Andrew Case @attrc.bsky.social · 21/07/2026To summarize: HuggingFace got compromised by a model from an American company. HF then tried to use American frontier model(s) to defend themselves, but were blocked by guardrails. HF then had to use open source Chinese models to defend themselves from an American org openai.com/index/huggin... 096
Andrew Case @attrc.bsky.social · 20/07/2026Thank you to @jags.bsky.social for the @volexity.com shout out in the latest Three Buddy Problem episode! If you aren't performing memory forensics in your environments, then you cannot make any definitive claims on whether you are compromised! podcasts.apple.com/us/podcast/h... 054
Andrew Case @attrc.bsky.social · 19/06/2026I am very excited to announce that my @volatilityfoundation.org 3 workshop with David McDonald and Pierre Breton was accepted for @defcon.bsky.social this summer!! 0103
Reposted by Andrew CaseVolexity @volexity.com · 15/06/2026Great conversations at #FIRSTCON26 so far! Come say hello to the @volexity.com team at Booth 7 & see how to rapidly resolve your investigations and find what other tools are missing. #DFIR #FIRSTCON #memoryforensics 023
Andrew Case @attrc.bsky.social · 08/06/2026Memory forensics is a required technique to detect and respond to modern malware. Come see Volcano in action at FIRST next week to learn how memory forensics can be applied at true enterprise scale. 021
Andrew Case @attrc.bsky.social · 04/06/2026Our new blog post details our investigation into how a compromised MSP led to at least one of its customers being compromised, including deployment of the BRICKSTORM malware on multiple edge devices. 042
Reposted by Andrew CaseAndrew Case @attrc.bsky.social · 14/04/2026Memory-only malware leaves no trace on the file system and is commonly used by threat actors ranging from criminal organizations to ransomware operators to APT groups. In our Volatility 3 training, students gain deep hands on experience analyzing such threats: memoryanalysis.net/courses-malw... 099
Reposted by Andrew Casebsidesmemphis.bsky.social @bsidesmemphis.bsky.social · 30/03/2026SAVE THE DATE!! BSides Memphis will be hosted at Epicenter Memphis on October 3rd, 2026! More info to come on tickets, CFP, Sponsors, ect. please share so the local community knows this is happening! 022
Reposted by Andrew CasePIVOTcon @pivotcon.bsky.social · 30/04/2026Countdown is real ⌛️ Next week‼️ #ThreatResearch community gathers in Málaga 🇪🇸 Time to remind our PIVOTcon song: soundcloud.com/argonix/pivo... But watch out — it's a banger! #CTI #ThreatIntel #PIVOTcon26media.tenor.coma man in a white sweater is playing a keyboard with a vase of flowers in the backgroundALT: a man in a white sweater is playing a keyboard with a vase of flowers in the background 098
Andrew Case @attrc.bsky.social · 17/04/2026I am excited to announce that I will be speaking at BSides Nashville on May 15th. Be sure to attend to see all the latest Volatility 3 (@volatilityfoundation.org) plugins against the most sophisticated and devastating malware from the wild! bsidesnash.orgbsidesnash.orgBSides Nashville 035
Andrew Case @attrc.bsky.social · 14/04/2026Memory-only malware leaves no trace on the file system and is commonly used by threat actors ranging from criminal organizations to ransomware operators to APT groups. In our Volatility 3 training, students gain deep hands on experience analyzing such threats: memoryanalysis.net/courses-malw... 099
Reposted by Andrew CaseVolatility @volatilityfoundation.org · 06/03/2026We are excited to announce the First Place winner of the 2025 #Volatility #PluginContest is: Daniel Baier for XRFM Inspector See the full Contest Results in our blog post: volatilityfoundation.org/the-2025-vol... Congrats to all winners & thank you to all participants! #DFIR #memoryforensicsvolatilityfoundation.orgThe 2025 Volatility Plugin Contest results are in!Results from the 13th Annual Volatility Plugin Contest are in! We received 8 submissions from 7 different countries that included 20 plugins. Contest submissions included a range of features… 153
Reposted by Andrew CaseVolexity @volexity.com · 04/12/2025@volexity.com tracks a variety of threat actors abusing Device Code & OAuth authentication workflows to phish credentials, which continue to see success due to creative social engineering. Our latest blog post details Russian threat actor UTA0355’s campaigns impersonating European security events.volexity.comDangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing AttacksIn early 2025, Volexity published two blog posts detailing a new trend among Russian threat actors targeting organizations through the abuse of Microsoft 365 OAuth and Device Code authentication workf... 0108
