Jamie Levy🦉 Profile Banner
Jamie Levy🦉 Profile
Jamie Levy🦉

@gleeda

9,647
Followers
5,905
Following
288
Media
15,200
Statuses

@Volatility Core Dev | Art of Memory Forensics co-author | Director of Adversary Tactics @HuntressLabs | #DFIR enthusiast/trainer | gleeda @infosec .exchange

remote
Joined December 2008
Don't wanna be here? Send us removal request.
@gleeda
Jamie Levy🦉
1 year
This is why people stop releasing open source projects: predatory companies ripping off projects and calling them “their own”. At least give an acknowledgment and abide by the license. 🤬🤬🤬 Original:
6
41
138
@gleeda
Jamie Levy🦉
1 year
I'm giving a training on #memoryforensics at @BlueTeamCon on August 25th! Sign up soon if you don't want to miss it! #DFIR #malware
Tweet media one
0
20
83
@gleeda
Jamie Levy🦉
3 years
Come take a FREE #dfir #cybersecurity HANDS-ON training with one of the threat researchers at @HuntressLabs next Tuesday!
2
25
81
@gleeda
Jamie Levy🦉
22 days
I can't believe it's been 10 years since we published this. A little piece of trivia: it was written in ~6 months as we were trying to get it done in time for Black Hat. So many edits, reviews, so much blood, sweat and tears... we didn't get rich, but ooh was it worth it.
@volatility
volatility
22 days
1/ To celebrate the 10th anniversary of The #ArtOfMemoryForensics , we are giving away 1 seat at the upcoming in-person Malware & Memory Forensics Training on #Volatility3 with a pass to From The Source #FTSCon ! Just post a pic of your book & tag @volatility !
Tweet media one
5
17
52
8
9
79
@gleeda
Jamie Levy🦉
8 months
I’m looking to hire a Principal Threat Intelligence Analyst here at @HuntressLabs . You’ll get to build a new program focused on the small business space (those that fall below the cybersecurity poverty line). Please feel free to reach out to me if you have questions or think
1
38
74
@gleeda
Jamie Levy🦉
6 years
I'm releasing an updated version of memtriage today. It has the newest winpmem drivers and yarascan added: #DFIR
1
45
69
@gleeda
Jamie Levy🦉
1 year
I am happy to announce that I will be giving a training at @defcon this summer on Windows Memory Forensics! #dfir #memoryforensics
@defcon
DEF CON
1 year
#defcontraining Las Vegas Spotlight Join @gleeda for "Windows Memory Forensics" for info and registration From the abstract: "This class demonstrates the importance of including Volatile memory in your investigations by covering several attack
3
8
38
2
10
63
@gleeda
Jamie Levy🦉
3 years
We recently had an investigation that involved #babyshark malware which was targeted against members of a national security think tank: #DFIR #malware #infosec cc: @HuntressLabs @_JohnHammond @DaveKleinatland @calebjstewart @MaxRogers5
4
14
61
@gleeda
Jamie Levy🦉
2 years
We're looking for an Incident Responder to join our R&D team here at @HuntressLabs Please feel free to reach out to me if you're interested! DMs are open #DFIR #malware #infosecjobs #memoryanalysis
1
27
58
@gleeda
Jamie Levy🦉
2 months
Wait… WAT? 🤣😂
Tweet media one
17
4
51
@gleeda
Jamie Levy🦉
3 months
So here’s a genuine question to those of you who actually run detective engineering teams: What do you consider as good inputs to that team? We could consider these as tickets, but what should those tickets contain? There seems to be a question of whether or not things should
20
8
45
@gleeda
Jamie Levy🦉
6 years
The initial release of Memtriage can be found here: #DFIR Note that you should test it out before deploying it in your environment.
