SANS DFIR (@sansforensics) 's Twitter Profile
SANS DFIR

@sansforensics

The world's leading Digital Forensics and Incident Response provider. This feed updates you on latest DFIR news, events, and training.

ID: 22280436

linkhttp://digital-forensics.sans.org calendar_today28-02-2009 18:18:29

32,32K Tweet

107,107K Takipรงi

99 Takip Edilen

SANS DFIR (@sansforensics) 's Twitter Profile Photo

๐Ÿ“ข Next up | Hiren Sadhwani is showing how to spot #Malware like Lumma Stealer & Bumblebee before #Ransomware operators get their hands on your network. โžก๏ธ Join FREE online: sans.org/u/1yCa #RansomwareSummit #ThreatHunting #DFIR

๐Ÿ“ข Next up | Hiren Sadhwani is showing how to spot #Malware like Lumma Stealer & Bumblebee before #Ransomware operators get their hands on your network.
 
โžก๏ธ Join FREE online: sans.org/u/1yCa

#RansomwareSummit #ThreatHunting #DFIR
SANS DFIR (@sansforensics) 's Twitter Profile Photo

๐Ÿ‘‰ Hiren Sadhwani shares traditional TTPs like #Phishing & RDP exploits still work, but attackers are getting creative with: โ€ฃ ClickFix / fake CAPTCHAs โ–ธ Email bombing + MS Teams spoofing โ–ธ Quishing (QR code phishing) โ–ธ SEO poisoning #RansomwareSummit #ThreatIntel #DFIR

๐Ÿ‘‰ Hiren Sadhwani shares traditional TTPs like #Phishing & RDP exploits still work, but attackers are getting creative with:

โ€ฃ ClickFix / fake CAPTCHAs
โ–ธ Email bombing + MS Teams spoofing
โ–ธ Quishing (QR code phishing)
โ–ธ SEO poisoning

#RansomwareSummit #ThreatIntel #DFIR
SANS DFIR (@sansforensics) 's Twitter Profile Photo

๐Ÿ“ฃ Happening now | From #LockBit to #ScatteredSpider, Christina Macaire & Sohan Lokula are mapping how law enforcement disruption is shifting the #RaaS model. ๐Ÿšจ Last chance to join us online: sans.org/u/1yCa #RansomwareSummit

๐Ÿ“ฃ Happening now | From #LockBit to #ScatteredSpider, Christina Macaire & Sohan Lokula are mapping how law enforcement disruption is shifting the #RaaS model.
 
๐Ÿšจ Last chance to join us online: sans.org/u/1yCa

#RansomwareSummit
SANS DFIR (@sansforensics) 's Twitter Profile Photo

๐Ÿ“Š 4,837 #Ransomware victims were posted to leak sites in 2024, up from 3,735 in 2023. And 2025 is on track to surpass both. Stats and projections from the PwC #ThreatIntel team at the #RansomwareSummit

๐Ÿ“Š 4,837 #Ransomware victims were posted to leak sites in 2024, up from 3,735 in 2023. And 2025 is on track to surpass both.

Stats and projections from the <a href="/PwC/">PwC</a> #ThreatIntel team at the #RansomwareSummit
SANS DFIR (@sansforensics) 's Twitter Profile Photo

๐Ÿ“ˆ The 2025 #Ransomware landscape isnโ€™t dominated by giants. Small, agile groups are on the rise. ๐Ÿ”‘ Key takeaways from PwC #ThreatIntel at the #RansomwareSummit: โ€ข Smaller RaaS crews = big impact โ€ข Prioritize based on victimology โ€ข Holistic data = smarter defense

๐Ÿ“ˆ The 2025 #Ransomware landscape isnโ€™t dominated by giants. Small, agile groups are on the rise.

๐Ÿ”‘ Key takeaways from <a href="/PwC/">PwC</a> #ThreatIntel at the #RansomwareSummit:
โ€ข Smaller RaaS crews = big impact
โ€ข Prioritize based on victimology
โ€ข Holistic data = smarter defense
SANS DFIR (@sansforensics) 's Twitter Profile Photo

๐ŸŽ‰That's a wrap! A BIG 'thank you' to everyone who joined us for the 2025 #RansomwareSummit ๐Ÿ‘Shoutout to our incredible speakers, panelists & chairs, Ryan "Chaps" Chapman & Mari Degrazia, for another standout event full of great info & discussions ๐Ÿ˜Ž Until next time, stay safe out there!

SANS DFIR (@sansforensics) 's Twitter Profile Photo

๐Ÿ‘€ Think youโ€™ve seen it all in #ransomware? #ScatteredSpider is here to prove otherwise. ๐Ÿ‘‰ Join us as we explore whatโ€™s changed & where itโ€™s all going. ๐Ÿ“† Jun 3 | 1PM ET ๐Ÿ”—: buff.ly/ZXgAktc #DFIR #IncidentResponse

๐Ÿ‘€ Think youโ€™ve seen it all in #ransomware? #ScatteredSpider is here to prove otherwise.

