Mari DeGrazia
@maridegrazia.bsky.social
📤 188
📥 29
📝 22
Digital Forensics and Incident Response SANS Instructor CyberSecurity VR E-Sports Maker
Overheard in the grocery store last night: "Why is beefstew not a good password?" Me, in my head: "That's terrible. No random numbers, letters, symbols.. actually random phrases..." Them: "It's not stroganoff"
6 months ago
0
3
0
Check out this cool new open-source Dark Web Monitoring AI Agent platform by AI Anytime - it looks like it will work with a local LLM too. I know what my next weekend project is going to be :)
#AI
#LocalLLMs
#DFIR
www.youtube.com/watch?v=9e24...
loading . . .
AI Agents for Dark Web Monitoring | AI for Security Agencies
YouTube video by AI Anytime
https://www.youtube.com/watch?v=9e24SkBKkeU
6 months ago
0
2
1
I'm a big believer in local LLMs for DFIR—privacy & security matter. In my keynote, "How to DFIR AI-ze Your Workflow," I demo how to use local LLMs with FOSS tools + share common pitfalls. 🎥
youtu.be/eG2wHGIPCaQ?...
#DFIR
#FOSS
@sansinstitute.bsky.social
loading . . .
Keynote | DFIR AI-ze Your Workflow
YouTube video by SANS Digital Forensics and Incident Response
https://youtu.be/eG2wHGIPCaQ?si=yLuiLbqMS662hshN
6 months ago
0
0
1
Check out this excellent blog post by Ryan Chapman from last month's Stay Ahead of Ransomware live stream. I was bummed I missed this one, but Ryan's recap is great.
#DFIR
www.sans.org/blog/shaking...
7 months ago
0
2
1
The SANS
#DFIR
Summit has always been one of my favorite conferences to attend. This year, I'm excited and honored to be giving the keynote! Attend in person or attend online for free!
www.sans.org/cyber-securi...
loading . . .
Digital Forensics & Incident Response Summit & Training 2025 | SANS Institute
Obtain hands-on, practical skills from the world's best instructors by taking a SANS course at DFIR Summit & Training 2025.
https://www.sans.org/cyber-security-training-events/digital-forensics-summit-2025/
7 months ago
0
1
0
The SANS Institute
#DFIR
Summit has always been one of my favorite conferences to attend. This year, I'm excited and honored to be giving the keynote! Attend in person or attend online for free -
www.sans.org/cyber-securi...
loading . . .
Digital Forensics & Incident Response Summit & Training 2025 | SANS Institute
Obtain hands-on, practical skills from the world's best instructors by taking a SANS course at DFIR Summit & Training 2025.
https://www.sans.org/cyber-security-training-events/digital-forensics-summit-2025/
7 months ago
0
1
1
It's almost here!!! Join Ryan Chapman and me at the SANS Ransomware Summit tomorrow. I will also be hosting an AI workshop over lunch. Learn how to install and use a local LLM. Register for the free conference and workshop here:
www.sans.org/cyber-securi...
loading . . .
Ransomware Summit | SANS Institute
SANS Ransomware Summit provides the very best forum for ransomware content and applicable lessons to safeguard ourselves and our organizations from harmful ransomware tactics.
https://www.sans.org/cyber-security-training-events/ransomware-summit-2025/
9 months ago
0
0
0
Thinking about taking the SANS 528 Ransomware course? I love teaching it—not only do we focus on ransomware, but also host-based forensics and analysis at scale. It's great for a wide range of investigations! Use code FOR528-SUMMIT for 30% off
www.sans.org/cyber-securi...
loading . . .
Ransomware Summit | SANS Institute
SANS Ransomware Summit provides the very best forum for ransomware content and applicable lessons to safeguard ourselves and our organizations from harmful ransomware tactics.
https://www.sans.org/cyber-security-training-events/ransomware-summit-2025/
9 months ago
0
0
0
reposted by
Mari DeGrazia
Curtis
10 months ago
🚨 New blog: BlackBasta’s leaks show how ransomware crews still exploit hybrid environments while Scattered Spider leans fully into cloud. Two actors, two strategies. What it means for IR, cloud defense, and ransomware readiness. 👉
invictus-ir.com/news/cloud-h...
#DFIR
#CloudSecurity
#CTI
loading . . .
Cloud Heavy, Hybrid Ready: Lessons from BlackBasta and Scattered Spider
https://invictus-ir.com/news/cloud-heavy-hybrid-ready-lessons-from-blackbasta-and-scattered-spider
0
0
1
Join me, Ryan Chapman and guest
@ransomwaresommelier.com
today at 10AM PT/ 1PM ET as we talk about the state of Ransomware payments.
www.linkedin.com/events/73031...
loading . . .