2
33
44
@gleeda
Jamie Levy🦉
2 years
Getting ready for tomorrow @attrc and I are teaching our Tactical #DFIR class starting tomorrow @BlackHatEvents !! See you tomorrow! #malware #memoryforensics
Tweet media one
Tweet media two
1
7
44
@gleeda
Jamie Levy🦉
4 months
@lizgallo @moorehn The whole “ask for forgiveness” mentality ☹️
0
0
45
@gleeda
Jamie Levy🦉
2 years
Out of curiosity, for those of you who do Threat Hunting, how many "hunts" do you conduct a week / month / quarter? What's a good cadence? #DFIR #malware #ThreatHunting
11
9
43
@gleeda
Jamie Levy🦉
2 years
Do you like hunting for active threats? We currently have a Threat Hunting role open here at @HuntressLabs ! Join the R&D team and work with talented people like @_JohnHammond @calebjstewart @DaveKleinatland and @GregAke #DFIR #malware #ThreatHunting
0
12
42
@gleeda
Jamie Levy🦉
9 years
there is more to come: #DFIR
5
28
36
@gleeda
Jamie Levy🦉
6 months
@jamieantisocial * When the job becomes boring * when you’re not listen to * when you’re doing something you no longer enjoy *when there’s a better opportunity for more growth elsewhere *when your career path is limited *when the culture has changed beyond what was tolerable * when the company
2
2
36
@gleeda
Jamie Levy🦉
1 month
I can’t believe we are at 400 people now (and continuing to grow!)!! 😮😮😮 @HuntressLabs 💙
Tweet media one
0
2
36
@gleeda
Jamie Levy🦉
10 years
this blog is awesome: Of Filesystems and Other Demons: http://t.co/IkO3BsWu7f #DFIR #memoryforensics #malware
1
20
35
@gleeda
Jamie Levy🦉
2 years
Awesome work @_JohnHammond @DaveKleinatland @KyleHanslovan @GregAke Matthew Brennan et al!! I’m so proud to work with you guys ❤️ #dfir #malware
0
7
33
@gleeda
Jamie Levy🦉
6 years
@IanColdwater Rare that you will get an answer on this though
3
0
32
@gleeda
Jamie Levy🦉
1 year
There are various slack channels, discord channels, chats etc for topics on #dfir / #CyberSecurity but do we have something like that dedicated for leadership topics in these fields? How to build and maintain teams, KPIs, etc? Would that be worthwhile, or not?
7
4
33
@gleeda
Jamie Levy🦉
2 years
I'll be giving a talk next week over my journey into #DFIR and give some tips to help others find their way into this space! #memoryforensics #malware #infosec #infosecurity
@WiCySorg
Women in CyberSecurity (WiCyS)
2 years
The journey into Cybersecurity is not one-size-fits-all but can vary from person to person. In this webinar with @HuntressLabs , Jamie Levy will cover how she found her way into this field and give tips for choosing the right path for you. #WiCyS
Tweet media one
1
13
28
1
11
32
@gleeda
Jamie Levy🦉
2 years
I’ve been listening to @MagnetForensics podcast DF IRL (Digital Forensics in Real Life) lately. So far it’s been absolutely fabulous. Love hearing the details of various cases #dfir
1
3
30
@gleeda
Jamie Levy🦉
2 years
Linux is also getting some love ❤️
Tweet media one
Tweet media two
1
3
28
@gleeda
Jamie Levy🦉
3 months
@vxunderground @LinusTech “Does it bother you that it’s just like here and that someone could do something with it?” 🤣⁉️ what does he think is going to happen? 🤣
4
0
29
@gleeda
Jamie Levy🦉
2 years
This was a wild ride! Can't wait to see the detailed breakdown by @_JohnHammond and @calebjstewart next week! cc @HuntressLabs #DFIR #vulnerability #RCE
@KyleHanslovan
Kyle Hanslovan
2 years
Whelp, wasn’t expecting this ConnectWise RCE to become public today. Guess we’ll publish on Monday how @HuntressLabs went from a researcher’s tweet to the ability to push ransomware through ~5,000 R1Soft servers that are exposed on Shodan. #staytuned
Tweet media one
10
117
348
0
2
29
@gleeda
Jamie Levy🦉
8 years
I love working in #dfir and helping out fellow investigators
0
19
28
@gleeda
Jamie Levy🦉
3 years
The #OSDFCon agenda is now out! I'll be giving a talk on #MemoryForensics at this free #DFIR virtual conference on December 1st :-D Don't forget to register! #infosec #volatility #malwareanalysis #malware #memoryanalysis
1
15
29
@gleeda
Jamie Levy🦉
10 years
First @volatility community blogpost of the year: Hunting and Decrypting Communications of Gh0st RAT in Memory http://t.co/BEzNQwlTAa #DFIR
0
32
29
@gleeda
Jamie Levy🦉
7 months
@bbaskin LOL have you taken a look at it to see what it was? 🤣🤣
1
0
26
@gleeda
Jamie Levy🦉
1 year
this is so true! People don't realize how beaten down you can get, how you start to believe that you deserve to be treated poorly. You probably will never truly understand unless you've experienced it yourself.
