Mari DeGrazia's Avatar

Mari DeGrazia

@maridegrazia

Digital Forensics and Incident Response SANS Instructor CyberSecurity VR E-Sports Maker

195
Followers
29
Following
22
Posts
26.11.2024
Joined
Posts Following

Latest posts by Mari DeGrazia @maridegrazia

Overheard in the grocery store last night:

"Why is beefstew not a good password?"

Me, in my head: "That's terrible. No random numbers, letters, symbols.. actually random phrases..."

Them: "It's not stroganoff"

22.08.2025 16:06 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
AI Agents for Dark Web Monitoring | AI for Security Agencies
AI Agents for Dark Web Monitoring | AI for Security Agencies YouTube video by AI Anytime

Check out this cool new open-source Dark Web Monitoring AI Agent platform by AI Anytime - it looks like it will work with a local LLM too. I know what my next weekend project is going to be :) #AI #LocalLLMs #DFIR

www.youtube.com/watch?v=9e24...

21.08.2025 21:15 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Keynote | DFIR AI-ze Your Workflow
Keynote | DFIR AI-ze Your Workflow YouTube video by SANS Digital Forensics and Incident Response

I'm a big believer in local LLMs for DFIRβ€”privacy & security matter. In my keynote, "How to DFIR AI-ze Your Workflow," I demo how to use local LLMs with FOSS tools + share common pitfalls. πŸŽ₯ youtu.be/eG2wHGIPCaQ?... #DFIR #FOSS @sansinstitute.bsky.social

18.08.2025 14:09 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Check out this excellent blog post by Ryan Chapman from last month's Stay Ahead of Ransomware live stream. I was bummed I missed this one, but Ryan's recap is great. #DFIR
www.sans.org/blog/shaking...

28.07.2025 19:51 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Digital Forensics & Incident Response Summit & Training 2025 | SANS Institute Obtain hands-on, practical skills from the world's best instructors by taking a SANS course at DFIR Summit & Training 2025.

The SANS #DFIR Summit has always been one of my favorite conferences to attend. This year, I'm excited and honored to be giving the keynote! Attend in person or attend online for free! www.sans.org/cyber-securi...

07.07.2025 17:40 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Digital Forensics & Incident Response Summit & Training 2025 | SANS Institute Obtain hands-on, practical skills from the world's best instructors by taking a SANS course at DFIR Summit & Training 2025.

The SANS Institute #DFIR Summit has always been one of my favorite conferences to attend. This year, I'm excited and honored to be giving the keynote! Attend in person or attend online for free - www.sans.org/cyber-securi...

07.07.2025 17:36 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Ransomware Summit | SANS Institute SANS Ransomware Summit provides the very best forum for ransomware content and applicable lessons to safeguard ourselves and our organizations from harmful ransomware tactics.

It's almost here!!! Join Ryan Chapman and me at the SANS Ransomware Summit tomorrow. I will also be hosting an AI workshop over lunch. Learn how to install and use a local LLM. Register for the free conference and workshop here: www.sans.org/cyber-securi...

29.05.2025 18:14 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Ransomware Summit | SANS Institute SANS Ransomware Summit provides the very best forum for ransomware content and applicable lessons to safeguard ourselves and our organizations from harmful ransomware tactics.

Thinking about taking the SANS 528 Ransomware course? I love teaching itβ€”not only do we focus on ransomware, but also host-based forensics and analysis at scale. It's great for a wide range of investigations!
Use code FOR528-SUMMIT for 30% off
www.sans.org/cyber-securi...

19.05.2025 16:27 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Cloud Heavy, Hybrid Ready: Lessons from BlackBasta and Scattered Spider

🚨 New blog: BlackBasta’s leaks show how ransomware crews still exploit hybrid environments while Scattered Spider leans fully into cloud.

Two actors, two strategies. What it means for IR, cloud defense, and ransomware readiness.

πŸ‘‰ invictus-ir.com/news/cloud-h...

#DFIR #CloudSecurity #CTI

02.04.2025 12:57 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
The State of Ransomware Payments | LinkedIn Episode One: The State of Ransomware Payments What's going on with ransomware payments? Have they dropped off? Have they gone up? What are we in the global IT community seeing in terms of ransomware ...

Join me, Ryan Chapman and guest @ransomwaresommelier.com today at 10AM PT/ 1PM ET as we talk about the state of Ransomware payments. www.linkedin.com/events/73031...

01.04.2025 15:34 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1

Anthropic explores the advancements and implications of frontier AI.''s dual-use capabilities in cybersecurity and biology. Learn more about their strategies to navigate emerging risks: https://www.anthropic.com/news/strategic-warning-for-ai-risk-progress-and-insights-from-our-frontier-red-team

21.03.2025 15:01 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

β€œYour face looks like a museum.”

