SANS DFIR (@sansforensics) 's Twitter Profile
SANS DFIR

@sansforensics

The world's leading Digital Forensics and Incident Response provider. This feed updates you on latest DFIR news, events, and training.

ID: 22280436

linkhttp://digital-forensics.sans.org calendar_today28-02-2009 18:18:29

32,32K Tweet

107,107K Followers

99 Following

SANS DFIR (@sansforensics) 's Twitter Profile Photo

📢 Next up | Hiren Sadhwani is showing how to spot #Malware like Lumma Stealer & Bumblebee before #Ransomware operators get their hands on your network. ➡️ Join FREE online: sans.org/u/1yCa #RansomwareSummit #ThreatHunting #DFIR

📢 Next up | Hiren Sadhwani is showing how to spot #Malware like Lumma Stealer & Bumblebee before #Ransomware operators get their hands on your network.
 
➡️ Join FREE online: sans.org/u/1yCa

#RansomwareSummit #ThreatHunting #DFIR
SANS DFIR (@sansforensics) 's Twitter Profile Photo

👉 Hiren Sadhwani shares traditional TTPs like #Phishing & RDP exploits still work, but attackers are getting creative with: ‣ ClickFix / fake CAPTCHAs ▸ Email bombing + MS Teams spoofing ▸ Quishing (QR code phishing) ▸ SEO poisoning #RansomwareSummit #ThreatIntel #DFIR

👉 Hiren Sadhwani shares traditional TTPs like #Phishing & RDP exploits still work, but attackers are getting creative with:

‣ ClickFix / fake CAPTCHAs
▸ Email bombing + MS Teams spoofing
▸ Quishing (QR code phishing)
▸ SEO poisoning

#RansomwareSummit #ThreatIntel #DFIR
SANS DFIR (@sansforensics) 's Twitter Profile Photo

📣 Happening now | From #LockBit to #ScatteredSpider, Christina Macaire & Sohan Lokula are mapping how law enforcement disruption is shifting the #RaaS model. 🚨 Last chance to join us online: sans.org/u/1yCa #RansomwareSummit

📣 Happening now | From #LockBit to #ScatteredSpider, Christina Macaire & Sohan Lokula are mapping how law enforcement disruption is shifting the #RaaS model.
 
🚨 Last chance to join us online: sans.org/u/1yCa

#RansomwareSummit
SANS DFIR (@sansforensics) 's Twitter Profile Photo

📊 4,837 #Ransomware victims were posted to leak sites in 2024, up from 3,735 in 2023. And 2025 is on track to surpass both. Stats and projections from the PwC #ThreatIntel team at the #RansomwareSummit

📊 4,837 #Ransomware victims were posted to leak sites in 2024, up from 3,735 in 2023. And 2025 is on track to surpass both.

Stats and projections from the <a href="/PwC/">PwC</a> #ThreatIntel team at the #RansomwareSummit
SANS DFIR (@sansforensics) 's Twitter Profile Photo

📈 The 2025 #Ransomware landscape isn’t dominated by giants. Small, agile groups are on the rise. 🔑 Key takeaways from PwC #ThreatIntel at the #RansomwareSummit: • Smaller RaaS crews = big impact • Prioritize based on victimology • Holistic data = smarter defense

📈 The 2025 #Ransomware landscape isn’t dominated by giants. Small, agile groups are on the rise.

🔑 Key takeaways from <a href="/PwC/">PwC</a> #ThreatIntel at the #RansomwareSummit:
• Smaller RaaS crews = big impact
• Prioritize based on victimology
• Holistic data = smarter defense
SANS DFIR (@sansforensics) 's Twitter Profile Photo

🎉That's a wrap! A BIG 'thank you' to everyone who joined us for the 2025 #RansomwareSummit 👏Shoutout to our incredible speakers, panelists & chairs, Ryan "Chaps" Chapman & Mari Degrazia, for another standout event full of great info & discussions 😎 Until next time, stay safe out there!

SANS DFIR (@sansforensics) 's Twitter Profile Photo

👀 Think you’ve seen it all in #ransomware? #ScatteredSpider is here to prove otherwise. 👉 Join us as we explore what’s changed & where it’s all going. 📆 Jun 3 | 1PM ET 🔗: buff.ly/ZXgAktc #DFIR #IncidentResponse

👀 Think you’ve seen it all in #ransomware? #ScatteredSpider is here to prove otherwise.