@NataliaAntonova
Natalia Antonova 🇺🇸🇺🇦
1 year
“Why do you talk about domestic abuse, how embarrassing, no one needs to know this stuff.” Nah. Because here’s the thing: When it was happening to me I had no idea that I didn’t deserve it, that no one deserves it, and that it’s possible to walk away and rebuild your life.
14
33
318
2
3
26
@gleeda
Jamie Levy🦉
1 month
It’s been a little while since I’ve gone around the island, but it was great to get the chance to do it again with great people! @HuntressLabs
Tweet media one
Tweet media two
0
1
26
@gleeda
Jamie Levy🦉
2 years
As usual, the 30 page whitepaper does not disappoint! Great job @attrc @nolaforensix et al! New Memory Forensics Techniques to Defeat Device Monitoring Malware: #DFIR #memoryforensics @volatility
0
13
26
@gleeda
Jamie Levy🦉
8 years
a new version of Forensic Acquisition Utilities (FAU) has been released, which includes a new SignTool #DFIR
0
26
25
@gleeda
Jamie Levy🦉
7 years
Setting up for our largest @BlackHatEvents training so far @attrc #dfir
Tweet media one
1
5
25
@gleeda
Jamie Levy🦉
4 years
Come participate in the @tanium CTF and Threat Response Workshop, online this Saturday (June 6th)! Also I'll be giving a talk on Memory Forensics! #DFIR #infosec #memoryforensics
1
14
25
@gleeda
Jamie Levy🦉
8 years
BTW, If you're ever looking for a good CTF platform, this is very easy to setup and use:
1
12
24
@gleeda
Jamie Levy🦉
2 months
could this finally be the year of the Linux laptop? 😅
4
1
24
@gleeda
Jamie Levy🦉
2 years
There’s still a line outside the door and people are still filtering in due to a traffic jam after the keynote, but @attrc ‘s talk has just started
Tweet media one
2
4
24
@gleeda
Jamie Levy🦉
2 years
We’re currently looking to hire someone with Windows Internals knowledge and golang development experience here at @HuntressLabs . Feel free to reach out to me for any questions regarding the position! #dfir #malware #golang #windows #edr
1
8
24
@gleeda
Jamie Levy🦉
2 months
So much to unpack here…. I’ll have to come back to it later, but I disagree with a lot of it. Especially this part, as if it’s a silver bullet: “Look into goat farming instead.” I do both, and they are BOTH a shit ton of work. Bottom line is: if you aren’t willing to put in
@divinetechygirl
C:\hristina
2 months
While it may not be a popular perspective, this author is absolutely right about the reality of a career in cybersecurity- information security. Spot on.
45
97
502
6
0
22
@gleeda
Jamie Levy🦉
3 months
This is a huge milestone! We're celebrating our Series D funding at @HuntressLabs 📷🥳🎉 We'll continue crushing more bad guys, and empowering essential businesses. Huge thanks to everyone who got us here: our customers, partners, investors, and the legendary badasses at
3
2
23
@gleeda
Jamie Levy🦉
9 years
quick and dirty bash script for using fresponse from a linux machine feel free to expand #DFIR
2
10
22
@gleeda
Jamie Levy🦉
5 years
There's going to be so much @volatility at #OSDFCon this year- including my workshop! #DFIR #memoryanalysis 🥳🥳
@volatility
volatility
5 years
We are honored that so many of you voted for our presentation in the #OSDFCon 2019 Survey. We can now officially tell you that we will be presenting "Volatility 3 Public Beta: The Insider’s Preview" -- more details to follow! #dfir #memoryforensics
Tweet media one
5
72
142
0
6
23
@gleeda
Jamie Levy🦉
21 days
this is seriously messed up. @Apple should do better! a thread 🧵
@doctorow
Cory Doctorow NONCONSENSUAL BLUE TICK (AFK)
22 days
Every performer and creator on Patreon is about to get screwed out of 30% of their gross earnings, which will be diverted to Apple, the most valuable company on Earth. Apple contributes nothing to their work, but it can steal a third of their wages: 1/
Tweet media one
7
341
586
1
8
23
@gleeda
Jamie Levy🦉
3 months
We've come a long way, even in the short time since I have joined. When I first started we only focused on autoruns. Now we have EDR for both Windows and macOS, Managed M365, SAT, SIEM... and what's coming next is going to be huge!
