Andrew Case

@attrc.bsky.social

Volatility Core developer, Dir. of Research Volexity, LSU Cyber

To summarize: HuggingFace got compromised by a model from an American company. HF then tried to use American frontier model(s) to defend themselves, but were blocked by guardrails. HF then had to use open source Chinese models to defend themselves from an American org openai.com/index/huggin...

Memory forensics is a required technique to detect and respond to modern malware. Come see Volcano in action at FIRST next week to learn how memory forensics can be applied at true enterprise scale.

Volexity@volexity.com · 2mo ago

Heading to Denver for #FIRSTCON26 next week? Stop by the @volexity.com booth to see a demo of Volcano! We’ll show you how memory analysis with Volcano uncovers advanced threat actors and helps rapidly resolve your investigations. #DFIR #FIRSTCON

@volexity.com tracks a variety of threat actors abusing Device Code & OAuth authentication workflows to phish credentials, which continue to see success due to creative social engineering. Our latest blog post details Russian threat actor UTA0355’s campaigns impersonating European security events.

Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks

In early 2025, Volexity published two blog posts detailing a new trend among Russian threat actors targeting organizations through the abuse of Microsoft 365 OAuth and Device Code authentication workf...

volexity.com

The full lineup for our From the Source event is out! The event take places on October 20th in Arlington, VA. Joe Grand will keynote followed by an amazing speaker line up across two tracks. All proceeds will be donated to Connect Our Kids. volatilityfoundation.org/from-the-sou...

From The Source 2025

Learn Directly from the World’s Leading Digital Investigators: On Monday, October 20, 2025, the Volatility Foundation is hosting From The Source, a one-day summit, in Arlington, VA, followed by fou…

volatilityfoundation.org

With Volcano, security teams can automate the entire workflow of acquisition of memory and select files to deep analysis to automated alerts that directly point to signs of memory only malware and attacker activity throughout RAM and key artifacts sources from disk.

Volexity@volexity.com · 10mo ago

@volexity.com Volcano Server & Volcano One v25.09.21 adds memory analysis support for ARM64 Linux, macOS 26 (Tahoe) & Windows 25H2, plus 75+ new YARA rules, 10+ new IOCs, analysis of udev rules & rolling upgrades for managed endpoints. For more information, contact us: volexity.com/company/cont...

The stylized blue, orange and black Volexity Volcano logo is centered, with the Volcano wordmark below it. The words “by Volexity” appear below the Volcano logo. There is a dark blue banner in the upper left with white letters that read “New Release”. The background is a faded gray abstract illustration evoking smoke.

I am very happy to announce that @volexity.com will be well represented at @bsidesnyc.org! David McDonald will be speaking on his latest automated Powershell Deobfuscation research & I will present the latest Volatility 3 advancements against sophisticated Windows malware: bsidesnyc.org/schedule/

Event Schedule

BSides NYC is an Information / Security conference that’s different. We’re a 100% volunteer organized event put on by and for the community, and we truly strive to keep information free.

bsidesnyc.org

This training course will be led by Andrew Case @attrc.bsky.social, Michael Ligh & Dave Lassalle. This is a great opportunity to gain valuable knowledge about #Volatility3 + learn all about #memoryforensics from Volatility core developers! Seats are filling up quickly so don't wait!

Volatility@volatilityfoundation.org · last yr.

The next in-person Malware & Memory Forensics Training will be in Arlington VA, October 21–24, 2025! This is the only #memoryforensics course taught directly by the Volatility developers. Course registration includes a pass to #FTSCon! Course details: memoryanalysis.net/courses-malw...

An image of Michael Hale Ligh, a Volatility core developer, leading a training session. There are students in the foreground focused on what is being discussed. In the background, out the window, is the Washington Monument. There is a top yellow banner that reads IN-PERSON TRAINING, and a blue text box on the bottom that reads "Malware & Memory Forensics Training, October 21-24, 2025 | Arlington VA"

Super excited to help @attrc.bsky.social teach memory forensics at a @defcon.bsky.social workshop this year! I'll also be at @bsideslv.org earlier in the week as well so if you run into me please say hi! (And I will have cool stickers)

@lsuresearch.bsky.social · last yr.

#LSU cyber students will teach new ways to fight malware at the world’s largest and longest-running hacking conference @defcon.bsky.social www.lsu.edu/blog/2025/06... #ScholarshipFirst #WBTTW @lsu.bsky.social @lsuengineering.bsky.social @attrc.bsky.social @volexity.com @volatilityfoundation.org