Sign in

Mari DeGrazia

@maridegrazia.bsky.social
216 followers 29 following 22 posts

Digital Forensics and Incident Response SANS Instructor CyberSecurity VR E-Sports Maker

PostsRepliesMedia
Mari DeGrazia @maridegrazia.bsky.social · 22/08/2025
Overheard in the grocery store last night: "Why is beefstew not a good password?" Me, in my head: "That's terrible. No random numbers, letters, symbols.. actually random phrases..." Them: "It's not stroganoff"
030
Mari DeGrazia @maridegrazia.bsky.social · 21/08/2025
Check out this cool new open-source Dark Web Monitoring AI Agent platform by AI Anytime - it looks like it will work with a local LLM too. I know what my next weekend project is going to be :) #AI #LocalLLMs #DFIR www.youtube.com/watch?v=9e24...
youtube.com
AI Agents for Dark Web Monitoring | AI for Security Agencies
YouTube video by AI Anytime
021
Mari DeGrazia @maridegrazia.bsky.social · 18/08/2025
I'm a big believer in local LLMs for DFIR—privacy & security matter. In my keynote, "How to DFIR AI-ze Your Workflow," I demo how to use local LLMs with FOSS tools + share common pitfalls. 🎥 youtu.be/eG2wHGIPCaQ?... #DFIR #FOSS @sansinstitute.bsky.social
youtu.be
Keynote | DFIR AI-ze Your Workflow
YouTube video by SANS Digital Forensics and Incident Response
001
Mari DeGrazia @maridegrazia.bsky.social · 28/07/2025
Check out this excellent blog post by Ryan Chapman from last month's Stay Ahead of Ransomware live stream. I was bummed I missed this one, but Ryan's recap is great. #DFIR www.sans.org/blog/shaking...
021
Mari DeGrazia @maridegrazia.bsky.social · 07/07/2025
The SANS #DFIR Summit has always been one of my favorite conferences to attend. This year, I'm excited and honored to be giving the keynote! Attend in person or attend online for free! www.sans.org/cyber-securi...
sans.org
Digital Forensics & Incident Response Summit & Training 2025 | SANS Institute
Obtain hands-on, practical skills from the world's best instructors by taking a SANS course at DFIR Summit & Training 2025.
010
Mari DeGrazia @maridegrazia.bsky.social · 07/07/2025
The SANS Institute #DFIR Summit has always been one of my favorite conferences to attend. This year, I'm excited and honored to be giving the keynote! Attend in person or attend online for free - www.sans.org/cyber-securi...
sans.org
Digital Forensics & Incident Response Summit & Training 2025 | SANS Institute
Obtain hands-on, practical skills from the world's best instructors by taking a SANS course at DFIR Summit & Training 2025.
011
Mari DeGrazia @maridegrazia.bsky.social · 29/05/2025
It's almost here!!! Join Ryan Chapman and me at the SANS Ransomware Summit tomorrow. I will also be hosting an AI workshop over lunch. Learn how to install and use a local LLM. Register for the free conference and workshop here: www.sans.org/cyber-securi...
sans.org
Ransomware Summit | SANS Institute
SANS Ransomware Summit provides the very best forum for ransomware content and applicable lessons to safeguard ourselves and our organizations from harmful ransomware tactics.
000
Mari DeGrazia @maridegrazia.bsky.social · 19/05/2025
Thinking about taking the SANS 528 Ransomware course? I love teaching it—not only do we focus on ransomware, but also host-based forensics and analysis at scale. It's great for a wide range of investigations! Use code FOR528-SUMMIT for 30% off www.sans.org/cyber-securi...
sans.org
Ransomware Summit | SANS Institute
SANS Ransomware Summit provides the very best forum for ransomware content and applicable lessons to safeguard ourselves and our organizations from harmful ransomware tactics.
000
Reposted by Mari DeGrazia
Curtis @cybershtuff.bsky.social · 02/04/2025
🚨 New blog: BlackBasta’s leaks show how ransomware crews still exploit hybrid environments while Scattered Spider leans fully into cloud. Two actors, two strategies. What it means for IR, cloud defense, and ransomware readiness. 👉 invictus-ir.com/news/cloud-h... #DFIR #CloudSecurity #CTI
invictus-ir.com
Cloud Heavy, Hybrid Ready: Lessons from BlackBasta and Scattered Spider
001
Mari DeGrazia @maridegrazia.bsky.social · 01/04/2025
Join me, Ryan Chapman and guest @ransomwaresommelier.com today at 10AM PT/ 1PM ET as we talk about the state of Ransomware payments. www.linkedin.com/events/73031...
linkedin.com
The State of Ransomware Payments | LinkedIn
Episode One: The State of Ransomware Payments What's going on with ransomware payments? Have they dropped off? Have they gone up? What are we in the global IT community seeing in terms of ransomware ...