@gleeda
Jamie Levy🦉
3 months
This is a huge milestone! We're celebrating our Series D funding at @HuntressLabs 📷🥳🎉 We'll continue crushing more bad guys, and empowering essential businesses. Huge thanks to everyone who got us here: our customers, partners, investors, and the legendary badasses at
3
2
23
2
1
22
@gleeda
Jamie Levy🦉
8 years
Currently working on the online @volatility course content. so much fun :-D #DFIR
3
5
22
@gleeda
Jamie Levy🦉
2 years
No. Why the hell would I? No one should feel guilty for taking a lunch even if they’re working from home.
@jennica_lobo
Recruiter Jenn
2 years
Work from home people, do you feel guilty for taking a lunch?
332
9
368
2
0
22
@gleeda
Jamie Levy🦉
9 years
you can dump registry hives using the dumpregistry plugin in @volatility #DFIR
0
20
22
@gleeda
Jamie Levy🦉
9 years
a @volatility tip: if the memory sample appears broken, try to use psscan and if that works, pass a process --dtb on the commandline #DFIR
0
15
20
@gleeda
Jamie Levy🦉
4 months
We’ve got some open job reqs for SOC Manager positions in the US, UK and AU, as well as some SOC analyst positions open here at @HuntressLabs #dfir
2
11
20
@gleeda
Jamie Levy🦉
9 years
OMFW 2014 slides on one way to hunt/profile w/memory: builds off of code coming #DFIR
1
19
19
@gleeda
Jamie Levy🦉
3 months
I had a random horse show up on my property today. How’s your day going? 🤣
Tweet media one
Tweet media two
5
0
20
@gleeda
Jamie Levy🦉
11 years
awesome blogpost by @bbaskin : Dumping Malware Configuration Data from Memory with @Volatility http://t.co/WaE7DDbvIv #DFIR
0
31
19
@gleeda
Jamie Levy🦉
27 days
Tweet media one
7
8
19
@gleeda
Jamie Levy🦉
5 years
We're looking for some talented Linux devs @Tanium If you might be interested in building some cool stuff, (and working with me ;-) ) feel free to reach out! You can even work in your pajamas at home (remotely) #DFIR #infosec
0
7
19
@gleeda
Jamie Levy🦉
9 months
@blackroomsec I’m so sorry to hear about this. We’re hiring for several positions at @HuntressLabs if you see anything that might be a fit, I’m willing to answer any questions you may have about them Please pass these along to anyone else who is effected and might be interested as well:
1
0
19
@gleeda
Jamie Levy🦉
1 month
Come check out the @HuntressLabs booth at @BlackHatEvents !! You'll get to hear some talks by @_JohnHammond @GregAke @birchb0y and @jsecurity101
@_JohnHammond
John Hammond
1 month
badass hype video from @HuntressLabs to get pumped up for Blackhat and Hacker Summer Camp 😎🔥
6
6
67
0
3
19
@gleeda
Jamie Levy🦉
7 years
LOL
@kaspersky
Kaspersky
7 years
How strong is your #password ? Use our free password checker & find out! #onlinesafety #security
Tweet media one
35
39
90
2
13
18
@gleeda
Jamie Levy🦉
4 years
Nice to see that people are looking more at AV hooks. I covered a possible way to whitelist them at OMFW in 2013:
@volatility
volatility
4 years
New @volatility Blog Post: When Anti-Virus Engines Look Like Kernel Rootkits — #DFIR #infosec
0
67
108
1
3
18
@gleeda
Jamie Levy🦉
10 years
if you are running @volatility against Win8/2012 x64 samples, it's best to use --kdbg to speed things up: #DFIR
1
23
18
@gleeda
