home.social

#memoryforensics — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #memoryforensics, aggregated by home.social.

  1. RE: infosec.exchange/@jackrhysider

    The latest #DarknetDiaries (Ep. 174: Pacific Rim) offers a look at state-sponsored groups targeting perimeter infrastructure & edge devices. Thanks @jackrhysider for mentioning our work!

    @volexity’s detection and response efforts combined network visibility, host-based analysis, #threatintelligence & #memoryforensics, enabling us to discover these complex #0days being exploited in the wild.

    Read our blog post for the original research mentioned: volexity.com/blog/2022/06/15/d

  2. RE: infosec.exchange/@jackrhysider

    The latest #DarknetDiaries (Ep. 174: Pacific Rim) offers a look at state-sponsored groups targeting perimeter infrastructure & edge devices. Thanks @jackrhysider for mentioning our work!

    @volexity’s detection and response efforts combined network visibility, host-based analysis, #threatintelligence & #memoryforensics, enabling us to discover these complex #0days being exploited in the wild.

    Read our blog post for the original research mentioned: volexity.com/blog/2022/06/15/d

  3. RE: infosec.exchange/@jackrhysider

    The latest #DarknetDiaries (Ep. 174: Pacific Rim) offers a look at state-sponsored groups targeting perimeter infrastructure & edge devices. Thanks @jackrhysider for mentioning our work!

    @volexity’s detection and response efforts combined network visibility, host-based analysis, #threatintelligence & #memoryforensics, enabling us to discover these complex #0days being exploited in the wild.

    Read our blog post for the original research mentioned: volexity.com/blog/2022/06/15/d

  4. RE: infosec.exchange/@jackrhysider

    The latest #DarknetDiaries (Ep. 174: Pacific Rim) offers a look at state-sponsored groups targeting perimeter infrastructure & edge devices. Thanks @jackrhysider for mentioning our work!

    @volexity’s detection and response efforts combined network visibility, host-based analysis, #threatintelligence & #memoryforensics, enabling us to discover these complex #0days being exploited in the wild.

    Read our blog post for the original research mentioned: volexity.com/blog/2022/06/15/d

  5. @volexity Volcano Server & Volcano One v26.04.27 adds memory analysis for arm64 Windows, memory-only .NET assemblies, SRUM database, Linux systemd units, history & timers from RAM.

    This release also adds detection of AppleScript usage, cleared Windows event logs, AV scanning of files & deployments across AWS accounts.

    Contact us for more information: volexity.com/company/contact/

    #memoryforensics #memoryanalysis #dfir

  6. 🎖️ El Curso Fundamentos de Forense Digital está permanente disponible en el aula virtual para acceso inmediato. 📲 WhatsApp: https://wa.me/51949304030 🌐 https://www.reydes.com/e/Curso_Fundamentos_de_Forense_Digital #memoryforensics #networkforensics #forensictools #digitalevidence #cybercrime #dfir #digitalforensics
  7. 🎖️ El Curso Fundamentos de Forense Digital está permanente disponible en el aula virtual para acceso inmediato. 📲 WhatsApp: https://wa.me/51949304030 🌐 https://www.reydes.com/e/Curso_Fundamentos_de_Forense_Digital #memoryforensics #networkforensics #forensictools #digitalevidence #cybercrime #dfir #digitalforensics
  8. 🎖️ El Curso Fundamentos de Forense Digital está permanente disponible en el aula virtual para acceso inmediato. 📲 WhatsApp: https://wa.me/51949304030 🌐 https://www.reydes.com/e/Curso_Fundamentos_de_Forense_Digital #memoryforensics #networkforensics #forensictools #digitalevidence #cybercrime #dfir #digitalforensics
  9. 🎖️ El Curso Fundamentos de Forense Digital está permanente disponible en el aula virtual para acceso inmediato. 📲 WhatsApp: https://wa.me/51949304030 🌐 https://www.reydes.com/e/Curso_Fundamentos_de_Forense_Digital #memoryforensics #networkforensics #forensictools #digitalevidence #cybercrime #dfir #digitalforensics
  10. 🎖️ El Curso de Informática Forense está permanente disponible en el aula virtual para acceso inmediato. 📲 WhatsApp: https://wa.me/51949304030 🌐 https://www.reydes.com/e/Curso_de_Informatica_Forense #digitalforensics #dfir #computerforensics #memoryforensics #diskforensics #datarecovery #cybercrime
  11. Memory Analysis for #Linux has always been a bit hit-or-miss. Trail of Bits has released a tool called #mquire that doesn't require debug symbols for the originating Kernel.

