SANS DFIR
@sansforensics
Followers
109K
Following
4K
Media
14K
Statuses
33K
The world's leading Digital Forensics and Incident Response provider. This feed updates you on latest DFIR news, events, and training.
Joined February 2009
Ransomware isn’t slowing down — and neither is the need for trained responders. #FOR528: #Ransomware & #CyberExtortion™ has updated pricing to make this critical ransomware response training accessible to more practitioners. Register: https://t.co/41ROzmH363
@rj_chap
0
0
24
The must-attend #CTI event of the year is back! Join top #ThreatIntel analysts, researchers & practitioners to share what’s working, what’s next, & how we can defend together. Leave w/ new tools, fresh insights & meaningful connections. 🔗 https://t.co/jd625AnG5H
#CTISummit
0
2
10
A rumbling beneath China is rising—the underground Church is about to erupt. Watch the broadcast with Hank Kunneman
0
17
151
📱Dive into #iOS App Forensics with our Third-Party Apps #Forensics Reference Guide Poster! This resource lists the most interesting files and folders in the "Data" folder for commonly used apps. 📄 Grab your copy: https://t.co/eevTx7ZO8K
#DFIR
0
2
13
If you work in cyber threat intelligence, the #CTISummit is the must-attend event of the year! Join us to explore the latest in threat intel & incident response. 🗓️ Summit: Jan 26-27 📍 Arlington, VA & 🌐 Free Live Online 💻 Training: Jan 28 - Feb 2 🔗 https://t.co/jd625AnG5H
0
3
11
☁️ What does #Ransomware look like when it moves into the cloud? It’s not what you expect... Join @maridegrazia, Eric Taylor & @megan_roddie as they take you inside modern cloud-based ransomware & #Extortion tactics & how to fight back. Join us today!: https://t.co/YgrtavSygO
0
0
4
Spritz Vibe. Limited Edition. Frosted over & fresh for the season, Spritz Vibe Sparkling Snowball Frost Limited Edition is here! CELSIUS. LIVE. FIT. GO.
535
752
11K
🔎 #Cybercriminals study us... @bushidotoken’s blog exposes how adversaries target #CTI & law enforcement platforms to run their own ops. Read the blog → https://t.co/nxaLoj8FwU
0
0
5
🚨 In case you missed it... 🔍 #ThreatHunting is moving in-house. The 2025 SANS survey shows fewer orgs are outsourcing #IncidentResponse. The FOR508 update delivers skills for this shift, from credential abuse to cloud detection. 📖 Read the blog here: https://t.co/pfqNpLNrwW
0
3
15
🚨 NEWLY UPDATED 🚨 🧠 Struggling w/ #MemoryAnalysis? Our #MemoryForensics Cheat Sheet is here to help! It introduces an analysis framework & covers everything from memory acquisition to live memory analysis & tool usage. 👉 Get your copy: https://t.co/K90zNOob5Y
#DFIR
0
15
62
⚡️ Every #DFIR course is powered by real data, actual case files, artifacts, logs, & evidence. Gain hands-on experience by working realistic scenarios step by step, to investigate w/ confidence. 🔥 See upcoming courses: https://t.co/uEqeKSMW9S
#SANSTraining #Cybersecurity
0
2
10
Only 3 in 10 Veterans know about 0% down home loans. Join our mission to help veterans find their way home.
5
5
51
✍️ As part of #CybersecurityAwarenessMonth, choose how you learn best! 🔥 OnDemand, Live Online, or In-Person. SANS #DFIR courses include deep labs & expert guidance. For a limited time, save 25% w/ code 25DFIR_Cyber 🔗 Check out our upcoming courses: https://t.co/uEqeKSMW9S
0
1
8
🔍 As tools and automation evolve, one takeaway from the 2025 #DFIRSummit stands out: people are still the true differentiator. Human intuition, collaboration, and creativity fuel every breakthrough in #DFIR. 👉 Read the recap: https://t.co/zskxEElCPR
#IncidentResponse
0
2
18
🚨 In case you didn't know @rj_chap & @maridegrazia host a monthly show discussing the latest #Ransomware threats that you need to know about! The Stay Ahead of Ransomware livestream airs the 1st Tuesday of each month. 🎥 Check out past episodes here: https://t.co/aDOvl80RXI
0
2
10
⚠️ Threats actors don’t rest & neither should your training. Our courses evolve to reflect the modern attacker tactics & challenges you face today, giving you the best edge to stay sharp. 👉 See our upcoming courses: https://t.co/uEqeKSMW9S
#DFIR #SANSTraining #Cybersecurity
0
0
5
📄 The Hunt Evil poster is your guide to understand what’s "normal" on a #Windows system. 👉 This poster breaks down expected behavior for core Windows processes, helping you spot suspicious activity. 📩 Grab your copy: https://t.co/eY05SALdPm
#ThreatHunting #IncidentResponse
3
20
88
🛠️ In this blog @rj_chap explores the difference preparation makes when #Ransomware strikes, outlining tactical steps for improving detection and response using the tools you already have. Read the blog → https://t.co/TlpQXktBZm
#OpenSource #DFIR
0
8
18
⚠️ @maridegrazia breaks down how #CISA’s Pre-#Ransomware Notification program shifts the fight from reaction to prevention and how to act fast on early warnings. Read more → https://t.co/bkJ8p9JCOd
0
2
16
Looking to expand your #ThreatIntel knowledge? Join your community at #CTISummit — an event devoted to the tradecraft of cyber threat analysis & intelligence. 🗓️ Summit: Jan 26-27 📍 Arlington, VA & 🌐 Free Online ➡️ Learn More: https://t.co/jd625AnG5H
#ThreatIntel
0
2
6
🚨 First Look: Fear the Dark: Preventing Lack of Data in DFIR — a new white paper from @HeatherMahalik, SANS Head of Curriculum & RSAC™ 2025 keynote, presented by @SANSInstitute + @OneRSAC. Close forensic “dark periods” before attackers exploit them: https://t.co/2fz7eZcvDO
1
6
9
"It’s like your diary times 10." 💬 Chatbot conversations could soon appear as evidence in court. In @RollingStone, @robtlee, SANS Chief of Research & AI, explains how AI logs are reshaping digital forensics and privacy. 🔗 https://t.co/9S5szULJgL
#AI #TechPolicy
rollingstone.com
User exchanges with ChatGPT and other AI tools are a valuable new form of evidence for law enforcement in criminal investigations and prosecutions.
1
10
10
🔎 Make the most of #CybersecurityAwareness Month by learning to analyze host, memory, malware, and cloud artifacts with SANS #DFIR courses. Follow digital evidence wherever it leads. 🔥 Save 25% using 25DFIR_Cyber ✍️ Learn more: https://t.co/Oe2bV3r0ec
#SANSTraining
0
2
3