@Volatility Core developer, Dir. of Research @Volexity, @lsucyber, The Art Of Memory Forensics Co-Author

Joined March 2010
271 Photos and videos
Pinned Tweet
3 Oct 2025
With Volcano, security teams can automate the entire workflow of acquisition of memory and select files to deep analysis to automated alerts that directly point to signs of memory only malware and attacker activity throughout RAM and key artifacts sources from disk.
1 Oct 2025
.@Volexity Volcano Server & Volcano One v25.09.21 adds memory analysis support for ARM64 Linux, macOS 26 (Tahoe) & Windows 25H2, as well as 75 new YARA rules, 10 new IOCs, analysis of udev rules, and rolling upgrades for managed endpoints. [1/2]
5
11
9,477
Andrew Case retweeted
NEW POD advisory! securityconversations.com/ep… Three buddy problem Episode 101: We discuss Anthropic’s Mythos 5 and Claude Fable 5 release and the bombshell that the company was silently downgrading paid users’ results, sparking a heated debate over guardrails, gatekeeping, and whether elite AI reasoning is becoming a privilege for the few. Plus, AI-generated N-day exploits killing the patch window, a record-shattering Patch Tuesday, Meta’s latest court filing against spyware maker NSO Group, the return of cyber paleontology, and a detour into the new government UFO drops. With @ryanaraine and @juanandres_gs
1
6
10
1,402
Andrew Case retweeted
🚨 BREAKING: More than 400 Arch Linux User Repository packages have been compromised with infostealer malware and a rootkit. Attacker posed as a trusted maintainer and "adopted" orphaned packages. Arch maintainers are purging infected packages now. Audit your AUR installs.
175
805
4,592
1,176,361
Andrew Case retweeted
Memory forensics is a required technique to detect and respond to modern malware. Come see Volcano in action at FIRST next week to learn how memory forensics can be applied at true enterprise scale.
Heading to Denver for #FIRSTCON26 next week? Stop by the @Volexity booth to see a demo of Volcano! We’ll show you how memory analysis with Volcano uncovers advanced threat actors and helps rapidly resolve your investigations. Come find us at Booth 7 to talk threat hunting and triage workflows with our team, including @stevenadair & @attrc! @FIRSTdotOrg #DFIR #FIRSTCON
5
17
3,811
Andrew Case retweeted
Been spending a lot of time with Unified Logs and discovered XProtect Behavioral Bastion events being handled by XProtectBridgeService. These all correspond to syspolicyd policy violations. Captures hash and path, very useful! Brief fun summary, more to come on this :) 🧵
1
7
26
1,409
Andrew Case retweeted
Recon agenda have been published cfp.recon.cx/recon-2026/sche…. Email have been sent to all training attendees, general email for conference attendees should get sent in the next 48 hours. See you all next week in Montreal!
1
12
26
2,877
Andrew Case retweeted
Our new blog post details our investigation into how a compromised MSP led to at least one of its customers being compromised, including deployment of the BRICKSTORM malware on multiple edge devices.
.@Volexity has published details from an incident response engagement in September 2025 involving multiple #BRICKSTORM variants deployed by a threat actor that Volexity tracks as VerdantBamboo. This case involved the breach of the victim organization’s MSP and multiple malware implants found on firewalls, cloud storage sync devices & NAS appliances. VerdantBamboo used a #0day privilege escalation exploit in the process and was also observed using administrative access to the victim organization's firewall to enable a custom VPN. For more details on how the incident unfolded, the malware used by the threat actor, and the end goal of the intrusion, check out the full blog post: volexity.com/blog/2026/06/04… #dfir
1
8
23
6,708
Andrew Case retweeted
Check out our blog on an activity we worked related to VerdantBamboo -- aka the TA that is known for wreaking havoc on edge devices and deploying BRICKSTORM. We found BRICKSTORM for BS on a pfSense firewall, new malware families, use of a 0day privesc, and custom VPN networks!