    It also uses SQL-based queries to perform analysis, similar to #OSquery.

    blog.trailofbits.com/2026/02/2

    #MemoryForensics #IncidentResponse #DFIR #DigitalForensics

  12. Memory Analysis for #Linux has always been a bit hit-or-miss. Trail of Bits has released a tool called #mquire that doesn't require debug symbols for the originating Kernel.

    It also uses SQL-based queries to perform analysis, similar to #OSquery.

    blog.trailofbits.com/2026/02/2

    #MemoryForensics #IncidentResponse #DFIR #DigitalForensics

  13. Memory Analysis for #Linux has always been a bit hit-or-miss. Trail of Bits has released a tool called #mquire that doesn't require debug symbols for the originating Kernel.

    It also uses SQL-based queries to perform analysis, similar to #OSquery.

    blog.trailofbits.com/2026/02/2

    #MemoryForensics #IncidentResponse #DFIR #DigitalForensics

  14. Memory Analysis for #Linux has always been a bit hit-or-miss. Trail of Bits has released a tool called #mquire that doesn't require debug symbols for the originating Kernel.

    It also uses SQL-based queries to perform analysis, similar to #OSquery.

    blog.trailofbits.com/2026/02/2

    #MemoryForensics #IncidentResponse #DFIR #DigitalForensics

  15. Memory Analysis for #Linux has always been a bit hit-or-miss. Trail of Bits has released a tool called #mquire that doesn't require debug symbols for the originating Kernel.

    It also uses SQL-based queries to perform analysis, similar to #OSquery.

    blog.trailofbits.com/2026/02/2

    #MemoryForensics #IncidentResponse #DFIR #DigitalForensics

  16. 🚀 Ah yes, the modern-day alchemist's dream: extract memories faster than your grandma can forget them! 🧠🔍 GitHub's latest concoction promises to make memory forensics as breezy as a summer’s fart—assuming you can navigate the UI from 1995. ⚙️💻
    github.com/volatilityfoundatio #memoryforensics #GitHub #techinnovation #UXdesign #digitalalchemy #HackerNews #ngated

  17. Recently, we submitting our Velociraptor plugin `Windows.Memory.Mem2Disk` to the official repository. Our plugin can detect common C2 frameworks live in RAM.

    We now published part 2 of the memory forensics blog post, explaining the technique in more detail:

    docs.velociraptor.app/blog/202

    Merry Christmas! 🎄

    #C2 #velociraptor #detection #memoryforensics #DFIR #cybersecurity #infosec #pwr2

  18. Recently, we submitting our Velociraptor plugin `Windows.Memory.Mem2Disk` to the official repository. Our plugin can detect common C2 frameworks live in RAM.

    We now published part 2 of the memory forensics blog post, explaining the technique in more detail:

    docs.velociraptor.app/blog/202

    Merry Christmas! 🎄

    #C2 #velociraptor #detection #memoryforensics #DFIR #cybersecurity #infosec #pwr2

  19. Update:

    Our velociraptor plugin `Windows.Memory.Mem2Disk` can detect RAM injections and fileless malware.

    We tested it against (among others) the C2 frameworks Sliver, Havoc and Mythic. All three were detected.

    It was recently featured in a blog post by Mike Cohen:

    docs.velociraptor.app/blog/202

    Stay tuned for memory analysis with velo part 2!

    #C2 #detection #memoryforensics #velociraptor #DFIR #cybersecurity #infosec #pwr2

  20. Update:

    Our velociraptor plugin `Windows.Memory.Mem2Disk` can detect RAM injections and fileless malware.

