Volatility Core developer, Dir. of Research Volexity, LSU Cyber
Andrew Case
Loading...
Memory-only malware leaves no trace on the file system and is commonly used by threat actors ranging from criminal organizations to ransomware operators to APT groups. In our Volatility 3 training, students gain deep hands on experience analyzing such threats:
memoryanalysis.net/courses-malw...
Memory-only malware leaves no trace on the file system and is commonly used by threat actors ranging from criminal organizations to ransomware operators to APT groups. In our Volatility 3 training, students gain deep hands on experience analyzing such threats:
memoryanalysis.net/courses-malw...
I am excited to announce that I will be speaking at BSides Nashville on May 15th. Be sure to attend to see all the latest Volatility 3 (@volatilityfoundation.org) plugins against the most sophisticated and devastating malware from the wild!
bsidesnash.org
SAVE THE DATE!!
BSides Memphis will be hosted at Epicenter Memphis on October 3rd, 2026!
More info to come on tickets, CFP, Sponsors, ect.
please share so the local community knows this is happening!
Memory forensics is a required technique to detect and respond to modern malware. Come see Volcano in action at FIRST next week to learn how memory forensics can be applied at true enterprise scale.
Our new blog post details our investigation into how a compromised MSP led to at least one of its customers being compromised, including deployment of the BRICKSTORM malware on multiple edge devices.
We are excited to announce the First Place winner of the 2025 #Volatility #PluginContest is:
Daniel Baier for XRFM Inspector
See the full Contest Results in our blog post: volatilityfoundation.org/the-2025-vol...
Congrats to all winners & thank you to all participants!
#DFIR #memoryforensics
Countdown is real ⌛️ Next week‼️
#ThreatResearch community gathers in Málaga 🇪🇸
Time to remind our PIVOTcon song: soundcloud.com/argonix/pivo...
But watch out — it's a banger!
#CTI #ThreatIntel #PIVOTcon26
@volexity.com tracks a variety of threat actors abusing Device Code & OAuth authentication workflows to phish credentials, which continue to see success due to creative social engineering. Our latest blog post details Russian threat actor UTA0355’s campaigns impersonating European security events.
@volexity.com has continued to see nation-state threat actors use AI + LLMs to assist in cyber attacks. Our recent research on a Chinese APT threat actor (UTA0388) using AI in its operation was something @stevenadair.bsky.social recently discussed with the @wsj.com.