๐Ÿ‘‰ Join us as we explore whatโ€™s changed &amp; where itโ€™s all going.

๐Ÿ“† Jun 3 | 1PM ET
๐Ÿ”—: buff.ly/ZXgAktc

#DFIR #IncidentResponse
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Join us at SANS #DFIRSummit when Federico Cedolini walks us through how threat actors persist in Microsoft 365 โ€” and how to detect, investigate, and shut them down. โžก๏ธ Save your spot: sans.org/u/1zv0

Join us at SANS #DFIRSummit when Federico Cedolini walks us through how threat actors persist in Microsoft 365 โ€” and how to detect, investigate, and shut them down.

โžก๏ธ Save your spot: sans.org/u/1zv0
SANS DFIR (@sansforensics) 's Twitter Profile Photo

๐Ÿ”Ž Sometimes a threat shows up & changes the game. #ScatteredSpider didnโ€™t just bend the rules, they created new ones. Join us TODAY as we cover whatโ€™s happening & what incident responders need to prepare for. ๐Ÿ“† TODAY | 1PM ET ๐Ÿ”— buff.ly/ZXgAktc #DFIR #Ransomware

๐Ÿ”Ž Sometimes a threat shows up &amp; changes the game. #ScatteredSpider didnโ€™t just bend the rules, they created new ones.

Join us TODAY as we cover whatโ€™s happening &amp; what incident responders need to prepare for.

๐Ÿ“† TODAY | 1PM ET
๐Ÿ”— buff.ly/ZXgAktc

#DFIR #Ransomware
SANS DFIR (@sansforensics) 's Twitter Profile Photo

The #DFIRSummit is your chance to reset your skills, mindset, & connection to the work that matters. Hear from top practitioners on the latest tools, methods & case studies in digital forensics & #IR. ๐Ÿ—“๏ธ Summit: Jul 24-25 | Courses: Jul 26-31 Register: sans.org/u/1zv5

The #DFIRSummit is your chance to reset your skills, mindset, &amp; connection to the work that matters. 

Hear from top practitioners on the latest tools, methods &amp; case studies in digital forensics &amp; #IR.

๐Ÿ—“๏ธ Summit: Jul 24-25 | Courses: Jul 26-31

Register: sans.org/u/1zv5
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Learn to acquire digital evidence from computers, mobile, cloud & more โ€” plus rapid triage skills to extract intel fast. Take FOR498 w/ Kevin Ripa at #DFIRSummit in July. ๐Ÿ’ฅ Save $600 w/ code SUMMIT*600 when you register & pay by July 11! โžก๏ธ Learn More: sans.org/u/1zv0

Learn to acquire digital evidence from computers, mobile, cloud &amp; more โ€” plus rapid triage skills to extract intel fast.

Take FOR498 w/ Kevin Ripa at #DFIRSummit in July.

๐Ÿ’ฅ Save $600 w/ code SUMMIT*600 when you register &amp; pay by July 11!

โžก๏ธ Learn More: sans.org/u/1zv0
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Join us at #DFIRSummit when Tony Knutson walks us through how to think like an examiner โ€” building a mindset that balances forensic accuracy w/ rapid IR decisions. ๐Ÿ—“๏ธ Summit: Jul 24-25 ๐Ÿ“ Salt Lake City, UT & Virtual โžก๏ธ Register: sans.org/u/1zv0 #DFIR #IncidentResponse

Join us at #DFIRSummit when Tony Knutson walks us through how to think like an examiner โ€” building a mindset that balances forensic accuracy w/ rapid IR decisions.

๐Ÿ—“๏ธ Summit: Jul 24-25
๐Ÿ“ Salt Lake City, UT &amp; Virtual

โžก๏ธ Register: sans.org/u/1zv0

#DFIR #IncidentResponse
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Join us at #DFIRSummit in Salt Lake City, July 24-25, for exclusive access to Pierre Lidome's hands-on Google Cloud workshop โ€” see how attackers exploit IAM & default service accounts, then investigate it yourself using SOF-ELK. โžก๏ธ Save Your Spot: sans.org/u/1zv0

Join us at #DFIRSummit in Salt Lake City, July 24-25,  for exclusive access to <a href="/texaquila/">Pierre Lidome</a>'s hands-on Google Cloud workshop โ€” see how attackers exploit IAM &amp; default service accounts, then investigate it yourself using SOF-ELK.
 