.@Volexity has published details from an incident response engagement in September 2025 involving multiple #BRICKSTORM variants deployed by a threat actor that Volexity tracks as VerdantBamboo. This case involved the breach of the victim organization’s MSP and multiple malware implants found on firewalls, cloud storage sync devices & NAS appliances. VerdantBamboo used a #0day privilege escalation exploit in the process and was also observed using administrative access to the victim organization's firewall to enable a custom VPN. For more details on how the incident unfolded, the malware used by the threat actor, and the end goal of the intrusion, check out the full blog post: volexity.com/blog/2026/06/04… #dfir
1
18
42
9,252
Andrew Case retweeted
I was thinking earlier today that MSRC has a limited window of time to impress us before Vegas when it gets really uncomfortable for them. Automated emails to all speakers asking them about vulnerabilities in MS products ain’t it. As a frequent speaker, I can say that if I’m giving a talk where I am dropping a vulnerability in your product and you don’t already know about it before the abstract is online, it’s because I really didn’t feel like I’d have a good time interacting with you about it.
Good lord 🤮
5
27
257
20,028
Andrew Case retweeted
Good lord 🤮
28
61
424
324,919
Hey @yarden_shafir please stop suggesting how vendors could use their already existing technologies to take data out of memory samples 💀
This gets even dumber. Microsoft built a VBS enclave into msedge! It protects data even from kernel drivers! That would've been the perfect place to store passwords! And they are using it to store... a bit of static configuration data.
1
25
5,662
Andrew Case retweeted
Your on-the-go life really changes when you get a powerful desktop (Mac Studio) at home and @Tailscale back for long running tasks
new walk of shame: agent still working, but the cafe closed
4
4
16
5,104
Andrew Case retweeted
1
8
40
10,657
I watched this keynote live last week and it was incredible! I highly recommend @aaronportnoy if your conference is looking for a keynote that is truly relevant to today's threat landscape.
ok, so this talk from @aaronportnoy from @ekoparty is absolutely phenomenal... my neck hurts from nodding my tldr takeaway: defenders need to start listening *really carefully* to actual, economically rational attackers the cadence of the OODA loop that we've grown used to over the years is now *way* too tight cdn.prod.website-files.com/6…
2
8
3,248
MSRC woke up and decided to kill off all the good will it has built up over the last decade: microsoft.com/en-us/msrc/blo…
13
59
361
28,494
Andrew Case retweeted
This looks like a really good conference
will be speaking at the real world ai security conference at stanford, you can sign up here: seclab.stanford.edu/RealWorl…
1
10
43
11,599
Does anyone know the actual effect of what Riot did? Are the cards actually bricked? OS updated required? Reinstall? The existing replies all seem to be from bots and are entirely useless.
congrats to the owners of a brand new $6k paperweight
8
4
2,786
Andrew Case retweeted
The latest @DarknetDiaries (Ep. 174: Pacific Rim) offers a look at state-sponsored groups targeting perimeter infrastructure & edge devices. Thanks @JackRhysider for mentioning our work! @Volexity’s detection and response efforts combined network visibility, host-based analysis, #threatintelligence & #memoryforensics, enabling us to discover these complex #0days being exploited in the wild. Read our blog post for the original research mentioned: volexity.com/blog/2022/06/15…
Ep 174 "Pacific Rim" is now live! 🔊 Sophos got attacked by a nation state actor. How they handled it is controversial. Curious what you would have done. darknetdiaries.com/episode/1…
8
13
2,220
Andrew Case retweeted
I'm glad we can finally talk about this! :D As an inveterate blabbermouth it has been killing me to keep my blabbering mouth shut
May 12
For the past 2 months, XBOW has been testing Mythos Preview under embargo as part of a select early-access group. Today, we can finally share what we found. The headline: Mythos Preview is a major advance. It is substantially better than prior models at finding vulnerability candidates, especially when source code is available. But it’s not perfect. We surfaced issues with exploit validation, judgment, and efficiency. Our full write-up covers where Mythos Preview shines, where it still needs support, and what we think this means for the future of offensive security: bit.ly/42zQl98
5
13
140
31,919