👉 Join us as we explore what’s changed &amp; where it’s all going.

📆 Jun 3 | 1PM ET
🔗: buff.ly/ZXgAktc

#DFIR #IncidentResponse
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Join us at SANS #DFIRSummit when Federico Cedolini walks us through how threat actors persist in Microsoft 365 — and how to detect, investigate, and shut them down. ➡️ Save your spot: sans.org/u/1zv0

Join us at SANS #DFIRSummit when Federico Cedolini walks us through how threat actors persist in Microsoft 365 — and how to detect, investigate, and shut them down.

➡️ Save your spot: sans.org/u/1zv0
SANS DFIR (@sansforensics) 's Twitter Profile Photo

🔎 Sometimes a threat shows up & changes the game. #ScatteredSpider didn’t just bend the rules, they created new ones. Join us TODAY as we cover what’s happening & what incident responders need to prepare for. 📆 TODAY | 1PM ET 🔗 buff.ly/ZXgAktc #DFIR #Ransomware

🔎 Sometimes a threat shows up &amp; changes the game. #ScatteredSpider didn’t just bend the rules, they created new ones.

Join us TODAY as we cover what’s happening &amp; what incident responders need to prepare for.

📆 TODAY | 1PM ET
🔗 buff.ly/ZXgAktc

#DFIR #Ransomware
SANS DFIR (@sansforensics) 's Twitter Profile Photo

The #DFIRSummit is your chance to reset your skills, mindset, & connection to the work that matters. Hear from top practitioners on the latest tools, methods & case studies in digital forensics & #IR. 🗓️ Summit: Jul 24-25 | Courses: Jul 26-31 Register: sans.org/u/1zv5

The #DFIRSummit is your chance to reset your skills, mindset, &amp; connection to the work that matters. 

Hear from top practitioners on the latest tools, methods &amp; case studies in digital forensics &amp; #IR.

🗓️ Summit: Jul 24-25 | Courses: Jul 26-31

Register: sans.org/u/1zv5
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Learn to acquire digital evidence from computers, mobile, cloud & more — plus rapid triage skills to extract intel fast. Take FOR498 w/ Kevin Ripa at #DFIRSummit in July. 💥 Save $600 w/ code SUMMIT*600 when you register & pay by July 11! ➡️ Learn More: sans.org/u/1zv0

Learn to acquire digital evidence from computers, mobile, cloud &amp; more — plus rapid triage skills to extract intel fast.

Take FOR498 w/ Kevin Ripa at #DFIRSummit in July.

💥 Save $600 w/ code SUMMIT*600 when you register &amp; pay by July 11!

➡️ Learn More: sans.org/u/1zv0
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Join us at #DFIRSummit when Tony Knutson walks us through how to think like an examiner — building a mindset that balances forensic accuracy w/ rapid IR decisions. 🗓️ Summit: Jul 24-25 📍 Salt Lake City, UT & Virtual ➡️ Register: sans.org/u/1zv0 #DFIR #IncidentResponse

Join us at #DFIRSummit when Tony Knutson walks us through how to think like an examiner — building a mindset that balances forensic accuracy w/ rapid IR decisions.

🗓️ Summit: Jul 24-25
📍 Salt Lake City, UT &amp; Virtual

➡️ Register: sans.org/u/1zv0

#DFIR #IncidentResponse
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Join us at #DFIRSummit in Salt Lake City, July 24-25, for exclusive access to Pierre Lidome's hands-on Google Cloud workshop — see how attackers exploit IAM & default service accounts, then investigate it yourself using SOF-ELK. ➡️ Save Your Spot: sans.org/u/1zv0

Join us at #DFIRSummit in Salt Lake City, July 24-25,  for exclusive access to <a href="/texaquila/">Pierre Lidome</a>'s hands-on Google Cloud workshop — see how attackers exploit IAM &amp; default service accounts, then investigate it yourself using SOF-ELK.
 
➡️ Save Your Spot: sans.org/u/1zv0
SANS DFIR (@sansforensics) 's Twitter Profile Photo

🚨 A #CyberBreach is tough—but poor communication makes it worse. Learn how to prepare, respond, and recover with confidence. Insights from Kelly Miller. Blog by Mari Degrazia. Read the blog → sans.org/u/1Bxd

🚨 A #CyberBreach is tough—but poor communication makes it worse. Learn how to prepare, respond, and recover with confidence. Insights from Kelly Miller. Blog by <a href="/maridegrazia/">Mari Degrazia</a>. 
 