Reposted by Andrew CaseVolexity @volexity.com · 14/11/2025@volexity.com has continued to see nation-state threat actors use AI + LLMs to assist in cyber attacks. Our recent research on a Chinese APT threat actor (UTA0388) using AI in its operation was something @stevenadair.bsky.social recently discussed with the @wsj.com. 144
Reposted by Andrew CaseVolatility @volatilityfoundation.org · 21/10/2025We had a great day yesterday at #FTSCon 2025! FTSCon Week continues with @joegrand.bsky.social's Hardware Hacking Basics + #Volatility Malware & Memory Forensics training with @attrc.bsky.social, Michael Ligh + Dave Lassalle. 024
Reposted by Andrew CaseVolatility @volatilityfoundation.org · 07/10/2025We would like to thank @volexity.com for sponsoring the #FTSCon 2025 Evening Reception, which will be at VUE Rooftop DC this year! If you haven’t registered for FTSCon yet, there’s still time! Registration closes Sunday Oct 12; learn more + register here: volatilityfoundation.org/from-the-sou... 034
Andrew Case @attrc.bsky.social · 06/10/2025The full lineup for our From the Source event is out! The event take places on October 20th in Arlington, VA. Joe Grand will keynote followed by an amazing speaker line up across two tracks. All proceeds will be donated to Connect Our Kids. volatilityfoundation.org/from-the-sou...volatilityfoundation.orgFrom The Source 2025Learn Directly from the World’s Leading Digital Investigators: On Monday, October 20, 2025, the Volatility Foundation is hosting From The Source, a one-day summit, in Arlington, VA, followed by fou… 033
Andrew Case @attrc.bsky.social · 03/10/2025With Volcano, security teams can automate the entire workflow of acquisition of memory and select files to deep analysis to automated alerts that directly point to signs of memory only malware and attacker activity throughout RAM and key artifacts sources from disk. 042
Reposted by Andrew CaseVolatility @volatilityfoundation.org · 19/09/2025#FTSCon Speaker Spotlight: Joe FitzPatrick (@securelyfitz.bsky.social) is presenting “Rethinking DMA Attacks with Erebus” in the MAKER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou... 015
Reposted by Andrew CaseVolatility @volatilityfoundation.org · 18/09/2025#FTSCon Speaker Spotlight: Andrew Case (@attrc.bsky.social) is presenting “Detection and Analysis of Memory-Only Linux Rootkits” in the MAKER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou... 024
Andrew Case @attrc.bsky.social · 08/09/2025I am very happy to announce that @volexity.com will be well represented at @bsidesnyc.org! David McDonald will be speaking on his latest automated Powershell Deobfuscation research & I will present the latest Volatility 3 advancements against sophisticated Windows malware: bsidesnyc.org/schedule/bsidesnyc.orgEvent ScheduleBSides NYC is an Information / Security conference that’s different. We’re a 100% volunteer organized event put on by and for the community, and we truly strive to keep information free. 134
Reposted by Andrew CaseAndrew Case @attrc.bsky.social · 03/09/2025The next in-person offering of our Malware and Memory Forensics Training will be held in Arlington, VA from Oct 21st-24th. This course has converted to Volatility 3, and all the material and labs are updated to cover the latest threats & analysis techniques memoryanalysis.net/courses-malw...memoryanalysis.netMalware and Memory Forensics Training - Memory AnalysisMalware and memory forensics training courses offered by the Memory Analysis Team. 076
Andrew Case @attrc.bsky.social · 03/09/2025The next in-person offering of our Malware and Memory Forensics Training will be held in Arlington, VA from Oct 21st-24th. This course has converted to Volatility 3, and all the material and labs are updated to cover the latest threats & analysis techniques memoryanalysis.net/courses-malw...memoryanalysis.netMalware and Memory Forensics Training - Memory AnalysisMalware and memory forensics training courses offered by the Memory Analysis Team. 076
Andrew Case @attrc.bsky.social · 02/09/2025At @bsidesorl.bsky.social, David McDonald and I will be delivering a hands-on workshop on using @volatilityfoundation.org 3 to detect sophisticated, memory-only malware as seen in the wild. Sign up ASAP before it fills! 175
