Sign in

Ali Hadi | B!n@ry

@binaryz0ne.bsky.social
1.4K followers 102 following 178 posts

DFIR and Adversary Simulation

PostsRepliesMedia
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 15/09/2025
After more than a decade in academia, teaching thousands of students and professionals, I’ve decided to return to the world of consulting. I’m deeply grateful to my family for their unwavering support and to everyone who has helped me grow into the person I am today. #DFIR
140
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 15/09/2025
I want to thank @brettshavers.bsky.social for the opportunity taking his "DF/IR Investigative Mindset" course! This is an amazing course for everyone! Whether you're a vetran or just starting your #DFIR career. I can't recommend it enough. Brett, thank you so much 🙏🏻
131
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 07/09/2025
Or these PDF/TXT executables!
100
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 07/09/2025
For those who love executables :)
100
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 28/07/2025
🚀 Starting August, you'll be able to test your malware analysis skills with our upcoming certification exam! Huge thanks to "Saad AHLA" for leading the development of this challenge. Get ready, this is truly a fun one! #malware #DFIR #CyberSecurity #ThreatHunting #BlueTeam #CCMA
011
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 28/07/2025
Our CCDFA Bootcamp is one of the best deals in DFIR training! The course content, labs, virtual lab access, and live sessions all included. Only have 2 seats left for the August bootcamp! academy.cyber5w.com/courses/c5w-... #DFIR #DigitalForensics #CyberSecurity #BlueTeam #IncidentResponse
academy.cyber5w.com
C5W CERTIFIED DIGITAL FORENSICS ANALYST - LIVE TRAINING
The Windows Forensics course explores the forensic artifacts one may encounter when working with the Windows operating system. This course is focused on hands-on labs that covers artifacts, which are ...
021
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 27/07/2025
Last semester I created a course to help students start learning about Threat Simulation & Hunting. I used GOAD for the testing environement. So shoutout to @M4yFly for creating GOAD. Every lab was themed around the Game of Thrones series; students liked it. labs.cyber5w.com/courses/218b...
labs.cyber5w.com
Threat Simulation and Hunting
From Shells to Thrones - Think Like an Adversary. Hunt as a Defender. Protect the Kingdom.
111
Reposted by Ali Hadi | B!n@ry
Phill Moore @phillmoore.bsky.social · 27/07/2025
Week 30 - 2025 #DFIR thisweekin4n6.com/2025/07/27/w...
thisweekin4n6.com
Week 30 – 2025
Use the discount code thisweekin4n6 for 15% off any class at Cyber5w.Use the code PM15 or click this link for 15% your next Hexordia classTakes a class with me! Akash Patel Who’s Using a Proxy or V…
011
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 27/07/2025
We created a simple certification exam "C5W Certified Digital Forensics Foundations (CDFF)" for those who took our FREE Intro to Digital Forensics course and want to test their skills #DFIR academy.cyber5w.com/courses/c5w-... #DFIR #C5W #CyberSecurity #DigitalForensics
academy.cyber5w.com
C5W Certified Digital Forensics Foundations Exam
The CDFF exam validates your understanding of digital forensics fundamentals, including evidence acquisition, file systems, FTK Imager, timestamp analysis, and reporting, ideal for beginners entering ...
121
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 27/07/2025
If you’re looking to get into Digital Forensics, this is probably the most affordable & complete training you’ll find. The value packed into this bootcamp goes far beyond the price, & right now, there’s a discount running! #DFIR #DigitalForensics #CyberSecurity PLEASE SHARE with others! Thank You!
110
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 27/07/2025
🔒 Master Windows Sandbox for secure app testing! Learn to install, configure, and safely run suspicious apps in an isolated environment. 💻 Hands-on labs included 💰 You can take it for FREE or Pay to Support Us! labs.cyber5w.com/courses/975e... #CyberSecurity #DFIR #C5W #WindowsSandbox #malware
000
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 24/06/2025
This is a great opportunity for beginners to put their skills to the test! #DFIR #Cybersecurity #Infosec #DigitalForensics
041
Reposted by Ali Hadi | B!n@ry
OpenSecurityTraining2 @opensectraining.bsky.social · 02/06/2025
We're happy to announce that @cyber5w.bsky.social is renewing their sponsorship of #OST2 at the Bronze🥉 level in 2025! Learn more about Cyber5W and their forensics training here: ost2.fyi/Sponsor_Cybe...