Jamie Levy🦉
2 years
We’ve really seen an uptick in Qakbot activity as of late. @embee_research has been looking into some of these and has extracted out some IOCs. In addition, we’ve added some good hygiene advice #dfir #malware #qakbot cc @HuntressLabs
0
4
17
@gleeda
Jamie Levy🦉
10 years
stop talking about E01 containers (really boring) and focus on GPU malware research (exciting++)!! http://t.co/kGULmhn6Yt #DFIR #malware
0
27
17
@gleeda
Jamie Levy🦉
6 years
The new @DFRWS challenge looks like fun! #DFIR #IoT It'd due March 20, 2019 so there's plenty of time to work on it :-D
0
14
12
@gleeda
Jamie Levy🦉
2 years
So far I’m really enjoying the talk by Allison Wikoff and Sveva Vitoria Scenarelli on spoofed companies and people. #blackhat2022
Tweet media one
Tweet media two
3
3
18
@gleeda
Jamie Levy🦉
1 year
Tweet media one
2
4
17
@gleeda
Jamie Levy🦉
7 years
I found the interrogation rooms #BlackHatUSA
Tweet media one
1
1
17
@gleeda
Jamie Levy🦉
2 years
What are your favorite #dfir / #infosec podcasts? 😀 looking for some good recommendations
8
1
15
@gleeda
Jamie Levy🦉
9 years
a @volatility tip: use the kdbgscan plugin to determine the Windows profile since it's quicker than imageinfo #DFIR
0
20
16
@gleeda
Jamie Levy🦉
1 year
Yay! some cool things about to come from @HuntressCTI 🥳🎉
1
5
17
@gleeda
Jamie Levy🦉
2 years
Ever wonder what it's like working as a Threat Analyst here at @HuntressLabs ? Our very own @Purp1eW0lf has written up a great blog detailing some of the very things they do in a day: P.S. We're hiring! DM me! #DFIR #infosec #malware #ThreatHunting
1
4
17
@gleeda
Jamie Levy🦉
3 months
@FrankMcG There are a few reasons, including: * unknown availability: plans may change at work or personally * unknown agenda: is the content going to be worth my time? * slow approval process: am I willing to pay out of pocket if work doesn’t cover?
1
0
16
@gleeda
Jamie Levy🦉
4 months
I’m not going to be at #RSAC but there will definitely be a @HuntressLabs booth there. Come by the booth and see @_JohnHammond , @birchb0y , @GregAke and others 🥳🎉
1
5
16
@gleeda
Jamie Levy🦉
8 years
Made the mistake of using EnCase v8 today. WTF is this crap? v6 made sense, this REALLY doesn't :'-( #DFIR
3
5
16
@gleeda
Jamie Levy🦉
4 months
@jstrosch YOLO 🤣
0
0
16
@gleeda
Jamie Levy🦉
7 years
how have I lived without pbcopy until now? #DFIR $ head -n 1 gigantic_ass_encoded_data.txt | pbcopy
1
6
16
@gleeda
Jamie Levy🦉
2 years
We’re looking to hire a Sr Manager for the R&D team here at @HuntressLabs ! Feel free to reach out to me for details! #dfir #malware #infosec #infosecjobs
0
5
16
@gleeda
Jamie Levy🦉
6 years
Think you should have more processes in your mac_pslist output? Try the more robust mac_tasks @volatility plugin instead!: #DFIR #DFIRtips
1
9
16
@gleeda
Jamie Levy🦉
9 years
Have a memory sample in encase format, but no encase? Don't convert, use ftk imager to mount it for free: #dfir
0
20
16
@gleeda
Jamie Levy🦉
4 months
Proud to announce that I will be teaching a course on Windows Memory Forensics at @defcon in Vegas this summer! 🥳
2
4
16
@gleeda
Jamie Levy🦉
6 years
@IanColdwater That’s interesting. I didn’t realize that
1
0
16