010
Reposted by Mari DeGrazia
djannot.bsky.social @djannot.bsky.social · 21/03/2025
Anthropic explores the advancements and implications of frontier AI.''s dual-use capabilities in cybersecurity and biology. Learn more about their strategies to navigate emerging risks: www.anthropic.com/news/strategic-wa…
001
Mari DeGrazia @maridegrazia.bsky.social · 12/02/2025
Like usual, the airport charging station is not working. I found a working plug in a pillar and all these strangers are plugged into my charging hub instead 😂 #JustTravelThings
000
Reposted by Mari DeGrazia
Women in Security and Privacy (WISP) @wisporg.bsky.social · 03/02/2025
Should you pursue the leadership track or thrive as an individual contributor in cybersecurity? Join us for a panel discussion on February 13 with top security leaders as they share insights on making this career-defining choice. Register now: us06web.zoom.us/meeting/regi...
011
Mari DeGrazia @maridegrazia.bsky.social · 03/02/2025
This is really cool and runs 100% locally - a silent speech recognition tool that reads your lips in real time and types whatever you mouth. The power of local LLMs is amazing. Open source too! - github.com/amanvirparha... #AI.
000
Mari DeGrazia @maridegrazia.bsky.social · 01/02/2025
I asked Deepseek-r1 14B to tell me a good digital forensics joke. Watching the thought process is so cute and entertaining... #DFIR #AI
010
Mari DeGrazia @maridegrazia.bsky.social · 25/01/2025
I'm honored to be hosting the SANS Institute Ransomware Summit in May with Ryan Chapman. 5 days left to submit a talk - we want to hear from you! www.sans.org/mlp/ransomwa...
010
Mari DeGrazia @maridegrazia.bsky.social · 24/01/2025
WinSCP and Rclone are used by this TA (and others) to exfiltrate data... check out my presentation on WinSCP artifacts to help locate relevant evidence : www.youtube.com/watch?v=sCqy...
youtube.com
WinSCP: Yeah you know me! | SANS@MIC Talk
YouTube video by SANS Institute
000
Mari DeGrazia @maridegrazia.bsky.social · 24/01/2025
This is one of my favorite #DFIR #INFOSEC conferences to attend. They have workshops for kids that I want to attend! Kids and students are free, and just $25 to attend. Well worth the price.
000
Mari DeGrazia @maridegrazia.bsky.social · 24/01/2025
One of my favorite tools for BEC cases just had a nice update! If you are working BEC cases, make sure and check it out www.invictus-ir.com/news/the-mic...
invictus-ir.com
Release: Microsoft Extractor Suite v3
010
Reposted by Mari DeGrazia
Phill Moore @phillmoore.bsky.social · 19/01/2025
Week 03 - 2025 #DFIR thisweekin4n6.com/2025/01/19/w...
thisweekin4n6.com
Week 03 – 2025
ThinkDFIRSRUMday Funday! Akash PatelHandling Incident Response: A Guide with Velociraptor and KAPE BelkasoftEmail Forensics with Belkasoft X Christopher Eng at Ogmini Homelab Part 1 – The Cur…
054
Reposted by Mari DeGrazia
mthcht @mthcht.bsky.social · 04/01/2025
I made a windows #DFIR artifacts collection MindMap, it's tough to fit everything into a readable overview (might change later)
12312
Mari DeGrazia @maridegrazia.bsky.social · 29/12/2024
Time for a decaf latte and a wrap up from last week's forensic goodies!
020
Reposted by Mari DeGrazia
Markus @mascho.bsky.social · 28/12/2024
For those looking to practice a realistic #DFIR scenario, here is a free case for you to investigate. Provided artifacts: - Disk Triage Collection - Memory Image + pagefile.sys: - PCAP File Link: bluecapesecurity.com/courses/elev...
bluecapesecurity.com
Elevate Your DFIR Skills: Deeper Insights and Practical Applications - Blue Cape Security
194
Mari DeGrazia @maridegrazia.bsky.social · 24/12/2024
Found my first #cruisingducks during my Christmas 🎄 cruise this year. Should I rehide it, or keep it???
000
Mari DeGrazia @maridegrazia.bsky.social · 14/12/2024
This is so important. Even if it's just a comment on a blog, something new you've seen with an update, find a way to share it with the community.
