully detected and completed inspection data was transmitted from multiple Windows computers to the external panel.
  • License-gated startup prevents the main application shell from running without valid authorization, integrity checks and server-side binding validation.
  • Central review exposes verdict, risk, trust factor, confidence-ranked findings, machine metadata and uploaded reports.

DETECTION / SECURITY DEPTH

Evidence with controlled release.

  • Scope: 17 collectors, 282 indicator rules, 7 evidence rule types and 4 correlation chains.
  • 64-bit WPF/.NET 8 client separates collection, parsing, detection, reporting, licensing, integrity checks and UI services.
  • Correlations include execution → deletion, archive extraction → execution, download → execution and USB activity near executable launch.
  • HMAC-SHA256 request authentication, RSA/SHA-256 response signatures, SHA-256 report verification, compressed reports and route-specific rate limits protect the data flow.
  • Release controls include signed manifests, Authenticode, runtime integrity checks, license heartbeats and .NET Reactor control-flow obfuscation/string encryption where configured.