Shenouda // NetDetective
Home
Services+
Process Cases Our Company FAQ Book Consultation

The Internet Detective who finds the unfindable and
recovers what others can't.

Hacked. Stalked. Extorted. When the police can't help and your IT team has run out of options — I take over. Elite Dutch Cyber Threat Intelligence, OSINT & Incident Recovery for individuals, executives and enterprises worldwide.

Report an Incident →
20+
Years in Cyber Defense
500+
Incidents Resolved
24/7
Emergency Response
// what we do

What We Do

Personal Protection

For individuals under threat

From anonymous stalkers to drained crypto wallets, catfish scams to hijacked accounts — I investigate, trace and resolve the digital crises that upend people's lives. Every case is treated with total discretion.

Corporate & Executive Security

For businesses and boardrooms

Corporate espionage, insider threats, brand impersonation and executive digital exposure — I deliver court-ready evidence and strategic risk assessments for companies and the people who run them.

Dark Web & Threat Intelligence

We illuminate the underground

Continuous monitoring of leak markets, underground forums and ransomware chatter — turning the deep and dark web into actionable intelligence before damage is done.

Incident Response & Recovery

When you're already under attack

Ransomware containment, network forensics, decryption sourcing and post-incident hardening. When the fire is already burning, I bring calm, proven, decisive action.

// engagement protocol

How We Work

Every case follows a proven four-phase methodology. Transparent, fast, relentless.

Contact

Reach out via the secure form, encrypted email or phone. I respond within hours — minutes for active emergencies.

~ Minutes to hours

Triage

Free, confidential 30-minute assessment. We map the situation, contain immediate damage and define mission scope.

~ 30 minutes · Free

Operate

OSINT collection, forensic analysis, dark-web hunting, takedown coordination — whatever the case demands.

~ Days to weeks

Resolve

Court-ready evidence, recovered assets, hardened systems and a clear path forward. You get your life back.

~ Full resolution
// whoami

Two Decades in the Field

I'm Joe Shenouda — a Dutch elite Cyber Threat Intelligence specialist, SOC architect and OSINT investigator. For two decades I have hunted threat actors across the surface web, deep web and dark web. I've defended Fortune-500 networks and personally pulled victims out of digital nightmares the police never had the tools to solve. I operate where ordinary investigators stop — and I do it discreetly.

CTI Specialist SOC Architect OSINT Expert Digital Forensics Expert Witness Crypto Tracing
// worldwide operations

Total Discretion, Global Reach

Based in the Netherlands, operating worldwide — for individuals, SMBs, enterprises, law firms and select government clients across Europe, the US, the Middle East and beyond. Every engagement is confidential by default: formal NDAs on request, encrypted case infrastructure, and court-ready evidence when it matters.

Netherlands · Worldwide ops 100% NDA on request 24/7 Emergency Response
// case files · anonymised

Real Operations. Real Outcomes.

A selection of cases — client identities and sensitive details are anonymised. The results are verified.

OPERATION · GHOSTNETRESOLVED

Anonymous Stalker Identified in 11 Days

Eight months of terror. Anonymous threats across multiple platforms targeting a family. Police stood down. OSINT revealed the person lived 200 meters away.

11d
Time to Resolve
14
Aliases Traced
OPERATION · ERP-FIRESTORMRECOVERED

Mid-Market ERP Restored in 4 Days

Ransomware locked the entire ERP stack of an EU manufacturer. Full containment, negotiation to 30% of demand, clean recovery with hardened infrastructure.

-70%
Ransom Reduction
96h
Time to Recovery
OPERATION · COLDCHAINTRACED

€180K Crypto Fraud — Partial Recovery

"Investment opportunity" drained six figures via a fake exchange. Cross-chain tracing through 2 mixers, 3 chains. Forensic report used to recover a substantial portion.

3
Chains Traced
62%
Funds Recovered
// voices of clients

Discretion is Non-Negotiable

Names and details are anonymised. The words are theirs.

★ ★ ★ ★ ★

"For 8 months an anonymous account terrorised my family. The police said there was 'nothing they could do.' Joe identified the person in 11 days. He lives 200 meters from us."

— L.M.Private client · Utrecht
★ ★ ★ ★ ★

"Ransomware locked our entire ERP. Joe coordinated containment, negotiated a 70% reduction, and delivered the keys with a clean recovery plan. We were back online in 4 days."

— CISOMid-market manufacturer · EU
★ ★ ★ ★ ★

"I lost €180K to a 'crypto investment.' Joe traced the funds across 3 chains and 2 mixers, and produced a forensic report my lawyers used to recover a substantial portion."

— R.K.Private investor
24/7 Response NDA Ready Worldwide EU/NL Region 100% Confidential Court-Ready Evidence Expert Witness Dark Web Monitoring 24/7 Response NDA Ready Worldwide EU/NL Region 100% Confidential Court-Ready Evidence Expert Witness Dark Web Monitoring
// secure intake

Contact Us

  • Our typical response time is minutes to a few hours for active emergencies.
  • We treat all provided information as strictly confidential.
  • If you are being actively attacked, extorted, or your business is mid-incident, write "EMERGENCY" in the subject.
  • Website: www.shenouda.nl · Based in the Netherlands · Worldwide operations.
Book Consultation →

Active emergency?

Whether you're a worried parent, a CEO at 3 AM watching your network burn, or a victim no one else has been able to help — you've reached the right person.

Please be aware that active emergencies marked in the form above are prioritised.
// common questions

Frequently Asked Questions

Is everything I tell you really confidential?
Absolutely. Every engagement is treated under strict confidentiality. I sign formal NDAs on request, store case data on encrypted, segregated infrastructure, and never disclose client identities — not even existence of an engagement — without explicit permission.
Do you work with private individuals, or only companies?
Both. Roughly half of my caseload is private people in crisis: parents, victims of stalking, people scammed out of life savings. The other half is corporate incident response and threat intelligence. The same expertise applies.
How fast can you respond to an emergency?
For confirmed active incidents (ransomware, ongoing extortion, live account takeover), I typically engage within minutes to a few hours — even outside business hours. Mark "EMERGENCY" in your subject.
Can you really trace stolen cryptocurrency?
In a large majority of cases, yes — including funds passed through mixers, bridges and exchanges. Speed matters: the sooner you contact me, the higher the recovery odds. I work with law enforcement and exchanges where appropriate.
Do you cooperate with law enforcement?
When it serves my client, yes. I produce court-ready forensic reports, package digital evidence to legal standards, and have provided expert witness testimony. I will never share your data without your authorisation.
What does it cost?
Cases vary widely, from a few hours of investigation to multi-week incident response. The initial 30-minute triage call is free. After that I'll provide a clear, fixed scope and fee before any work begins.
Where are you based and who do you work with?
I am Dutch and based in the Netherlands, but I operate worldwide — for individuals, SMBs, enterprises, law firms and select government clients across Europe, the US, the Middle East and beyond.