The State of Ransomware Payments | LinkedIn
Episode One: The State of Ransomware Payments What's going on with ransomware payments? Have they dropped off? Have they gone up? What are we in the global IT community seeing in terms of ransomware ...
https://www.linkedin.com/events/7303110544440389632/
10 months ago
0
1
1
reposted by
Mari DeGrazia
11 months ago
Anthropic explores the advancements and implications of frontier AI.''s dual-use capabilities in cybersecurity and biology. Learn more about their strategies to navigate emerging risks: https://www.anthropic.com/news/strategic-warning-for-ai-risk-progress-and-insights-from-our-frontier-red-team
0
0
1
reposted by
Mari DeGrazia
Dr. Shannon Cofield 🪨🌊
11 months ago
“Your face looks like a museum.” For all my geology + ocean peeps 🧪🪨🌊
add a skeleton here at some point
1
54
10
Like usual, the airport charging station is not working. I found a working plug in a pillar and all these strangers are plugged into my charging hub instead 😂
#JustTravelThings
12 months ago
0
0
0
reposted by
Mari DeGrazia
Women in Security and Privacy (WISP)
about 1 year ago
Should you pursue the leadership track or thrive as an individual contributor in cybersecurity? Join us for a panel discussion on February 13 with top security leaders as they share insights on making this career-defining choice. Register now:
us06web.zoom.us/meeting/regi...
0
1
1
This is really cool and runs 100% locally - a silent speech recognition tool that reads your lips in real time and types whatever you mouth. The power of local LLMs is amazing. Open source too! -
github.com/amanvirparha...
#AI
.
loading . . .
about 1 year ago
0
0
0
I asked Deepseek-r1 14B to tell me a good digital forensics joke. Watching the thought process is so cute and entertaining...
#DFIR
#AI
about 1 year ago
0
1
0
I'm honored to be hosting the SANS Institute Ransomware Summit in May with Ryan Chapman. 5 days left to submit a talk - we want to hear from you!
www.sans.org/mlp/ransomwa...
about 1 year ago
0
1
0
WinSCP and Rclone are used by this TA (and others) to exfiltrate data... check out my presentation on WinSCP artifacts to help locate relevant evidence :
www.youtube.com/watch?v=sCqy...
add a skeleton here at some point
about 1 year ago
0
0
0
This is one of my favorite
#DFIR
#INFOSEC
conferences to attend. They have workshops for kids that I want to attend! Kids and students are free, and just $25 to attend. Well worth the price.
add a skeleton here at some point
about 1 year ago
0
0
0
One of my favorite tools for BEC cases just had a nice update! If you are working BEC cases, make sure and check it out
www.invictus-ir.com/news/the-mic...
loading . . .
Release: Microsoft Extractor Suite v3
https://www.invictus-ir.com/news/the-microsoft-extractor-suite-v3
about 1 year ago
0
1
0
reposted by
Mari DeGrazia
Phill Moore
about 1 year ago
Week 03 - 2025
#DFIR
thisweekin4n6.com/2025/01/19/w...
loading . . .
Week 03 – 2025
ThinkDFIRSRUMday Funday! Akash PatelHandling Incident Response: A Guide with Velociraptor and KAPE BelkasoftEmail Forensics with Belkasoft X Christopher Eng at Ogmini Homelab Part 1 – The Cur…
https://thisweekin4n6.com/2025/01/19/week-03-2025/
0
5
4
reposted by
Mari DeGrazia
mthcht
about 1 year ago
I made a windows
#DFIR
artifacts collection MindMap, it's tough to fit everything into a readable overview (might change later)
1
23
12
Time for a decaf latte and a wrap up from last week's forensic goodies!
add a skeleton here at some point
about 1 year ago
0
2
0
reposted by
Mari DeGrazia
Markus
about 1 year ago
For those looking to practice a realistic
#DFIR
scenario, here is a free case for you to investigate. Provided artifacts: - Disk Triage Collection - Memory Image + pagefile.sys: - PCAP File Link:
bluecapesecurity.com/courses/elev...
loading . . .
Elevate Your DFIR Skills: Deeper Insights and Practical Applications - Blue Cape Security
https://bluecapesecurity.com/courses/elevate-your-dfir-skills-workshop-series/
1
9
4
Found my first
#cruisingducks
during my Christmas 🎄 cruise this year. Should I rehide it, or keep it???
about 1 year ago
0
0
0
This is so important. Even if it's just a comment on a blog, something new you've seen with an update, find a way to share it with the community.
add a skeleton here at some point
about 1 year ago
0
1
0
Want to learn more about conducting forensic investigations on Windows? I will be teaching SANS FOR500: Windows Forensic Analysis in San Francisco end of next month! Day 2 is my fav where we dive into the registry!
www.sans.org/cyber-securi...
loading . . .