    We tested it against (among others) the C2 frameworks Sliver, Havoc and Mythic. All three were detected.

    It was recently featured in a blog post by Mike Cohen:

    docs.velociraptor.app/blog/202

    Stay tuned for memory analysis with velo part 2!

    #C2 #detection #memoryforensics #velociraptor #DFIR #cybersecurity #infosec #pwr2

  21. Update:

    Our velociraptor plugin `Windows.Memory.Mem2Disk` can detect RAM injections and fileless malware.

    We tested it against (among others) the C2 frameworks Sliver, Havoc and Mythic. All three were detected.

    It was recently featured in a blog post by Mike Cohen:

    docs.velociraptor.app/blog/202

    Stay tuned for memory analysis with velo part 2!

    #C2 #detection #memoryforensics #velociraptor #DFIR #cybersecurity #infosec #pwr2

  22. Update:

    Our velociraptor plugin `Windows.Memory.Mem2Disk` can detect RAM injections and fileless malware.

    We tested it against (among others) the C2 frameworks Sliver, Havoc and Mythic. All three were detected.

    It was recently featured in a blog post by Mike Cohen:

    docs.velociraptor.app/blog/202

    Stay tuned for memory analysis with velo part 2!

    #C2 #detection #memoryforensics #velociraptor #DFIR #cybersecurity #infosec #pwr2

  23. Update:

    Our velociraptor plugin `Windows.Memory.Mem2Disk` can detect RAM injections and fileless malware.

    We tested it against (among others) the C2 frameworks Sliver, Havoc and Mythic. All three were detected.

    It was recently featured in a blog post by Mike Cohen:

    docs.velociraptor.app/blog/202

    Stay tuned for memory analysis with velo part 2!

    #C2 #detection #memoryforensics #velociraptor #DFIR #cybersecurity #infosec #pwr2

  24. Today we have another #DEFCONTraining Bahrain Spotlight - “A Complete Practical Approach to Malware Analysis & Threat Hunting with Memory Forensics, Endpoint Telemetry, & AI-Driven Hunting” with Monnappa K A and Sajan Shetty on November 3-4.

    This 2-day intensive, hands-on training teaches the concepts, tools, and techniques required to analyze, investigate, and hunt malware by combining four powerful approaches: malware analysis, reverse engineering, memory forensics, and endpoint telemetry-based threat hunting. The course begins with the foundations of malware analysis, Windows internals, and memory forensics, before moving into advanced concepts of malware investigation and hunting adversary techniques.

    What makes this training unique and future-ready is the introduction to the concept of AI-powered autonomous hunting with the Garuda Threat Hunting Framework.

    Take a deeper look and register for this course today: training.defcon.org/collection

    Explore the full list of offerings in Bahrain at training.defcon.org/collection

    #defcon #cyber #training #defconbahrain #AICS2025 #Bahrain #UAE #SaudiArabia #cybertraining #infosec #cybersecurity #cyberdefense #malwareanalysis #threathunting #memoryforensics #AI #endpointtelemetry

  25. Today we have another #DEFCONTraining Bahrain Spotlight - “A Complete Practical Approach to Malware Analysis & Threat Hunting with Memory Forensics, Endpoint Telemetry, & AI-Driven Hunting” with Monnappa K A and Sajan Shetty on November 3-4.

    This 2-day intensive, hands-on training teaches the concepts, tools, and techniques required to analyze, investigate, and hunt malware by combining four powerful approaches: malware analysis, reverse engineering, memory forensics, and endpoint telemetry-based threat hunting. The course begins with the foundations of malware analysis, Windows internals, and memory forensics, before moving into advanced concepts of malware investigation and hunting adversary techniques.

    What makes this training unique and future-ready is the introduction to the concept of AI-powered autonomous hunting with the Garuda Threat Hunting Framework.

