SANS instructor, DFIR, malware analysis, network forensics, GSE #26, cyclist, private pilot, he/him

Joined May 2008
357 Photos and videos
🐧 Hunting threats on Linux? Come learn it right. I'm teaching FOR577 at SANS Austin, June 22–27 β€” IR, threat hunting, and GLIR cert prep. Early-bird ends May 7! πŸ–πŸŽΈ πŸ‘‰ sans.org/cyber-security-trai… #SANS #FOR577 #DFIR #Linux
1
1
2
176
Hunting Linux threats in sunny San Diego? 🌴🐚 I’m running #FOR577 LINUX Incident Response & Threat Hunting at #SANSSecWest 2026 in May with @sansforensics β€” hands-on labs, real-world IR, and threat hunting to level up your Linux DFIR game on the world’s favorite server OS.
1
114
Jim - #BlackLivesMatter 🌈 retweeted
How to lose the 21st century to China: 1. Unilaterally disarm regarding the soft power competition by ending economic aid and international media agencies. 2. Impose tariffs irrationally on everyone. 3. Invade Greenland, break up NATO, and isolate the US from the entire world. 4. Defund universities. 5. Discourage the best and brightest from immigrating to the US. 6. Withdraw from international organizations, handing over their control to the Chinese Communist Party. 7. Foment polarization between Americans. 8. Stop supporting democracy abroad; just talk about power. 9. Weaken American democratic institutions at home.
1,060
5,377
21,861
804,412
Jim - #BlackLivesMatter 🌈 retweeted
When you learn that they blocked a doctor and the ambulance how do you come to any other conclusion than that they wanted her dead?
769
5,500
48,549
516,702
Jim - #BlackLivesMatter 🌈 retweeted
I'm a former defense attorney and currently a civil liberties attorney with no political dog in this fight. I watched the video at least 10 times from different angles and at different speeds and waited to offer an opinion, which I still reserve the right to change if additional information changes the calculus. It is very clear that the officers instigated the confrontation. The woman initially tried to wave them past her. ICE officers have no authority to search a US citizen or arrest her (unless there's probable cause to believe she's harboring undocumented individuals, not a contention here). A woman surrounded by masked, armed men who have no law enforcement authority over her has every right to try to escape. Video shows her steering wheel is turned to the right, clearly an attempt to leave WITHOUT hitting anyone and steer clear of the officer standing towards the front of her car. That officer had time to step to the side, which is where he was when he shot her. Even a real police officer would not have the right to shoot at her for trying to flee. This is well-established in the case law; deadly force may not be used simply to prevent someone from getting away. Given that the ICE officers had no law enforcement authority to begin with, AND the video footage shows she was trying to escape a perceived threat, not to kill anyone, the crime is all the more inexcusable. I'm praying for the victim's family, especially her children. I'm also praying for all the conservatives who are so unprincipled and lost they're excusing this terrible crime, and gloating over a death that will leave three young children motherless, because of the victim's politics.
13,009
25,136
137,835
17,493,828
Jim - #BlackLivesMatter 🌈 retweeted
You’re gonna need a bigger snowblower! Put the door back down and go back to bed...until spring. πŸ˜‚
1,220
2,982
39,666
2,271,420
Jim - #BlackLivesMatter 🌈 retweeted
🚨 ICE IS DETAINING A CITIZEN AS β€œUNDOCUMENTED.” 🚨 DHS has now transferred Dulce Consuelo Diaz Morales to Texas. Dulce Consuelo Diaz Morales was born in a hospital in Laurel, Maryland. Her official birth certificate exists. It has been posted. It is not in dispute. Despite this, DHS has moved her from Maryland πŸ‘‰ Louisiana πŸ‘‰ now Texas, while continuing to falsely claim she is not a U.S. citizen. Read that again. A documented U.S. BORN citizen is being treated as deportable. It gets worse. A federal judge has explicitly ordered DHS that they are NOT allowed to deport her or alter her legal status, stating: β€œRespondents… are enjoined from removing Petitioner Dulce Consuelo Diaz Morales from the United States or altering her legal status during the pendency of this action.” Yet, DHS continues to transfer her between states, even moving her to Texas before allowing her to speak with her attorney about the transfer. That is not normal procedure. That is not due process. Throughout all of this, DHS continues to insist she is not a U.S. citizen, in direct contradiction of her birth records and a standing court order. This is not an error. This is a test. If the government can override documentation, ignore a judge, and move a citizen at will, then citizenship becomes conditional… and revocable by force. If this can happen to her, it can happen to anyone.
897
6,863
15,444
803,582
Jim - #BlackLivesMatter 🌈 retweeted
24 Dec 2025
NetExec v1.5.0 has been released!πŸ”₯ Merry Christmas everyone!πŸŽ‰ It's been a very long time since the last release, so there are a TON of new features! Some of the highlights: - Built-in LDAP signing and channel binding checks - RDP command execution - certipy find integration
14
152
742
83,620
Jim - #BlackLivesMatter 🌈 retweeted
25 Dec 2025
πŸ˜‚. Who made this. This is great.
918
16,691
156,238
5,180,879
Jim - #BlackLivesMatter 🌈 retweeted
If you work in cyber threat intelligence, the #CTISummit is the must-attend event of the year! Join us to explore the latest in threat intel with your community. πŸ—“οΈ Summit: Jan 26-27 πŸ“ Arlington, VA & 🌐 Free Live Online ➑️ View Agenda & Register: sans.org/u/1CtB
1
2
4
2,111
Jim - #BlackLivesMatter 🌈 retweeted
🚨 NEWLY UPDATED 🚨 🧠 Struggling w/ #MemoryAnalysis? Our #MemoryForensics Cheat Sheet is here to help! It introduces an analysis framework & covers everything from memory acquisition to live memory analysis & tool usage. πŸ‘‰ Get your copy: sans.org/u/1Dfb #DFIR
13
59
5,073
2 more days to get the early-bird discount for one of my all-time favorite conferences, #SANS #DFIRCON in Miami in Nov. There are a bunch of hands-on workshops on Sun, 16 Nov, lots of evening events during the week #FOR577 my last in 2025. @sansforensics sans.org/cyber-security-cour…
2
6
1,765
RT @stealthygeek: We should really all be retweeting this daily.
12,663
Jim - #BlackLivesMatter 🌈 retweeted
16 Aug 2025
hashcat v7.1.0 released! This update includes important bug fixes, new features, and support for new hash-modes, including KeePass with Argon2. Read the full write-up here: hashcat.net/forum/thread-133…
5
46
157
20,472
Jim - #BlackLivesMatter 🌈 retweeted
1 Aug 2025
hashcat v7.0.0 released! After nearly 3 years of development and over 900,000 lines of code changed, this is easily the largest release we have ever had. Detailed writeup is available here: hashcat.net/forum/thread-133…
21
369
1,210
79,343
Jim - #BlackLivesMatter 🌈 retweeted
Join us at #DFIRSummit in July when Jessica Gorman shares how modular design can streamline IR playbooks β€” saving time, cutting errors, & scaling updates across dozens (or hundreds) of workflows. ➑️ View Agenda & Register: sans.org/u/1zv0 #IncidentResponse #SOAR
1
3
1,020