Ryan "Chaps" Chapman @rj_chap
DFIR & malware analyst. @sansforensics FOR528 Author & FOR610 Instructor. @CactusCon crew. Husband & father. Comments = own. incidentresponse.training Phoenix, AZ Joined December 2008-
Tweets8K
-
Followers8K
-
Following3K
-
Likes10K
Fantastic con for your next talk. Check it out!
GREAT con to sponsor and overall be a part of! Check them out!
GREAT con to sponsor and overall be a part of! Check them out!
Domain Admin shouldn’t logon to workstations. Here’s one way to restrict DA logins to workstations: Create a GPO… Computer Config → Windows Settings → Security Settings → Local Policies → User Rights Assignment → ‘Deny log on locally’ & ‘Deny log on through RDP’ → add…
"Not all heroes wear capes. Some have YouTube channels." .... hot DAAYUUMM CONGRATULATIONS @ScammerPayback !!!!!! 🤩💥🔥🥳🎊🎉 justice.gov/usao-sdca/pr/y…
Catch up on the latest insights from this year's SANS #DFIRSummit. Stream the full playlist now! 📺 youtube.com/playlist?list=…
🚨LAST CALL to submit your #DFIR tool! 🛠️ Submissions for the #EZTool Challenge closes today. @EricRZimmerman is standing by to build the winning idea. 💥 Want to shape the future of DFIR #OpenSource tooling? Learn more here: sans.org/u/1Cso
First we saw APT28 using an LLM to generate commands in their malware and now, a ransomware is using an LLM to start file system encryption 👀
It's hot out there, but there is a light at the end of the tunnel. CACTUSCON 14 IS FEBRUARY 6TH AND 7TH, 2026! Just 165 days away. And our CFP is just around the corner! Stay cool friends.
OSINT-Advanced Searching🔍📝 github.com/The-Osint-Tool…
This IS awesome!
If you know me, you know this is my credo. Try it! It works!
Last weekend marked the 5th year in a row that @ARosenmund and I have presented a workshop at DefCon! Our DC33 Workshop is entitled "Putting EDRs in Their Place: Killing and Silencing EDR Agents Like an Adversary." Not only do we have step-by-step instructions on GitHub, but our…
I'm a big believer in local LLMs for DFIR—privacy & security matter. In my keynote, "How to DFIR AI-ze Your Workflow," I demo how to use local LLMs with FOSS tools + share common pitfalls. #DFIR #FOSS @sansforensics youtu.be/eG2wHGIPCaQ?si…
If you ever find a Yarn video/gif that doesn't play/display, just change the domain to yarn[.]co. I run into this all the time. Yarn users seem to get my humor and clip funny things for which I'm Googling :).
Proud to highlight @SANSInstitute's @HeatherMahalik and her digital forensics work that dismantled the alibi in the Idaho student murders case. Her team painstakingly analyzed data from the defendant’s phone and devices, building a minute by minute timeline that gave…
Listening to @Grifter801's episode of @DarknetDiaries w/@JackRhysider. Had no idea that @dc801 was one of the first DC Groups! And yet I have nearly all their badges and love them for #badgelife reasons. My how much you learn via this dang podcast! Wonderful.

Florian Roth ⚡️ @cyb3rops
206K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
Dave Kennedy @HackingDave
223K Followers 6K Following Founder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
Justin Elze @HackingLZ
65K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Ali Hadi | B!n@ry @binaryz0ne
33K Followers 565 Following DFIR and Adversary Simulation | DFIR @ ProtonMail
SANS DFIR @sansforensics
109K Followers 98 Following The world's leading Digital Forensics and Incident Response provider. This feed updates you on latest DFIR news, events, and training.
