Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 15/09/2025Soon, I’ll be joining an incredible team, and I truly can’t wait to begin this next chapter of my #DFIR career! THANK YOU ALL! 020
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 15/09/2025After more than a decade in academia, teaching thousands of students and professionals, I’ve decided to return to the world of consulting. I’m deeply grateful to my family for their unwavering support and to everyone who has helped me grow into the person I am today. #DFIR 140
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 15/09/2025Course can be found here: www.suspectbehindthekeyboard.comsuspectbehindthekeyboard.comPlacing the Suspect Behind the KeyboardDFIR attribution; that is the key to DFIR. 010
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 15/09/2025I want to thank @brettshavers.bsky.social for the opportunity taking his "DF/IR Investigative Mindset" course! This is an amazing course for everyone! Whether you're a vetran or just starting your #DFIR career. I can't recommend it enough. Brett, thank you so much 🙏🏻 131
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 09/09/2025these are related to the idea that there is a way to run an executable disguised as a .txt / .pdf / .lol or whatever. I just have not found the time to document it yet. 000
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 28/07/2025🚀 Starting August, you'll be able to test your malware analysis skills with our upcoming certification exam! Huge thanks to "Saad AHLA" for leading the development of this challenge. Get ready, this is truly a fun one! #malware #DFIR #CyberSecurity #ThreatHunting #BlueTeam #CCMA 011
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 28/07/2025Our CCDFA Bootcamp is one of the best deals in DFIR training! The course content, labs, virtual lab access, and live sessions all included. Only have 2 seats left for the August bootcamp! academy.cyber5w.com/courses/c5w-... #DFIR #DigitalForensics #CyberSecurity #BlueTeam #IncidentResponseacademy.cyber5w.comC5W CERTIFIED DIGITAL FORENSICS ANALYST - LIVE TRAININGThe Windows Forensics course explores the forensic artifacts one may encounter when working with the Windows operating system. This course is focused on hands-on labs that covers artifacts, which are ... 021
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 27/07/2025This is what I have so far! #DFIR #ThreatSimulation #Cybersecurity #Offsec 020
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 27/07/2025I will be sharing all the content, which are basically the labs, files (simple tools/scripts/etc), and few presentations for anyone who would like to use in their classroom. So keep an eye out for this. #DFIR #Cybersecurity #Infosec #ThreatHunting #ThreatSimulation 110
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 27/07/2025If you have the resources, maybe through an Elastic or Splunk server and use that for your investigations/hunting/etc. That will be something for you to decide/do. 100
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 27/07/2025I did not want to use a SIEM (Elastic/Splunk/etc) to simulate situations when you don't have such a capability, but you will still need to do hunting/investigations with limited and/or FREE tools. So we installed Sysmon on all systems and had a Velociraptor server with agents. 100
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 27/07/2025Last semester I created a course to help students start learning about Threat Simulation & Hunting. I used GOAD for the testing environement. So shoutout to @M4yFly for creating GOAD. Every lab was themed around the Game of Thrones series; students liked it. labs.cyber5w.com/courses/218b...labs.cyber5w.comThreat Simulation and HuntingFrom Shells to Thrones - Think Like an Adversary. Hunt as a Defender. Protect the Kingdom. 111
Reposted by Ali Hadi | B!n@ryPhill Moore @phillmoore.bsky.social · 27/07/2025Week 30 - 2025 #DFIR thisweekin4n6.com/2025/07/27/w...thisweekin4n6.comWeek 30 – 2025Use the discount code thisweekin4n6 for 15% off any class at Cyber5w.Use the code PM15 or click this link for 15% your next Hexordia classTakes a class with me! Akash Patel Who’s Using a Proxy or V… 011
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 27/07/2025A few details about the exam: ✅ Hands-on, browser-based ✅ Covers imaging, file systems & artifacts ✅ Perfect for beginners & career switchers academy.cyber5w.com/courses/c5w-... #DFIR #C5W #CyberSecurity #DigitalForensics 010