Reposted by Andrew CaseCYBERWARCON @cyberwarcon.bsky.social · 28/08/2025CYBERWARCON is coming!!! Registration and CFP are now open for this year's #CYBERWARCON! This year's keynote speaker will be @dmitri.silverado.org!! We are back in Arlington, VA this year on November 19th. www.cyberwarcon.comcyberwarcon.comCYBERWARCON 12822
Andrew Case @attrc.bsky.social · 03/08/2025If you will be at @bsideslv.org on Monday, then be sure to check out David's talk on automated detection and de-obfuscation of malicious Powershell scripts! bsideslv.org/talks#LBQDEBbsideslv.orgTalks - BSides Las VegasBSides Las Vegas is a nonprofit organization formed to stimulate the Information Security industry and community. 173
Reposted by Andrew CaseVolexity @volexity.com · 09/07/2025This training course will be led by Andrew Case @attrc.bsky.social, Michael Ligh & Dave Lassalle. This is a great opportunity to gain valuable knowledge about #Volatility3 + learn all about #memoryforensics from Volatility core developers! Seats are filling up quickly so don't wait! 068
Reposted by Andrew CaseAndrew Case @attrc.bsky.social · 17/06/2025I am *very* excited to announce that the workshop I submitted to @defcon.bsky.social along with @lsu.bsky.social PhD students, Lauren Pace and Daniel Donze, was accepted!!! We will teach you how to automatically detect and analyze the sophisticated, memory-only malware techniques used in the wild. 13710
Andrew Case @attrc.bsky.social · 02/07/2025I am excited to announce that I will be speaking at @hou-sec-con.bsky.social at the end of September in Houston! Be sure to check out my talk on Tuesday morning and my friend @mayahustle.bsky.social's talk on Wednesday afternoon. Full agenda at the following link: web.cvent.com/event/9ba9c5...web.cvent.comAgenda - HOU.SEC.CON. 2025 010
Reposted by Andrew CaseDaniel @dadonzeaux.bsky.social · 02/07/2025Super excited to help @attrc.bsky.social teach memory forensics at a @defcon.bsky.social workshop this year! I'll also be at @bsideslv.org earlier in the week as well so if you run into me please say hi! (And I will have cool stickers) 011
Reposted by Andrew Caselsuresearch.bsky.social @lsuresearch.bsky.social · 30/06/2025#LSU cyber students will teach new ways to fight malware at the world’s largest and longest-running hacking conference @defcon.bsky.social www.lsu.edu/blog/2025/06... #ScholarshipFirst #WBTTW @lsu.bsky.social @lsuengineering.bsky.social @attrc.bsky.social @volexity.com @volatilityfoundation.org 033
Andrew Case @attrc.bsky.social · 18/06/2025With Volcano for analysis and Surge Collect Pro for acquisition, you can automatically check your critical systems for signs of malware and attacker toolkits across memory and key artifact sources from disk. Contact us if you would like to schedule a virtual demo or one in person in Vegas! 000
Andrew Case @attrc.bsky.social · 17/06/2025I am *very* excited to announce that the workshop I submitted to @defcon.bsky.social along with @lsu.bsky.social PhD students, Lauren Pace and Daniel Donze, was accepted!!! We will teach you how to automatically detect and analyze the sophisticated, memory-only malware techniques used in the wild. 13710
Andrew Case @attrc.bsky.social · 13/06/2025The CFP for our 2nd annual From the Source event is now open! The event includes two tracks, the first for Makers of open source DFIR tools and the second for Hunters who have performed the most interesting investigations of the last year. volatilityfoundation.org/announcing-f...volatilityfoundation.orgAnnouncing FTSCon 2025 & In-person Malware and Memory Forensics Training!Mark your calendars for Monday, October 20, 2025! We will again be hosting FTSCon in Arlington, Virginia.You can read more event details here. Registration is now open! 023
Andrew Case @attrc.bsky.social · 11/06/2025Our highly popular and technical training, "Malware and Memory Forensics with Volatility", has been fully converted to @volatilityfoundation.org 3 and significantly updated, including many new sections and 8 new, in-depth labs. Available online & in VA in October memoryanalysis.net/courses-malw...memoryanalysis.netMalware and Memory Forensics Training - Memory AnalysisMalware and memory forensics training courses offered by the Memory Analysis Team. 074
Reposted by Andrew CaseDerek B. Johnson @derekbjohnson.bsky.social · 04/06/2025I tried to strike a balance in this story between the dangers I was hearing about AI-assisted and "vibe coded" software and the hard, cold reality that there's probs no going back and this is going to be (if it isn't already) the "new normal" for huge chunks of software development. Check it out! 1127