Stephan Berger @malmoeb
28K Followers 1K Following Head of Investigations @InfoGuardAG https://t.co/A5lnFAu7eX
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
Thomas Roccia 🤘 @fr0gger_
31K Followers 2K Following AI Security x Threat Intel · Sr. Threat Researcher @Microsoft · Creator of #Unprotect & #NOVA · Malware Warlock · Python 🧡 · Prev @McAfee_Labs · Views mine 😈
Mehmet Ergene @Cyb3rMonk
13K Followers 437 Following https://t.co/uAlYlXIpyV Learn #KQL for #ThreatHunting, #DetectionEngineering, and #DFIR @BluRavenSec | Microsoft Security MVP | #DataScience
Andrew Thompson @ImposeCost
39K Followers 1K Following Head of Research and Discovery (RAD) @Google Threat Intelligence Group via @Mandiant acquisition. Posts are attributable to me—not my employer. Former @USMC.
Eric Capuano - Bsky: ... @eric_capuano
11K Followers 3K Following Co-Founder @recon_infosec | SANS DFIR Instructor | IANS Faculty | https://t.co/yUXCSu2Yso | ⬡ ❤ @shortxstack
💻 Sherrod DeGrippo... @sherrod_im
36K Followers 7K Following Weird security voyeur. Vibe merchant. CISO of your 🩷 Official USPS fan account. 🎉 Host of THE Microsoft Threat Intelligence Podcast. I like crime actors.
Michael Koczwara @MichalKoczwara
23K Followers 2K Following Threat Researcher/Founder @Intel_Ops_io Threat Intelligence, Adversary Infrastructure Hunting, Curated TI Feed (Coming Soon) https://t.co/VQWaze6gaF
Will @BushidoToken
36K Followers 3K Following Senior Threat Intel Advisor @TeamCymru | Co-founder @CuratedIntel | Co-author @SANSForensics FOR589 | Co-founder @BSidesBournemth | @darknetdiaries #126: REvil
Christopher Peacock @SecurePeacock
7K Followers 2K Following #PurpleTeam | Ex @RaytheonTech MSSP, @SCYTHE_IO, & @GD_OTS | Taught at BlackHat & DEFCON | #100DaysofSigma | Keep exploring, keep learning, and stay curious
Nicole Beckwith @NicoleBeckwith
42K Followers 7K Following Director, Security Operations @kroger 🍓 Intel, Hunting, IR, Detection Engineering, Insider Risk, Fraud & Forensics 💻 Fmr LE & DFIR for OH & Secret Service TF.
Josh Stroschein | The... @jstrosch
12K Followers 1K Following Reverse engineer at FLARE/@Google | @pluralsight author | 😱 1M+ views on YT | 🎙️ Host of Behind the Binary podcast 👇
Nasreddine Benchercha... @nas_bench
11K Followers 1K Following Detection @Splunk & @cisco | previously @nextronsystems | @sigma_hq & @magicswordio maintainer | Eternal Learner
J⩜⃝mie Williams @jamieantisocial
10K Followers 7K Following threats && stuff || #UNC1799 forever 🤘|| @DistrictHeather ♥️ + 🍷 **𝚅𝚒𝚎𝚠𝚜 𝚎𝚡𝚙𝚛𝚎𝚜𝚜𝚎𝚍 𝚊𝚛𝚎 𝚖𝚈 օ𝚠𝚗**
Black Hills Informati... @BHinfoSecurity
48K Followers 2K Following Specializing in pen testing, red teaming, and Active SOC. We share our knowledge through blogs, webcasts, open-source tools, and Backdoors & Breaches game.
Virisqa @Virisqa78611
16 Followers 626 Following
MCSR Gen @GenMcsr
6 Followers 278 Following
JamieLee @JamieLe81047117
12 Followers 145 Following
Cyber_nerd @Benjamin15469
95 Followers 1K Following Security + Pentesting + Web + Mobile + Network + Cloud + Ai + RE + IR
VioletHal @Sz6blvSnxw2Z4v
96 Followers 3K Following
MadgeSpencer @HqbvV75aA9yoz
2 Followers 87 Following
St0pp3r @_st0pp3r_
223 Followers 261 Following Detection Engineering · Threat Hunting · Incident Response
Artos @_1Artos
5 Followers 26 Following
LisaLandon @0gRyGhHfHJerYn7
29 Followers 1K Following
tweetterraton @tweetterraton
0 Followers 96 Following
David Isaiah Abrio @middleChild1229
0 Followers 20 Following
Joseph Nguyễn @josephbt7o
4 Followers 201 Following
Mathew Musango @MathewMusango
17 Followers 2K Following
tsunamipapi @tsUn4m1p4p1_ph
0 Followers 183 Following
PC Philanthropy @PcPhilanthropy
26K Followers 2K Following Tech enthusiast | Nostalgia Addict | Philosopher | The natural world has much to teach if we but just listen…
Fabricio Aranda @fabricioarandaz
21 Followers 374 Following Publish your dynamic content management system sites as static so your site will be secure, faster & scalable. Supports WP, Joomla and Drupal.