    Take a deeper look and register for this course today: training.defcon.org/collection

    Explore the full list of offerings in Bahrain at training.defcon.org/collection

    #defcon #cyber #training #defconbahrain #AICS2025 #Bahrain #UAE #SaudiArabia #cybertraining #infosec #cybersecurity #cyberdefense #malwareanalysis #threathunting #memoryforensics #AI #endpointtelemetry

  26. Today we have another #DEFCONTraining Bahrain Spotlight - “A Complete Practical Approach to Malware Analysis & Threat Hunting with Memory Forensics, Endpoint Telemetry, & AI-Driven Hunting” with Monnappa K A and Sajan Shetty on November 3-4.

    This 2-day intensive, hands-on training teaches the concepts, tools, and techniques required to analyze, investigate, and hunt malware by combining four powerful approaches: malware analysis, reverse engineering, memory forensics, and endpoint telemetry-based threat hunting. The course begins with the foundations of malware analysis, Windows internals, and memory forensics, before moving into advanced concepts of malware investigation and hunting adversary techniques.

    What makes this training unique and future-ready is the introduction to the concept of AI-powered autonomous hunting with the Garuda Threat Hunting Framework.

    Take a deeper look and register for this course today: training.defcon.org/collection

    Explore the full list of offerings in Bahrain at training.defcon.org/collection

    #defcon #cyber #training #defconbahrain #AICS2025 #Bahrain #UAE #SaudiArabia #cybertraining #infosec #cybersecurity #cyberdefense #malwareanalysis #threathunting #memoryforensics #AI #endpointtelemetry

  27. Today we have another #DEFCONTraining Bahrain Spotlight - “A Complete Practical Approach to Malware Analysis & Threat Hunting with Memory Forensics, Endpoint Telemetry, & AI-Driven Hunting” with Monnappa K A and Sajan Shetty on November 3-4.

    This 2-day intensive, hands-on training teaches the concepts, tools, and techniques required to analyze, investigate, and hunt malware by combining four powerful approaches: malware analysis, reverse engineering, memory forensics, and endpoint telemetry-based threat hunting. The course begins with the foundations of malware analysis, Windows internals, and memory forensics, before moving into advanced concepts of malware investigation and hunting adversary techniques.

    What makes this training unique and future-ready is the introduction to the concept of AI-powered autonomous hunting with the Garuda Threat Hunting Framework.

    Take a deeper look and register for this course today: training.defcon.org/collection

    Explore the full list of offerings in Bahrain at training.defcon.org/collection

    #defcon #cyber #training #defconbahrain #AICS2025 #Bahrain #UAE #SaudiArabia #cybertraining #infosec #cybersecurity #cyberdefense #malwareanalysis #threathunting #memoryforensics #AI #endpointtelemetry

  28. Today we have another #DEFCONTraining Bahrain Spotlight - “A Complete Practical Approach to Malware Analysis & Threat Hunting with Memory Forensics, Endpoint Telemetry, & AI-Driven Hunting” with Monnappa K A and Sajan Shetty on November 3-4.

    This 2-day intensive, hands-on training teaches the concepts, tools, and techniques required to analyze, investigate, and hunt malware by combining four powerful approaches: malware analysis, reverse engineering, memory forensics, and endpoint telemetry-based threat hunting. The course begins with the foundations of malware analysis, Windows internals, and memory forensics, before moving into advanced concepts of malware investigation and hunting adversary techniques.

    What makes this training unique and future-ready is the introduction to the concept of AI-powered autonomous hunting with the Garuda Threat Hunting Framework.

    Take a deeper look and register for this course today: training.defcon.org/collection

    Explore the full list of offerings in Bahrain at training.defcon.org/collection

    #defcon #cyber #training #defconbahrain #AICS2025 #Bahrain #UAE #SaudiArabia #cybertraining #infosec #cybersecurity #cyberdefense #malwareanalysis #threathunting #memoryforensics #AI #endpointtelemetry

  29. @volexity researchers will be presenting at THREE conferences in Las Vegas this August! Here’s where you can hear about some of our latest research in #memoryforensics and automated malicious script detection and de-obfuscation:
     
    Monday, August 4:  Detecting, Deobfuscating, and Preventing Obfuscated Script Execution with Tree-sitter @ BSides Las Vegas (bsideslv.org/talks#LBQDEB)
     