โžก๏ธ Save Your Spot: sans.org/u/1zv0
SANS DFIR (@sansforensics) 's Twitter Profile Photo

๐Ÿšจ A #CyberBreach is toughโ€”but poor communication makes it worse. Learn how to prepare, respond, and recover with confidence. Insights from Kelly Miller. Blog by Mari Degrazia. Read the blog โ†’ sans.org/u/1Bxd

๐Ÿšจ A #CyberBreach is toughโ€”but poor communication makes it worse. Learn how to prepare, respond, and recover with confidence. Insights from Kelly Miller. Blog by <a href="/maridegrazia/">Mari Degrazia</a>. 
 
Read the blog โ†’ sans.org/u/1Bxd
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Learn to respond to ransomware threats like HumOR & RaaS using real-world attacks & forensic artifacts. Take FOR528 at #DFIRSummit w/ Ryan "Chaps" Chapman next month! ๐Ÿ’ฅ Save $600 w/ code SUMMIT*600 when you register and pay by July 11! ๐Ÿ”— Register: sans.org/u/1zv0

Learn to respond to ransomware threats like HumOR &amp; RaaS using real-world attacks &amp; forensic artifacts.

Take FOR528 at #DFIRSummit w/ <a href="/rj_chap/">Ryan "Chaps" Chapman</a> next month!

๐Ÿ’ฅ Save $600 w/ code SUMMIT*600 when you register and pay by July 11!  

๐Ÿ”— Register: sans.org/u/1zv0
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Join us at #DFIRSummit on July 24-25 when Dennis Labossiere dives into a 2023 Intune investigation tied to Scattered Spider โ€” featuring Graph API analysis, PowerShell decoding w/ CyberChef, & forensic techniques for cloud-based attacks. โžก๏ธ Save Your Spot: sans.org/u/1zv0

Join us at #DFIRSummit on July 24-25 when Dennis Labossiere dives into a 2023 Intune investigation tied to Scattered Spider โ€” featuring Graph API analysis, PowerShell decoding w/ CyberChef, &amp; forensic techniques for cloud-based attacks.

โžก๏ธ Save Your Spot: sans.org/u/1zv0
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Learn to reverse-engineer malware that targets Windows systems using real-world tools & techniques. Take FOR610 at #DFIRSummit w/ Evan H. Dygert next month! ๐Ÿ’ฅ Save $600 w/ code SUMMIT*600 when you register and pay by July 11! ๐Ÿ”— Register: sans.org/u/1zv0 #MalwareAnalysis

Learn to reverse-engineer malware that targets Windows systems using real-world tools &amp; techniques.

Take FOR610 at #DFIRSummit w/ <a href="/edygert/">Evan H. Dygert</a> next month!

๐Ÿ’ฅ Save $600 w/ code SUMMIT*600 when you register and pay by July 11!

๐Ÿ”— Register: sans.org/u/1zv0

#MalwareAnalysis
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Whether youโ€™re in a SOC, working in IR, analyzing malware, or just entering DFIR โ€” DFIR Bytes will sharpen your investigative skills with hands-on, guided simulations. Join us at DFIR Summit in Salt Lake City, July 24-25! ๐Ÿ”— View Agenda & Save Your Spot: sans.org/u/1zv0

Whether youโ€™re in a SOC, working in IR, analyzing malware, or just entering DFIR โ€” DFIR Bytes will sharpen your investigative skills with hands-on, guided simulations.

Join us at DFIR Summit in Salt Lake City, July 24-25!

๐Ÿ”— View Agenda &amp; Save Your Spot: sans.org/u/1zv0
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Join us at #DFIRSummit in Salt Lake City for exclusive access to Mattia Epifani & Heather Mahalik Barnhartโ€™s hands-on workshop โ€” uncover what โ€œprivate browsingโ€ really leaves behind on phones & computers. ๐Ÿ—“๏ธ Summit: July 24-25 Save Your Spot: sans.org/dfir-summit #DFIR #DigitalForensics

Join us at #DFIRSummit in Salt Lake City for exclusive access to <a href="/mattiaep/">Mattia Epifani</a> &amp; <a href="/HeatherMahalik/">Heather Mahalik Barnhart</a>โ€™s hands-on workshop โ€” uncover what โ€œprivate browsingโ€ really leaves behind on phones &amp; computers.

๐Ÿ—“๏ธ Summit: July 24-25

Save Your Spot: sans.org/dfir-summit

#DFIR #DigitalForensics
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Learn to track human-driven threats with tactical, operational, and strategic CTI skills. Take FOR578 at #DFIRSummit w/ John Doyle next month! ๐Ÿ’ฅ Save $600 w/ code SUMMIT*600 when you register & pay by July 11! ๐Ÿ”— Explore Summit: sans.org/u/1zv0 #CTI #ThreatIntel

Learn to track human-driven threats with tactical, operational, and strategic CTI skills.

Take FOR578 at #DFIRSummit w/ John Doyle next month!

๐Ÿ’ฅ Save $600 w/ code SUMMIT*600 when you register &amp; pay by July 11!

๐Ÿ”— Explore Summit: sans.org/u/1zv0

#CTI #ThreatIntel