053
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 05/05/2025
I was asked last week to help some students in the lab, but got surprised by my Digital Forensics senior students being there for one last time and giving me this gift! I will miss you all and I am so lucky that I got to work with you for the last 4 years! THANK YOU SO MUCH ❤️
110
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 29/04/2025
This modexp.wordpress.com/2025/04/27/b... is an interesting post by modexpblog ... highly recommend checking it out.
modexp.wordpress.com
Beacon Object Files vs Tiny EXE Files
TL;DR A lot of bloat in an EXE file is just the statically linked C runtime. Link dynamically to msvcrt.dll (or ucrtbase.dll on Win 10+) plus a 40-line stub, and depending on the size of the progra…
010
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 26/04/2025
Join me at the @ Techno Security & Digital Forensics Conference! I’ll be speaking on "Utilizing ETW for Ransomware Threat Detection" Register today at technosecurity.us/east/registr... and save 10% with code SPK25 #TechnoSecurity #DFIR #Malware #Ransomware
020
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 26/04/2025
Great thread to read #DFIR
010
Reposted by Ali Hadi | B!n@ry
Arsenal Recon @arsenalrecon.bsky.social · 25/04/2025
Arsenal Image Mounter v3.11.307 is now available with minor fixes & other improvements which include improved handling of corrupt Registry hives when launching virtual machines. See the change log for more information. arsenalrecon.com/downloads #DFIR
022
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 16/04/2025
Excited to announce that I’ll be delivering a keynote at ICTCS’25 titled: "Beyond Tools: DFIR in the Era of Emerging Threats" Looking forward to connecting with researchers at #ICTCS25! #DFIR #CyberSecurity #DigitalForensics
031
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 05/04/2025
Using Windows Sandbox - Course This is another FREE course to learn howto setup and use Windows Sandbox for #malware analysis or anything you want. #DFIR #infosec #CyberSecurity Check it out: labs.cyber5w.com/courses/975e...
labs.cyber5w.com
Micro - Using Windows Sandbox
In this micro-course, you will learn how to install and configure Windows Sandbox to be used for different testing scenarios, such as malware analysis. By the end of this course, you will have a fully...
040
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 05/04/2025
Interested in learning about #DFIR and don't know where to start? Then I recommend checking our full "C5W-100 - Introduction to Digital Forensics" course. It is completely FREE and it should help you get started. #infosec #cybersecurity CC: @cyber5w.bsky.social academy.cyber5w.com/courses/C5W-...
academy.cyber5w.com
C5W-100 INTRODUCTION TO DIGITAL FORENSICS
012
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 05/04/2025
Hey #DFIR community! I’m excited to share that I’ve turned my 010 Editor video series into a full course. It includes 40+ videos and hands-on labs, so you can practice what you learn. Please share with anyone who might find it useful!
151
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 07/03/2025
Scheduled Tasks and GhostTask Investigations | #ShadowMe Webinar #DFIR #Cybersecurity www.youtube.com/watch?v=Xhez...
youtube.com
Scheduled Tasks and GhostTask Investigations | ShadowMe Webinar
YouTube video by Ali Hadi
020
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 01/03/2025
What to expect in the #ShadowMe series? #DFIR #Cybersecurity #Malware #Infosec ShadowMe #1 - Intro to Static Malware Analysis youtube.com/watch?v=8qq0...
151
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 21/02/2025
Don't miss the livestream tomorrow with @johnhammond.bsky.social talking #DFIR ...
041
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 11/02/2025
📢 Missed our IoT Forensics webinar? Watch it now! 🎥 Expert @cyberyom.bsky.social shares key techniques for extracting & analyzing data from IoT devices. Don't miss out! 🚀 Watch here: academy.cyber5w.com/courses/webi... #DFIR #Cybersecurity #Infosec #IoT #Investigations
academy.cyber5w.com
Webinar #6: IoT Forensics
In this webinar, IoT forensics expert Tom Claflin explored the role of IoT devices in modern investigations, demonstrating data extraction techniques, device disassembly, and key forensic tools. He al...
020
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 08/02/2025
Hey #DFIR community. Last month, we decided to open our @cyber5w.bsky.social C5W-100 Intro to Digital Forensics course & make it FREE; yes completely FREE! Since then more than 1K of new learners joined & we hope more will too. Please share with anyone who wants to learn. #Cybersecurity
1104
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 05/02/2025
Happening now by @cyberyom.bsky.social #DFIR #IoT #Cybersecurity
000
Reposted by Ali Hadi | B!n@ry
hasherezade.bsky.social @hasherezade.bsky.social · 26/01/2025
In case if you wonder what broke #ProcessHollowing on Windows 11 24H2, I have something for you: hshrzd.wordpress.com/2025/01/27/p...
hshrzd.wordpress.com
Process Hollowing on Windows 11 24H2
Process Hollowing (a.k.a. RunPE) is probably the oldest, and the most popular process impersonation technique (it allows to run a malicious executable under the cover of a benign process). It is us…
05838
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 01/02/2025
Some people tend to forget that kindness and manners are free. #life
060
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 29/01/2025
If you're interested in #IoT #DFIR? Don't miss this month's @cyber5w.bsky.social webinar. We have a special guest @cyberyom.bsky.social who will do both HW+SW forensics on an IoT device. #infosec #cybersecurity #webinar #C5W academy.cyber5w.com/products/liv...