    Wednesday, August 6: Volatility 3 @ Black Hat Arsenal (blackhat.com/us-25/arsenal/sch)
     
    Friday, August 8: Effectively Detecting Modern Malware with Volatility 3 Workshop @ DEF CON 33 (defcon.org/html/defcon-33/dc-3)
     
    Many members of the @volexity team will be also in Vegas, so if you’d like to meet up with our leadership, development, engineering, services, or threat intelligence teams, please reach out or complete our contact form: volexity.com/contact/meet-up-i

  30. Doing some interesting #memoryforensics on @signalapp tonight. Still would trust them with my life, and the lives of my friends, but interesting stuff in the memory.

    For instance, people I haven't talked to in 3 years showed up in the memory dump with a field called "SharedGroupNames" that listed every group that both I and that individual were associated with.

    Also, the "LastMessage" field was often populated with a plaintext version of the last thing the individual had messaged me.

  31. @volexity Volcano Server & Volcano One v25.02.21 adds 300 new YARA rules; consistent Bash/ZSH history & sessions from Linux/macOS memory and files; and parses Linux systemd journals, macOS unified logs, and Windows USNs (search + timeline for all).

    This release also extracts cmd history from Windows 24H2 RAM; and adds admin options for SAML and S3 bucket watching. 



    For more information about Volcano Server & Volcano One, contact us: volexity.com/company/contact/

    #dfir #memoryforensics #memoryanalysis

  32. It’s great to see NCSC drawing attention to the ongoing issues with network devices & appliances. ncsc.gov.uk/news/cyber-agencie



    Hopefully, vendors will heed the volatile data collection guidance: “Volatile data logging should support collection of… memory both at a kernel and individual process level.”

    As reported in several of our recent blog posts, #memoryforensics of edge devices plays a critical role in helping to understand vulnerabilities and perform post-exploitation investigations: volexity.com/blog/tag/edge-dev



    No ‘Ware To Hide!

    #dfir

  33. Interested in searching for unknown malicious software? Our team in Microsoft Research is hiring. The position can be fully remote.

    jobs.careers.microsoft.com/glo

    #FediHire #MemoryForensics #ReverseEngineering

  34. On Thursday, Feb 6, @attrc will be at @WWHackinFest to present "Effectively Detecting Modern Code Injection Techniques with Volatility 3". See the full conference agenda here: wildwesthackinfest.com/wild-we. 

#dfir #memoryforensics #Volatility3 @volatility

  35. On Thursday, Feb 6, @attrc will be at @WWHackinFest to present "Effectively Detecting Modern Code Injection Techniques with Volatility 3". See the full conference agenda here: wildwesthackinfest.com/wild-we. 

#dfir #memoryforensics #Volatility3 @volatility

  36. On Thursday, Feb 6, @attrc will be at @WWHackinFest to present "Effectively Detecting Modern Code Injection Techniques with Volatility 3". See the full conference agenda here: wildwesthackinfest.com/wild-we. 

#dfir #memoryforensics #Volatility3 @volatility

  37. On Thursday, Feb 6, @attrc will be at @WWHackinFest to present "Effectively Detecting Modern Code Injection Techniques with Volatility 3". See the full conference agenda here: wildwesthackinfest.com/wild-we. 

#dfir #memoryforensics #Volatility3 @volatility

  38. Detected a C2 framework in RAM today with velociraptor. Dumped the process memory with velo, created a zignature with radare2.

    Never thought I'd ever reach that level...

    Blogpost and velo artifact incoming :blobsmile:

    #velociraptor #radare2 #detection #c2 #MemoryForensics #DFIR

  39. Memory mounting with MemProcFS? This changes everything...

    Our Luke Davis dives into MemProcFS in our latest blog, exploring how this tool has transformed memory forensics. MemProcFS allows memory dumps to be mounted and browsed like file systems, making complex memory structures easy to analyse. 💻

    Using MemProcFS, investigators can:

    Quickly analyse suspicious processes, like tracking Excel launching malicious code

    Monitor network connections tied to ransomware groups and other threats

    Explore advanced features like memory timelines and registry browsing to trace system activity and investigate security breaches 🔍

