Transparency & method

Rigorous investigation, without unrealistic promises

ScamHunter.ch helps scam victims document events, digital identities and financial flows through legal, traceable methods.

Legal OSINT onlyConfidentialityNo guaranteed outcome

Person responsible for ScamHunter.ch

Danilson Ramos

Head of ScamHunter.ch and coordinator of digital-investigation cases.

View professional profile ↗

Depending on the case, technical specialists or legal professionals may act within their own field. Their role, scope and fees are disclosed before any engagement.

ScamHunter.ch at a glance

ScamHunter.ch is an independent Swiss digital-investigation service based in Geneva. It helps online-scam victims preserve evidence, correlate digital identities, analyse public flows — including blockchain data — and prepare a documented case file for their next steps.

Entity
ScamHunter.ch, an independent digital-investigation service.
Location
Rue du Rhône 14, 1204 Geneva, Switzerland.
Responsible person
Danilson Ramos, digital-investigation case coordinator.
Methods
Legal OSINT, infrastructure analysis, evidence preservation and public-transaction analysis.
Deliverable
A sourced report separating facts, hypotheses, limitations and possible next actions.
Limits
No hacking, asset seizure, legal representation or guaranteed outcome.
360° expertise

Cybersecurity, from strategy to operations

An end-to-end view to understand risk, design defences, test resilience, detect threats and lead the response.

14key fields
GovernRisk, strategy, compliance
ProtectArchitecture, data, identities
TestAudit, AppSec, simulation
RespondDetection, DFIR, resilience

Governance, risk & compliance

Turn business issues into measurable, defensible security priorities.

  • GRC
  • ISO 27001/27005
  • NIST CSF
  • CIS Controls
  • EBIOS RM
  • Audit
  • Security policies
  • BCP / DRP
  • Crisis management
  • Third-party risk

Architecture & Zero Trust

Design resilient, segmented and secure-by-default environments.

  • Security by design
  • Zero Trust
  • Threat modeling
  • Microsegmentation
  • Hardening
  • Bastion
  • PAM
  • PKI
  • Secrets management
  • High availability

Networks, systems & endpoints

Protect infrastructure, workstations, servers and communications.

  • TCP/IP
  • DNS
  • VPN
  • Firewall / WAF
  • IDS / IPS
  • NAC
  • EDR / XDR
  • Windows
  • Linux
  • Active Directory
  • Patch management

Cloud, containers & identity

Control access and configuration across hybrid and cloud-native environments.

  • AWS
  • Azure
  • GCP
  • IAM
  • SSO / MFA
  • OAuth 2.0
  • OIDC
  • SAML
  • Kubernetes
  • Docker
  • CSPM
  • IaC

Application security & DevSecOps

Build security into code, APIs and the software delivery chain.

  • OWASP Top 10
  • API Security
  • Secure coding
  • SAST / DAST / IAST
  • SCA
  • SBOM
  • CI/CD
  • Supply chain
  • Code review
  • SSDLC

Authorised offensive security

Assess attack surfaces within a contractual, controlled and repeatable framework.

  • Attack surface
  • Vulnerability assessment
  • Web / API pentest
  • Network audit
  • Cloud audit
  • Wireless
  • Red team
  • Controlled social engineering
  • Remediation testing

SOC, detection & threat hunting

Build visibility, qualify alerts and detect adversarial behaviour.

  • SIEM
  • SOAR
  • MITRE ATT&CK
  • Detection engineering
  • Sigma
  • YARA
  • EDR telemetry
  • Threat hunting
  • UEBA
  • SOC metrics

Incident response & forensics

Contain incidents, preserve evidence and rebuild defensible timelines.

  • DFIR
  • Triage
  • Containment
  • Disk forensics
  • Memory forensics
  • Network forensics
  • Logs
  • Timeline
  • Chain of custody
  • Ransomware

Threat intelligence, OSINT & fraud

Connect digital identities, infrastructure, campaigns and financial flows.

  • CTI
  • OSINT
  • IOC / TTP
  • Cautious attribution
  • Dark web monitoring
  • Domain intelligence
  • Phishing
  • Brand protection
  • Link analysis

Cryptography, data & privacy

Protect information throughout its lifecycle without mistaking encryption for complete security.

  • Encryption
  • Hashing
  • TLS
  • Key management
  • HSM
  • DLP
  • Data classification
  • Backup
  • Privacy by design
  • FADP / GDPR

Malware, mobile, IoT & OT

Analyse threats and constraints specific to malicious software and specialist systems.

  • Malware triage
  • Reverse engineering
  • Sandboxing
  • Android / iOS
  • Firmware
  • IoT
  • ICS / SCADA
  • Industrial protocols
  • Embedded security

Blockchain, crypto-assets & Web3

Understand protocols, trace assets and assess risks in decentralised ecosystems.

  • Bitcoin
  • Ethereum
  • Wallets
  • Smart contracts
  • On-chain analysis
  • Bridges
  • DeFi
  • NFT
  • AML / KYT
  • Tracing
  • Custody

Human factors, email & physical security

Reduce human risk, secure communications and address insider or physical threats.

  • Awareness
  • Phishing simulation
  • BEC
  • SPF / DKIM / DMARC
  • Email security
  • Insider risk
  • Background checks
  • Physical security
  • Access control
  • Security culture

AI & emerging technologies

Anticipate new attack vectors and secure the adoption of rapidly evolving technologies.

  • AI security
  • LLM security
  • Prompt injection
  • Model supply chain
  • Data poisoning
  • Shadow AI
  • Post-quantum
  • Deception
  • Honeypots
  • Attack simulation
Engagement frameworkOffensive assessments are conducted only with written authorisation and a defined scope. Skills are applied according to the case's actual needs, with a transparent distinction between analysis, execution and any specialist partner's involvement.

How this expertise is documented

Technical terms are not decorative labels: they are tied to recognised frameworks and applied only when they address the case's actual needs.

Who

Content and case files are prepared under Danilson Ramos's responsibility. A specialist partner may contribute when the scope requires it.

How

Findings are cross-checked against open sources, technical data and primary frameworks. Every report separates fact, hypothesis and limitation.

Why

The aim is to make a situation usable by the victim, their bank, lawyer or public authorities — without creating false hope.

Public frameworks used to structure these fields:

Last editorial review: . Practical guides prioritise applicable official Swiss sources.

Our four-step method

Feasibility review

We assess the timeline, amounts, payment channels, available evidence and initial leads before proposing an investigation.

Collection and preservation

Relevant material is organised: conversations, domains, profiles, transactions, technical identifiers and open sources.

Legal cross-checking

We correlate public data, digital infrastructure and traceable flows without unauthorised access to any account or device.

Report and next actions

The client receives documented findings, limitations and leads that may be shared with a bank, lawyer or public authority.

What we do not promise

  • We never guarantee that a person will be identified or that funds will be recovered.
  • We do not hack accounts, phones, wallets or systems.
  • We do not replace the police, banks or judicial authorities.
  • We never need your password, one-time code or crypto recovery phrase.
Important — Legal support on this site means preparing and organising a case file. Reserved legal advice or representation is provided by a qualified professional under a separate mandate.

Our commitments

Proportionality

We do not open an investigation when the evidence or prospects do not justify the resources required.

Traceability

Material findings are tied to sources, clearly separating fact, hypothesis and limitation.

Confidentiality

Information is used to assess or process the case under our privacy policy.

Honesty

A private investigation cannot force a freeze, seizure or refund, and we say so plainly.

Would you like a feasibility review?

Describe the situation without sharing a password, seed phrase, bank code or identity document in your first message.

Assess my case