For all my geology + ocean peeps πŸ§ͺπŸͺ¨πŸŒŠ

13.03.2025 02:12 πŸ‘ 54 πŸ” 9 πŸ’¬ 1 πŸ“Œ 1
Post image

Like usual, the airport charging station is not working. I found a working plug in a pillar and all these strangers are plugged into my charging hub instead πŸ˜‚ #JustTravelThings

12.02.2025 21:22 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Should you pursue the leadership track or thrive as an individual contributor in cybersecurity? Join us for a panel discussion on February 13 with top security leaders as they share insights on making this career-defining choice. Register now: us06web.zoom.us/meeting/regi...

03.02.2025 15:23 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

This is really cool and runs 100% locally - a silent speech recognition tool that reads your lips in real time and types whatever you mouth. The power of local LLMs is amazing. Open source too! - github.com/amanvirparha... #AI.

03.02.2025 14:47 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

I asked Deepseek-r1 14B to tell me a good digital forensics joke. Watching the thought process is so cute and entertaining... #DFIR #AI

01.02.2025 19:21 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

I'm honored to be hosting the SANS Institute Ransomware Summit in May with Ryan Chapman. 5 days left to submit a talk - we want to hear from you! www.sans.org/mlp/ransomwa...

25.01.2025 16:10 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

WinSCP and Rclone are used by this TA (and others) to exfiltrate data... check out my presentation on WinSCP artifacts to help locate relevant evidence : www.youtube.com/watch?v=sCqy...

24.01.2025 23:05 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

This is one of my favorite #DFIR #INFOSEC conferences to attend. They have workshops for kids that I want to attend! Kids and students are free, and just $25 to attend. Well worth the price.

24.01.2025 22:12 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Release: Microsoft Extractor Suite v3

One of my favorite tools for BEC cases just had a nice update! If you are working BEC cases, make sure and check it out
www.invictus-ir.com/news/the-mic...

24.01.2025 16:12 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Week 03 – 2025 ThinkDFIRSRUMday Funday! Akash PatelHandling Incident Response: A Guide with Velociraptor and KAPE BelkasoftEmail Forensics with Belkasoft X Christopher Eng at Ogmini Homelab Part 1 – The Cur…

Week 03 - 2025 #DFIR
thisweekin4n6.com/2025/01/19/w...

19.01.2025 10:00 πŸ‘ 5 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0
Post image

I made a windows #DFIR artifacts collection MindMap, it's tough to fit everything into a readable overview (might change later)

04.01.2025 23:50 πŸ‘ 23 πŸ” 12 πŸ’¬ 1 πŸ“Œ 0

Time for a decaf latte and a wrap up from last week's forensic goodies!

29.12.2024 20:12 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Elevate Your DFIR Skills: Deeper Insights and Practical Applications - Blue Cape Security

For those looking to practice a realistic #DFIR scenario, here is a free case for you to investigate.

Provided artifacts:
- Disk Triage Collection
- Memory Image + pagefile.sys:
- PCAP File

Link: bluecapesecurity.com/courses/elev...

28.12.2024 16:18 πŸ‘ 9 πŸ” 4 πŸ’¬ 1 πŸ“Œ 0
Post image

Found my first #cruisingducks during my Christmas πŸŽ„ cruise this year. Should I rehide it, or keep it???

24.12.2024 14:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

This is so important. Even if it's just a comment on a blog, something new you've seen with an update, find a way to share it with the community.

14.12.2024 16:04 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
SANS San Francisco Winter 2025 | Cyber Security Training SANS San Francisco Winter 2025 (Jan 27-Feb 1) offers hands-on cyber security training taught by real-world practitioners. Attend Live Online or in San Francisco, CA.

Want to learn more about conducting forensic investigations on Windows? I will be teaching SANS FOR500: Windows Forensic Analysis in San Francisco end of next month! Day 2 is my fav where we dive into the registry! www.sans.org/cyber-securi...

11.12.2024 15:14 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Black Basta Gang Uses MS Teams, Email Bombing to Spread Malware Follow us on Bluesky, Twitter (X) and Facebook at @Hackread

Black Basta Ransomware Uses MS Teams, Email Bombing to Spread Malware

11.12.2024 06:12 πŸ‘ 11 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0
Post image Post image Post image Post image

Releasing a new #DFIR tool today! Swap Recon performs brute-force decompression of Windows 10 & 11 swap. Swap Recon was built when we couldn't find existing tools or techniques to decompress modern Windows swap properly in one of our highest-stakes cases. arsenalrecon.com

06.12.2024 17:38 πŸ‘ 9 πŸ” 5 πŸ’¬ 1 πŸ“Œ 1
Preview
Humble Tech Book Bundle: Hacking 2024 by No Starch Level up your hacking and skills with this tech bundle from No Starch. Learn to protect yourself and others! Pay what you want & support charity!

New cyber humble bundle out!

#DFIR #cyber #infosec #security
www.humblebundle.com/books/hackin...

03.12.2024 07:24 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0