010
Mari DeGrazia @maridegrazia.bsky.social · 11/12/2024
Want to learn more about conducting forensic investigations on Windows? I will be teaching SANS FOR500: Windows Forensic Analysis in San Francisco end of next month! Day 2 is my fav where we dive into the registry! www.sans.org/cyber-securi...
sans.org
SANS San Francisco Winter 2025 | Cyber Security Training
SANS San Francisco Winter 2025 (Jan 27-Feb 1) offers hands-on cyber security training taught by real-world practitioners. Attend Live Online or in San Francisco, CA.
110
Reposted by Mari DeGrazia
Patrick C Miller @patrickcmiller.bsky.social · 11/12/2024
Black Basta Ransomware Uses MS Teams, Email Bombing to Spread Malware
hackread.com
Black Basta Gang Uses MS Teams, Email Bombing to Spread Malware
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
0114
Reposted by Mari DeGrazia
Arsenal Recon @arsenalrecon.bsky.social · 06/12/2024
Releasing a new #DFIR tool today! Swap Recon performs brute-force decompression of Windows 10 & 11 swap. Swap Recon was built when we couldn't find existing tools or techniques to decompress modern Windows swap properly in one of our highest-stakes cases. arsenalrecon.com
195
Reposted by Mari DeGrazia
Maximilian Larum @0xm4xdf1r.bsky.social · 03/12/2024
New cyber humble bundle out! #DFIR #cyber #infosec #security www.humblebundle.com/books/hackin...
humblebundle.com
Humble Tech Book Bundle: Hacking 2024 by No Starch
Level up your hacking and skills with this tech bundle from No Starch. Learn to protect yourself and others! Pay what you want & support charity!
022
Reposted by Mari DeGrazia
Alexis Brignoni🪫 @abrignoni.com · 03/12/2024
It sure was. #DigitalForensics #MobileForensics #DFIR
1192
Mari DeGrazia @maridegrazia.bsky.social · 01/12/2024
Sunday morning reading - catch up on the latest #DFIR with @phillmoore.bsky.social. There is a great article on RDP bitmap cache.. speaking of which.. don't forget to check for RDP Thumbnails if the RDP App was used. Check out my blog post here on it: www.zerofox.com/blog/remote-...
zerofox.com
Remote Desktop Application vs MSTSC Forensics: The RDP Artifacts You Might Be Missing
Find out the various RDP artifacts that may not be in traditional locations checked by incident responders.
050
Reposted by Mari DeGrazia
Chris DiSalle @chrisdfir.updatex64.zip · 01/12/2024
While there are some awesome methods to detect web shells with Yara, sometimes structured data can help solve the case. In this oversimplified example, I go over how you can use two artifacts with Velociraptor to help you find evil on your Linux server. #dfir #blueteam #cybersecurity
linkedin.com
Hunting Linux Web Shells with Velociraptor
Linux forensics can be tricky, especially when investigating subtle threats like web shells. Unlike Windows, which provides tools like the Master File Table ($MFT) for metadata-rich investigations, Li...
0126
Reposted by Mari DeGrazia
Jessica Hyde @b1n2h3x.bsky.social · 22/11/2024
#DFIR 💭 of the Day: #CTFs are a fantastic way to learn! They are a great way to learn providing access to forensic images and questions that can increase and challenge your skills. Registration is now open for the Magnet Virtual Summit 2025 CTF powered by Hexordia. youtu.be/YNEnpwoADKs
youtu.be
Capture The Flag 2025
YouTube video by Magnet Forensics
0124
Reposted by Mari DeGrazia
Ali Hadi | B!n@ry @binaryz0ne.bsky.social · 24/11/2024
If you're interested in Linux DFIR? Then check all our talks/workshops below. #Linux #DFIR #Cybersecurity CC: @maryst33d.bsky.social linuxdfir.ashemery.com
03814
Mari DeGrazia @maridegrazia.bsky.social · 26/11/2024
I love this weekly blog. Helps keep me up to date, especially on weeks where I am busy traveling.
030
Reposted by Mari DeGrazia
Alexis Brignoni🪫 @abrignoni.com · 24/11/2024
Indeed.
Picture of a WV Beetle with a license plate that says Feature. The caption of the image says: possibly the nerdiest joke ever.
09013
Reposted by Mari DeGrazia
Taggart @taggart-tech.com · 25/11/2024
1. Velociraptor rips 2. Whitney and Eric are the best at what they do. Don't miss this opportunity if you have any interest in the material.
2166