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 27/07/2025We created a simple certification exam "C5W Certified Digital Forensics Foundations (CDFF)" for those who took our FREE Intro to Digital Forensics course and want to test their skills #DFIR academy.cyber5w.com/courses/c5w-... #DFIR #C5W #CyberSecurity #DigitalForensicsacademy.cyber5w.comC5W Certified Digital Forensics Foundations ExamThe CDFF exam validates your understanding of digital forensics fundamentals, including evidence acquisition, file systems, FTK Imager, timestamp analysis, and reporting, ideal for beginners entering ... 121
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 27/07/2025URL to Digital Forensics bootcamp: academy.cyber5w.com/courses/c5w-... #DFIR #DigitalForensics #CyberSecurity #C5Wacademy.cyber5w.comC5W CERTIFIED DIGITAL FORENSICS ANALYST - LIVE TRAININGThe Windows Forensics course explores the forensic artifacts one may encounter when working with the Windows operating system. This course is focused on hands-on labs that covers artifacts, which are ... 010
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 27/07/2025If you’re looking to get into Digital Forensics, this is probably the most affordable & complete training you’ll find. The value packed into this bootcamp goes far beyond the price, & right now, there’s a discount running! #DFIR #DigitalForensics #CyberSecurity PLEASE SHARE with others! Thank You! 110
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 27/07/2025🔒 Master Windows Sandbox for secure app testing! Learn to install, configure, and safely run suspicious apps in an isolated environment. 💻 Hands-on labs included 💰 You can take it for FREE or Pay to Support Us! labs.cyber5w.com/courses/975e... #CyberSecurity #DFIR #C5W #WindowsSandbox #malware 000
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 24/06/2025This is a great opportunity for beginners to put their skills to the test! #DFIR #Cybersecurity #Infosec #DigitalForensics 041
Reposted by Ali Hadi | B!n@ryOpenSecurityTraining2 @opensectraining.bsky.social · 02/06/2025We're happy to announce that @cyber5w.bsky.social is renewing their sponsorship of #OST2 at the Bronze🥉 level in 2025! Learn more about Cyber5W and their forensics training here: ost2.fyi/Sponsor_Cybe... 053
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 05/05/2025It has a remote control and can be used to change the light colors 😅 They also gave me a card with all of their kind words and signatures on it !!! Very lucky that I had such students and I will miss them a lot! Thank you for being my students ❤️ 000
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 05/05/2025I was asked last week to help some students in the lab, but got surprised by my Digital Forensics senior students being there for one last time and giving me this gift! I will miss you all and I am so lucky that I got to work with you for the last 4 years! THANK YOU SO MUCH ❤️ 110
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 29/04/2025This modexp.wordpress.com/2025/04/27/b... is an interesting post by modexpblog ... highly recommend checking it out.modexp.wordpress.comBeacon Object Files vs Tiny EXE FilesTL;DR A lot of bloat in an EXE file is just the statically linked C runtime. Link dynamically to msvcrt.dll (or ucrtbase.dll on Win 10+) plus a 40-line stub, and depending on the size of the progra… 010
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 26/04/2025Join me at the @ Techno Security & Digital Forensics Conference! I’ll be speaking on "Utilizing ETW for Ransomware Threat Detection" Register today at technosecurity.us/east/registr... and save 10% with code SPK25 #TechnoSecurity #DFIR #Malware #Ransomware 020
Reposted by Ali Hadi | B!n@ryArsenal Recon @arsenalrecon.bsky.social · 25/04/2025Arsenal Image Mounter v3.11.307 is now available with minor fixes & other improvements which include improved handling of corrupt Registry hives when launching virtual machines. See the change log for more information. arsenalrecon.com/downloads #DFIR 022
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 16/04/2025Excited to announce that I’ll be delivering a keynote at ICTCS’25 titled: "Beyond Tools: DFIR in the Era of Emerging Threats" Looking forward to connecting with researchers at #ICTCS25! #DFIR #CyberSecurity #DigitalForensics 031
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 05/04/2025Using Windows Sandbox - Course This is another FREE course to learn howto setup and use Windows Sandbox for #malware analysis or anything you want. #DFIR #infosec #CyberSecurity Check it out: labs.cyber5w.com/courses/975e...labs.cyber5w.comMicro - Using Windows SandboxIn this micro-course, you will learn how to install and configure Windows Sandbox to be used for different testing scenarios, such as malware analysis. By the end of this course, you will have a fully... 040