Read the blog → sans.org/u/1Bxd
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Learn to respond to ransomware threats like HumOR & RaaS using real-world attacks & forensic artifacts. Take FOR528 at #DFIRSummit w/ Ryan "Chaps" Chapman next month! 💥 Save $600 w/ code SUMMIT*600 when you register and pay by July 11! 🔗 Register: sans.org/u/1zv0

Learn to respond to ransomware threats like HumOR &amp; RaaS using real-world attacks &amp; forensic artifacts.

Take FOR528 at #DFIRSummit w/ <a href="/rj_chap/">Ryan "Chaps" Chapman</a> next month!

💥 Save $600 w/ code SUMMIT*600 when you register and pay by July 11!  

🔗 Register: sans.org/u/1zv0
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Join us at #DFIRSummit on July 24-25 when Dennis Labossiere dives into a 2023 Intune investigation tied to Scattered Spider — featuring Graph API analysis, PowerShell decoding w/ CyberChef, & forensic techniques for cloud-based attacks. ➡️ Save Your Spot: sans.org/u/1zv0

Join us at #DFIRSummit on July 24-25 when Dennis Labossiere dives into a 2023 Intune investigation tied to Scattered Spider — featuring Graph API analysis, PowerShell decoding w/ CyberChef, &amp; forensic techniques for cloud-based attacks.

➡️ Save Your Spot: sans.org/u/1zv0
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Learn to reverse-engineer malware that targets Windows systems using real-world tools & techniques. Take FOR610 at #DFIRSummit w/ Evan H. Dygert next month! 💥 Save $600 w/ code SUMMIT*600 when you register and pay by July 11! 🔗 Register: sans.org/u/1zv0 #MalwareAnalysis

Learn to reverse-engineer malware that targets Windows systems using real-world tools &amp; techniques.

Take FOR610 at #DFIRSummit w/ <a href="/edygert/">Evan H. Dygert</a> next month!

💥 Save $600 w/ code SUMMIT*600 when you register and pay by July 11!

🔗 Register: sans.org/u/1zv0

#MalwareAnalysis
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Whether you’re in a SOC, working in IR, analyzing malware, or just entering DFIR — DFIR Bytes will sharpen your investigative skills with hands-on, guided simulations. Join us at DFIR Summit in Salt Lake City, July 24-25! 🔗 View Agenda & Save Your Spot: sans.org/u/1zv0

Whether you’re in a SOC, working in IR, analyzing malware, or just entering DFIR — DFIR Bytes will sharpen your investigative skills with hands-on, guided simulations.

Join us at DFIR Summit in Salt Lake City, July 24-25!

🔗 View Agenda &amp; Save Your Spot: sans.org/u/1zv0
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Join us at #DFIRSummit in Salt Lake City for exclusive access to Mattia Epifani & Heather Mahalik Barnhart’s hands-on workshop — uncover what “private browsing” really leaves behind on phones & computers. 🗓️ Summit: July 24-25 Save Your Spot: sans.org/dfir-summit #DFIR #DigitalForensics

Join us at #DFIRSummit in Salt Lake City for exclusive access to <a href="/mattiaep/">Mattia Epifani</a> &amp; <a href="/HeatherMahalik/">Heather Mahalik Barnhart</a>’s hands-on workshop — uncover what “private browsing” really leaves behind on phones &amp; computers.

🗓️ Summit: July 24-25

Save Your Spot: sans.org/dfir-summit

#DFIR #DigitalForensics
SANS DFIR (@sansforensics) 's Twitter Profile Photo

Learn to track human-driven threats with tactical, operational, and strategic CTI skills. Take FOR578 at #DFIRSummit w/ John Doyle next month! 💥 Save $600 w/ code SUMMIT*600 when you register & pay by July 11! 🔗 Explore Summit: sans.org/u/1zv0 #CTI #ThreatIntel

Learn to track human-driven threats with tactical, operational, and strategic CTI skills.

Take FOR578 at #DFIRSummit w/ John Doyle next month!

💥 Save $600 w/ code SUMMIT*600 when you register &amp; pay by July 11!

🔗 Explore Summit: sans.org/u/1zv0

#CTI #ThreatIntel