032
Reposted by Ali Hadi | B!n@ry
The DFIR Report @thedfirreport.bsky.social · 27/01/2025
🌟New report out today!🌟 Cobalt Strike and a Pair of SOCKS Lead to LockBit Ransomware Analysis & reporting completed by @r3nzsec, @MyDFIR & @MittenSec. Audio: Available on Spotify, Apple, YouTube and more! thedfirreport.com/2025/01/27/c...
thedfirreport.com
Cobalt Strike and a Pair of SOCKS Lead to LockBit Ransomware
Key Takeaways This intrusion began with the download and execution of a Cobalt Strike beacon that impersonated a Windows Media Configuration Utility. The threat actor used Rclone to exfiltrate data…
12410
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 26/01/2025
Scheduled Tasks and GhostTask Investigations | #ShadowMe Webinar recording... Special thanks to @maryst33d.bsky.social for joining me... The recording can be found below. #DFIR #Investigations www.youtube.com/watch?v=Xhez...
youtube.com
Scheduled Tasks and GhostTask Investigations | ShadowMe Webinar
YouTube video by Ali Hadi
021
Reposted by Ali Hadi | B!n@ry
Phill Moore @phillmoore.bsky.social · 26/01/2025
Week 04 - 2025 #DFIR thisweekin4n6.com/2025/01/26/w...
thisweekin4n6.com
Week 04 – 2025
Added something new to the site this week; a couple of training vendors have reached out to offer readers a discount on their next training class purchase. Using these discount codes will also supp…
042
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 07/01/2025
Exciting News🚀🎉: Our @cyber5w.bsky.social Intro to DFIR Course is now FREE!🔍 Please read our announcement found below. The course will also be available for FREE @opensectraining.bsky.social very soon! #DFIR #infosec #cybersecurity #DigitalForensics cyber5w.com/into-dfir.html
11610
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 06/01/2025
This was the output of Zeek! #DFIR #Cybersecurity #Infosec #malware
062
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 06/01/2025
Something big is coming... Tomorrow, I'll reveal what it's all about! ... Stay tuned! 🚀 #DFIR #Infosec #Cybersecurity
042
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 03/01/2025
T-Warz is our new CTF going live at TechnoSecurity East this year! This isn’t your ordinary CTF, it’s a #Cyberwarzone! If you’re up for a challenge, join us. Don’t miss out! #DFIR #Cybersecurity #CTF www.technosecurity.us/east/confere...
157
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 01/01/2025
This is a nice micro course if anyone is interested in learning how to use Windows Sandbox for Malware Analysis. Your feedback is very welcomed! #DFIR #Cybersecurity #Infosec #WindowsSandbox #Sandbox labs.cyber5w.com/courses/975e...
083
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 30/12/2024
Our @cyber5w.bsky.social next month #DFIR webinar will be about Windows Scheduled Tasks and GhostTask Investigations. #DFIR #Cybersecurity #infosec If you would like to join, please sign-up below (FREE). bit.ly/ghost-task
bit.ly
Webinar #5: Scheduled Tasks and GhostTask Investigations
Discover the secrets of Windows Forensic Investigations in our exclusive online event. Learn how to master Scheduled Tasks and GhostTasks for enhanced digital investigations.
142
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 30/12/2024
What are ppl using to export data from #Elastic to copy to another elasticsearch host? #DFIR #Cybersecurity #logs #elasticsearch #SOC
000
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 30/12/2024
Parsing Multiple Registry Hives using VSCToolset and RegRipper #DFIR #Windows #Investigations www.youtube.com/watch?v=Lokq...
000
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 30/12/2024
Parsing Run Keys using RegRipper #DFIR #Windows www.youtube.com/watch?v=OhOx...
011
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 30/12/2024
Run Key Mystery - Did the Program Truly Run or Not? #DFIR #Windows #Investigations www.youtube.com/watch?v=un48...
000
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 27/12/2024
I have a huge announcement coming first week of 2025! Don't miss it :) #DFIR #Cybersecurity #Infosec
040
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 23/12/2024
You take the red pill... you stay in Artifactland, and I show you how deep the rabbit hole goes… You take the blue pill, the story ends, you wake up in your bed and believe whatever you want to believe about your logs… #DFIR Thanks to @brettshavers.bsky.social for sharing this!
180
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 20/12/2024
Fast Way to Build and use Batch Files with Eric Zimmerman's RECmd ... #DFIR Note: this is an update to my previous recording which had some sound issues... I also added something extra related to KAPE based on the feedback I received... www.youtube.com/watch?v=jn8J...
youtube.com
Fast Way to Build and use Batch Files with Eric Zimmerman's RECmd
YouTube video by Ali Hadi
070
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 19/12/2024
Fast Way to Build and use Batch Files with Eric Zimmerman's RECmd #DFIR www.youtube.com/watch?v=KfjP...
131
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 15/12/2024
Recording of December 2024 Webinar: Windows Forensic Investigation – Internal Investigation (Part 1) #DFIR #Cybersecurity #Infosec www.youtube.com/watch?v=kDFd...
141