    This post is a must-read for anyone delving into digital forensics or curious about memory mounting: 🔗pentestpartners.com/security-b

    #MemoryForensics #MemProcFS #DigitalForensics #Cybersecurity #MalwareAnalysis #Infosec

  40. In our latest blog, Luke Davis, Head of DFIR, explores the role of memory forensics in cyber investigations.🕵️‍♂️

    Discover how analysing a system's RAM can uncover critical volatile data, such as running processes, encryption keys, network connections, and real-time user activity—evidence often missed by traditional disk forensics.
     
    Learn how this approach helps detect malware, recover hidden data, and identify unauthorised access for a deeper understanding of cyber incidents.
     
    👉 Read the full blog here: pentestpartners.com/security-b
     
    🔜 Stay tuned for part two, where Luke dives into the innovative MemProcFS tool and how it revolutionises memory analysis.
     
    #DFIR #MemoryForensics #DigitalForensics #CyberSecurity #IncidentResponse #ForensicTools #CyberInvestigations #InfoSec

  41. In our latest blog, Luke Davis, Head of DFIR, explores the role of memory forensics in cyber investigations.🕵️‍♂️

    Discover how analysing a system's RAM can uncover critical volatile data, such as running processes, encryption keys, network connections, and real-time user activity—evidence often missed by traditional disk forensics.
     
    Learn how this approach helps detect malware, recover hidden data, and identify unauthorised access for a deeper understanding of cyber incidents.
     
    👉 Read the full blog here: pentestpartners.com/security-b
     
    🔜 Stay tuned for part two, where Luke dives into the innovative MemProcFS tool and how it revolutionises memory analysis.
     
    #DFIR #MemoryForensics #DigitalForensics #CyberSecurity #IncidentResponse #ForensicTools #CyberInvestigations #InfoSec

  42. In our latest blog, Luke Davis, Head of DFIR, explores the role of memory forensics in cyber investigations.🕵️‍♂️

    Discover how analysing a system's RAM can uncover critical volatile data, such as running processes, encryption keys, network connections, and real-time user activity—evidence often missed by traditional disk forensics.
     
    Learn how this approach helps detect malware, recover hidden data, and identify unauthorised access for a deeper understanding of cyber incidents.
     
    👉 Read the full blog here: pentestpartners.com/security-b
     
    🔜 Stay tuned for part two, where Luke dives into the innovative MemProcFS tool and how it revolutionises memory analysis.
     
    #DFIR #MemoryForensics #DigitalForensics #CyberSecurity #IncidentResponse #ForensicTools #CyberInvestigations #InfoSec

  43. In our latest blog, Luke Davis, Head of DFIR, explores the role of memory forensics in cyber investigations.🕵️‍♂️

    Discover how analysing a system's RAM can uncover critical volatile data, such as running processes, encryption keys, network connections, and real-time user activity—evidence often missed by traditional disk forensics.
     
    Learn how this approach helps detect malware, recover hidden data, and identify unauthorised access for a deeper understanding of cyber incidents.
     
    👉 Read the full blog here: pentestpartners.com/security-b
     
    🔜 Stay tuned for part two, where Luke dives into the innovative MemProcFS tool and how it revolutionises memory analysis.
     
    #DFIR #MemoryForensics #DigitalForensics #CyberSecurity #IncidentResponse #ForensicTools #CyberInvestigations #InfoSec

  44. @volexity Volcano Server & Volcano One v24.09.12 includes many new features:
     
    • Adds 320 new YARA rules & IOCs for reverse shells on Linux
    • Supports non-English unicode
    • Extracts browser history from RAM
    • Adds collected files into timelines & searches
    • Parses IIS web logs, Linux syslogs, and Linux logon events
    • Extends integration with MITRE ATT&CK + Splunk HEC
    • Deploys collection tools to AWS EC2 and Azure VMs
    • ...and much more!
     
    For information about Volcano Server & Volcano One, contact us: volexity.com/company/contact/
     
    #dfir #memoryforensics #memoryanalysis