Reposted by Andrew CaseAndrew Case @attrc.bsky.social · 19/05/2025I will be showing off Volatility 3 during my talk on Wednesday afternoon at RVASec. Be sure to attend and come say hello if you will be around! rvasec.com/rvasec-14-sp...rvasec.comRVAsec 14 Speaker Feature: Andrew Case - RVAsecAndrew Case is the Director of Research at Volexity and has significant experience in incident response handling, digital forensics, and malware analysis. Case is a core developer of Volatility, the m... 097
Andrew Case @attrc.bsky.social · 19/05/2025I will be showing off Volatility 3 during my talk on Wednesday afternoon at RVASec. Be sure to attend and come say hello if you will be around! rvasec.com/rvasec-14-sp...rvasec.comRVAsec 14 Speaker Feature: Andrew Case - RVAsecAndrew Case is the Director of Research at Volexity and has significant experience in incident response handling, digital forensics, and malware analysis. Case is a core developer of Volatility, the m... 097
Andrew Case @attrc.bsky.social · 16/05/2025We are VERY excited to announce that Volatility 3 has now reached feature parity with Volatility 2! With this parity release, Volatility 2 is now deprecated. Full details in the blog post linked below. 02011
Andrew Case @attrc.bsky.social · 01/04/2025Check out this great research and new open source tool by our threat intel team! 0137
Reposted by Andrew CaseAndrew Case @attrc.bsky.social · 07/03/2025I will be speaking at @kernelcon.bsky.social on Fri, Apr 3rd. The talk will cover previously-unreported features of the sedexp Linux malware found in the wild - including loading of a memory-only rootkit! Talk will cover how the rootkit was discovered & how to analyze with @volatilityfoundation.orgkernelcon.org 0129
Reposted by Andrew CasePIVOTcon @pivotcon.bsky.social · 26/03/2025We are excited to present our #PIVOTcon25 #Keynote speaker: Jackie Burns Koven! She is Head of Cyber Threat Intelligence at @chainalysis.bsky.social where her team tracks the wallets of those who scam, steal, and extort for cryptocurrency 💰💸🦹 #CTI #ThreatIntel (1/4) 11910
Andrew Case @attrc.bsky.social · 23/03/2025Six days away! I am very much looking forward to speaking in San Diego next weekend! 031
Andrew Case @attrc.bsky.social · 20/03/2025The sedexp Linux malware was disclosed in late 2024. In my talk at @kernelcon.bsky.social, I will present my own deep dive of the malware, including many parts that have not been made public, such as loading of a memory-only rootkit. Be sure to attend for a teardown with @volatilityfoundation.org 3! 0127
Andrew Case @attrc.bsky.social · 07/03/2025I will be speaking at @kernelcon.bsky.social on Fri, Apr 3rd. The talk will cover previously-unreported features of the sedexp Linux malware found in the wild - including loading of a memory-only rootkit! Talk will cover how the rootkit was discovered & how to analyze with @volatilityfoundation.orgkernelcon.org 0129
Andrew Case @attrc.bsky.social · 05/03/2025The 2005 DFRWS Windows memory forensics challenge spawned a generation of DFIR researchers, and the 2008 Linux challenge is what led me to @volatilityfoundation.org. The 25th anniversary event will be held in Chicago this summer and promises to be an incredible time: dfrws.org/dfrws-jubile...dfrws.orgDFRWS Jubilee - 25th Anniversary - DFRWSThis year is the 25th anniversary of the Digital Forensics Research Conference. The DFRWS community has grown from a small group of researchers and practitioners to collaboration of thousands around t... 064
Andrew Case @attrc.bsky.social · 03/03/2025On March 29th, I will be speaking at @bsidessd.bsky.social on Volatility 3, including all its new features and plugins. Be sure to attend to catch a sneak peak at the new framework before the major release later this Spring! www.bsidessd.org #DFIR #infosec 087
Andrew Case @attrc.bsky.social · 21/02/2025I will be attending RE//verse next weekend in Orlando. Let me know if you will be around and want to meet up: re-verse.iore-verse.ioRE//verseRE//verse is a premier reverse engineering, vulnerability research and malware analysis conference. We offer trainings and talks from industry-leading experts. 020
Andrew Case @attrc.bsky.social · 01/02/2025If you will be at @wildwesthackinfest.bsky.social next week then be sure to attend my talk! 064