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 05/04/2025Interested in learning about #DFIR and don't know where to start? Then I recommend checking our full "C5W-100 - Introduction to Digital Forensics" course. It is completely FREE and it should help you get started. #infosec #cybersecurity CC: @cyber5w.bsky.social academy.cyber5w.com/courses/C5W-...academy.cyber5w.comC5W-100 INTRODUCTION TO DIGITAL FORENSICS 012
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 05/04/2025The course is Pay-What-You-Can, and YES, you can access it completely FREE if you’d like! Check it out here: labs.cyber5w.com/courses/5dd8... Please share with anyone who might find it useful! #DFIR #DigitalForensics #010Editor #CyberSecurity #MalwareAnalysislabs.cyber5w.comWorking with 010 EditorWorking with 010 Editor: A Practical Guide to Binary Analysis 010
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 05/04/2025Hey #DFIR community! I’m excited to share that I’ve turned my 010 Editor video series into a full course. It includes 40+ videos and hands-on labs, so you can practice what you learn. Please share with anyone who might find it useful! 151
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 07/03/2025Scheduled Tasks and GhostTask Investigations | #ShadowMe Webinar #DFIR #Cybersecurity www.youtube.com/watch?v=Xhez...youtube.comScheduled Tasks and GhostTask Investigations | ShadowMe WebinarYouTube video by Ali Hadi 020
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 01/03/2025Want to play them? Check them out here: justhacking.com OR labs.cyber5w.com #DFIR #Malware #DataRecovery #Infosec #Cybersecurity 010
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 01/03/2025ShadowMe #4 (HAL) - UNALLOCATED Space Investigation #DFIR #DataRecovery #Unallocated youtube.com/watch?v=nfeM... 110
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 01/03/2025Data Recovery Basics (ShadowMe #3) #DFIR #DataRecovery youtube.com/watch?v=fFwh... 100
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 01/03/2025ShadowMe #2 - Dynamic Malware Analysis #Malware #DFIR youtube.com/watch?v=6Kzw... 100
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 01/03/2025What to expect in the #ShadowMe series? #DFIR #Cybersecurity #Malware #Infosec ShadowMe #1 - Intro to Static Malware Analysis youtube.com/watch?v=8qq0... 161
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 21/02/2025Don't miss the livestream tomorrow with @johnhammond.bsky.social talking #DFIR ... 041
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 11/02/2025📢 Missed our IoT Forensics webinar? Watch it now! 🎥 Expert @cyberyom.bsky.social shares key techniques for extracting & analyzing data from IoT devices. Don't miss out! 🚀 Watch here: academy.cyber5w.com/courses/webi... #DFIR #Cybersecurity #Infosec #IoT #Investigationsacademy.cyber5w.comWebinar #6: IoT ForensicsIn this webinar, IoT forensics expert Tom Claflin explored the role of IoT devices in modern investigations, demonstrating data extraction techniques, device disassembly, and key forensic tools. He al... 020
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 08/02/2025The course is being used by LE agencies, university professors, and many other professionals. If you have any feedback? You are very welcome to share with us. Read more about the decision and URL to the course below. #DFIR #Cybersecurity #infosec cyber5w.com/into-dfir.htmlcyber5w.comCyber5W | SponsorsDigital Forensics Courses and Training 011
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 08/02/2025Hey #DFIR community. Last month, we decided to open our @cyber5w.bsky.social C5W-100 Intro to Digital Forensics course & make it FREE; yes completely FREE! Since then more than 1K of new learners joined & we hope more will too. Please share with anyone who wants to learn. #Cybersecurity 1104
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 05/02/2025Happening now by @cyberyom.bsky.social #DFIR #IoT #Cybersecurity 000
Reposted by Ali Hadi | B!n@ryhasherezade.bsky.social @hasherezade.bsky.social · 26/01/2025In case if you wonder what broke #ProcessHollowing on Windows 11 24H2, I have something for you: hshrzd.wordpress.com/2025/01/27/p...hshrzd.wordpress.comProcess Hollowing on Windows 11 24H2Process Hollowing (a.k.a. RunPE) is probably the oldest, and the most popular process impersonation technique (it allows to run a malicious executable under the cover of a benign process). It is us… 05838
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 01/02/2025Some people tend to forget that kindness and manners are free. #life 060