Juicy Greens @GreensJuicy
137 Followers 81 Following Where's the pay pigs? I need more like a cash 🐄!
Dan @DanIskandarov
51 Followers 2K Following
Brown Jack @BrownJack596114
0 Followers 359 Following
Grace Mulligan @GraceMulli35404
1 Followers 85 Following
LisaHerty @37M6zpWCJ2MEwKR
18 Followers 719 Following
Simon Roses @simonroses
3K Followers 993 Following AppSec, Pen Testing, Technology, Business and anything interesting. Founder & CEO of @vulnexsl (https://t.co/s15XGDIFGD) -Un mallorquin explorando el mundo
Loo @Loo55047531
0 Followers 28 Following
¯\_(ツ�... @Nobody892797075
0 Followers 679 Following
PossumSec @0xPossumSec
45 Followers 1K Following
Michael Lenz Jr @jr_lenz27968
19 Followers 22 Following
Ezra Woods @Shammahwoods
114 Followers 58 Following we do a bit of security research ‘round these parts.
IgorHackman @igorhackman
2 Followers 114 Following
d!giD0F @DigiDOF
680 Followers 6K Following Gen-X - Experienced from A-trax to A.i. from The X-Men 2 Ox/Hex 2 Quantum Leap, from the 80s - 2G to π Learning the Learner.
TheMagician @31337Magician
1K Followers 846 Following I'm The Magician, I pick locks, social engineer folks, & test pens. I only know #dadjokes. Built in Rick Roll. #Pentester #ADHD #ActuallyAutistic #Cyborg
Kali 🅅 🏳️�... @RadicalKjax
2K Followers 643 Following 🪴👩🏼💻🧘🏼♀️🏳️⚧️🔮✨🌕🐇| She/Her | weeb | nerd | goober | hack-a-doodler | smartest airhead | https://t.co/Edx234I8sK
Edna (they/them) 🅅 @ednas
1K Followers 1K Following Black Badge WWHF '25 | @DEATHCon2025 Orlando Site organizer | @BsidesORL Vol Coordinator | DEF CON Group Orlando | Malware analyst
Kaida @ShutenDoji1337
1 Followers 48 Following
TelWha. @TelWha
102 Followers 3K Following
Bl4ckM1rror @Bl4ckM1rror
30 Followers 318 Following Sometimes friend of ntdll, only when is unhooked | Red Team Operator | Malware Developer | Windows Infernals
GAMALIEL SANKAY TSHIS... @SankayMarc22830
156 Followers 4K Following
Egabi @Egabi6271
102 Followers 2K Following
Florian Roth ⚡️ @cyb3rops
206K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
Dave Kennedy @HackingDave
223K Followers 6K Following Founder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
Jake Williams @MalwareJake
142K Followers 2K Following Breaker of software | VP R&D @hunterstrategy | CTI/DFIR | @ians_security faculty | Bookings: jake at malwarejake dot com | GSE #150 | He/him
Justin Elze @HackingLZ
65K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Mick Douglas 🇺🇦... @bettersafetynet
30K Followers 568 Following Consultant for InfoSec Innovations | @SANSInstitute Principal Instructor | @IANS_Security Faculty | I like information security. How about you?
4n6lady @4n6lady
62K Followers 669 Following #DFIR & #BlueTeam | IR & Threat Detection | #OSINT enthusiast | waiting for HL3 | AWS CIRT - my views are my own
Ali Hadi | B!n@ry @binaryz0ne
33K Followers 565 Following DFIR and Adversary Simulation | DFIR @ ProtonMail
SANS DFIR @sansforensics
109K Followers 98 Following The world's leading Digital Forensics and Incident Response provider. This feed updates you on latest DFIR news, events, and training.
