Information security · IT expert witness
Gabriel Pamies
An expert specialised in information security, an entrepreneur and passionate about cybersecurity. He runs 0Invader Cybersecurity and its digital forensics laboratory in Elche, where the digital evidence he later defends in court as court expert no. 02714 (ASPEJURE) is acquired, analysed and certified.
Digital evidence is not worth the screenshot, but the method used to obtain it, preserve it and explain it to a court.
Credentials
What backs every report he signs
Registered court expert in digital forensics: his reports are filed in proceedings and he confirms them in court.
Official Cellebrite certification in physical extraction and analysis of mobile devices. Code AAS-0235884, valid until 03/12/2027.
University training specific to the acquisition, analysis and presentation of digital evidence.
LPI senior-level certification in Linux systems security: encryption, access control, hardening and network security.
The laboratory he runs works with procedures certified by Applus+ for acquiring, preserving and keeping evidence.
Spain’s National Security Framework at its most demanding level, to work with public bodies and courts.
Education and career
From information security to the courtroom
-
Entrepreneur · Director of 0Invader Cybersecurity
Digital forensics and cybersecurity laboratory in Elche: evidence certification, expert reports, incident response, offensive security and compliance.
-
Court expert in digital forensics · no. 02714
Registered with ASPEJURE: he signs the laboratory’s expert reports and confirms them in court.
-
2025
Cellebrite Certified Physical Analyst (CCPA)
Cellebrite certification in physical extraction from mobile devices (Inseyets), code AAS-0235884.
-
University expert in digital forensics
University specialisation degree in digital forensics and digital evidence.
-
LPIC-3 Security
Linux Professional Institute certification in systems security.
Specialities
Where he steps in
Security management, systems hardening and compliance (ISO/IEC 27001, ENS, NIS2) at the head of the 0Invader team.
Acquisition and analysis of phones, computers, emails and accounts, with an ISO/IEC 27037 chain of custody.
Party reports, counter-reports and testimony in court, in person or by videoconference.
Containing an intrusion or ransomware without destroying the evidence needed later.
Method
How a report is built
- Evidence is acquired with a signed record and a SHA-256 hash, in your presence whenever possible.
- Every conclusion links to a piece of evidence, every piece of evidence to a hash and a record.
- The report is written with cross-examination in mind: no adjectives, no guesswork.
- Whoever analyses is whoever signs and testifies: the evidence never changes hands.