SANS San Francisco Winter 2025 | Cyber Security Training
SANS San Francisco Winter 2025 (Jan 27-Feb 1) offers hands-on cyber security training taught by real-world practitioners. Attend Live Online or in San Francisco, CA.
https://www.sans.org/cyber-security-training-events/san-francisco-winter-2025/
about 1 year ago
1
1
0
reposted by
Mari DeGrazia
Patrick C Miller
about 1 year ago
Black Basta Ransomware Uses MS Teams, Email Bombing to Spread Malware
loading . . .
Black Basta Gang Uses MS Teams, Email Bombing to Spread Malware
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
https://hackread.com/black-basta-gang-ms-teams-email-bombing-malware/
0
11
4
reposted by
Mari DeGrazia
Arsenal Recon
about 1 year ago
Releasing a new
#DFIR
tool today! Swap Recon performs brute-force decompression of Windows 10 & 11 swap. Swap Recon was built when we couldn't find existing tools or techniques to decompress modern Windows swap properly in one of our highest-stakes cases.
arsenalrecon.com
1
9
6
reposted by
Mari DeGrazia
Maximilian Larum
about 1 year ago
New cyber humble bundle out!
#DFIR
#cyber
#infosec
#security
www.humblebundle.com/books/hackin...
loading . . .
Humble Tech Book Bundle: Hacking 2024 by No Starch
Level up your hacking and skills with this tech bundle from No Starch. Learn to protect yourself and others! Pay what you want & support charity!
https://www.humblebundle.com/books/hacking-2024-no-starch-books?hmb_source=&hmb_medium=product_tile&hmb_campaign=mosaic_section_1_layout_index_1_layout_type_threes_tile_index_1_c_hacking2024nostarch_bookbundle
0
2
2
reposted by
Mari DeGrazia
Alexis Brignoni🪫
about 1 year ago
It sure was.
#DigitalForensics
#MobileForensics
#DFIR
1
19
2
Sunday morning reading - catch up on the latest
#DFIR
with
@phillmoore.bsky.social
. There is a great article on RDP bitmap cache.. speaking of which.. don't forget to check for RDP Thumbnails if the RDP App was used. Check out my blog post here on it:
www.zerofox.com/blog/remote-...
add a skeleton here at some point
about 1 year ago
0
5
0
reposted by
Mari DeGrazia
Chris DiSalle
about 1 year ago
While there are some awesome methods to detect web shells with Yara, sometimes structured data can help solve the case. In this oversimplified example, I go over how you can use two artifacts with Velociraptor to help you find evil on your Linux server.
#dfir
#blueteam
#cybersecurity
loading . . .
Hunting Linux Web Shells with Velociraptor
Linux forensics can be tricky, especially when investigating subtle threats like web shells. Unlike Windows, which provides tools like the Master File Table ($MFT) for metadata-rich investigations, Li...
https://www.linkedin.com/pulse/hunting-linux-web-shells-velociraptor-chris-disalle-wfame
0
10
6
reposted by
Mari DeGrazia
Jessica Hyde
about 1 year ago
#DFIR
💭 of the Day:
#CTFs
are a fantastic way to learn! They are a great way to learn providing access to forensic images and questions that can increase and challenge your skills. Registration is now open for the Magnet Virtual Summit 2025 CTF powered by Hexordia.
youtu.be/YNEnpwoADKs
loading . . .
Capture The Flag 2025
YouTube video by Magnet Forensics
https://youtu.be/YNEnpwoADKs?si=qahkY4TA8f8DcfVM
0
11
5
reposted by
Mari DeGrazia
Ali Hadi | B!n@ry
about 1 year ago
If you're interested in Linux DFIR? Then check all our talks/workshops below.
#Linux
#DFIR
#Cybersecurity
CC:
@maryst33d.bsky.social
linuxdfir.ashemery.com
0
37
14
I love this weekly blog. Helps keep me up to date, especially on weeks where I am busy traveling.
add a skeleton here at some point
about 1 year ago
0
3
0
reposted by
Mari DeGrazia
Alexis Brignoni🪫
about 1 year ago
Indeed.
0
91
13
reposted by
Mari DeGrazia
Taggart
about 1 year ago
1. Velociraptor rips 2. Whitney and Eric are the best at what they do. Don't miss this opportunity if you have any interest in the material.
add a skeleton here at some point
3
16
6
you reached the end!!
feeds!
log in