Stephan Berger @malmoeb
28K Followers 1K Following Head of Investigations @InfoGuardAG https://t.co/A5lnFAu7eX
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
Kostas @Kostastsale
18K Followers 367 Following @TheDFIRReport | No longer active here – find me on Bluesky: https://t.co/qHzDSxCRfG. 🇬🇷🇨🇦
DebugPrivilege @DebugPrivilege
40K Followers 2K Following Windows Nerd | Ex-MSFT | Microsoft MVP in Windows | Interested in Security, Debugging, and Windows Internals.
Chris Sanders 🔎 �... @chrissanders88
34K Followers 489 Following Ed.D. | Founder @networkdefense @RuralTechFund | Former @Mandiant, DoD | Author: Intrusion Detection Honeypots, Practical Packet Analysis, Applied NSM
Thomas Roccia 🤘 @fr0gger_
31K Followers 2K Following AI Security x Threat Intel · Sr. Threat Researcher @Microsoft · Creator of #Unprotect & #NOVA · Malware Warlock · Python 🧡 · Prev @McAfee_Labs · Views mine 😈
Mehmet Ergene @Cyb3rMonk
13K Followers 437 Following https://t.co/uAlYlXIpyV Learn #KQL for #ThreatHunting, #DetectionEngineering, and #DFIR @BluRavenSec | Microsoft Security MVP | #DataScience
Andrew Thompson @ImposeCost
39K Followers 1K Following Head of Research and Discovery (RAD) @Google Threat Intelligence Group via @Mandiant acquisition. Posts are attributable to me—not my employer. Former @USMC.
Eric Capuano - Bsky: ... @eric_capuano
11K Followers 3K Following Co-Founder @recon_infosec | SANS DFIR Instructor | IANS Faculty | https://t.co/yUXCSu2Yso | ⬡ ❤ @shortxstack
Florian Hansemann @CyberWarship
84K Followers 47 Following Father, Founder @HanseSecure, Pentesting, Student, ExploitDev, Redteaming, InfoSec & CyberCyber; -- Mastodon: https://t.co/KFSKYUN98M
spencer @techspence
12K Followers 2K Following 🛡️Empowering defenders & dismantling threats | Ethical Threat | pentester @securit360 | host @cyberthreatpov | SWAG https://t.co/AFJtZQcti7
@[email protected]... @Baybe_Doll
4K Followers 1K Following AKA n3x7. #TeamHashcat. @defcon SOC GOON. Staff DEF CON @PasswordVillage, @BSidesLV, @Hushcon. Bug hunter @SynackRedTeam. Fmr COO @TerahashCorp
PC Philanthropy @PcPhilanthropy
26K Followers 2K Following Tech enthusiast | Nostalgia Addict | Philosopher | The natural world has much to teach if we but just listen…
sixtyvividtails @sixtyvividtails
3K Followers 395 Following Currently working as an independent GUID merchant. Fully licensed. I acquire, produce, and sell high-quality GUIDs.
CodeX @codex_tf2
2K Followers 211 Following advanced persistent clown 🤡 📕 redteam blog: https://t.co/ihAv2kG3JR 🛠️ github: https://t.co/VhmOUAWcTp
Security BSides Albuq... @BSides_ABQ
540 Followers 56 Following 𝐖𝐡𝐞𝐧: 25 & 26 July 2025 𝐖𝐡𝐞𝐫𝐞: UNM Continuing Education 𝐓𝐢𝐜𝐤𝐞𝐭: https://t.co/qr8h0p9CfZ
Simon Roses @simonroses
3K Followers 993 Following AppSec, Pen Testing, Technology, Business and anything interesting. Founder & CEO of @vulnexsl (https://t.co/s15XGDIFGD) -Un mallorquin explorando el mundo
Ezra Woods @Shammahwoods
114 Followers 58 Following we do a bit of security research ‘round these parts.
Nathan McNulty @NathanMcNulty
17K Followers 1K Following Loves Jesus, loves others | Husband, father of 4, security solutions architect, love to learn and teach | Microsoft MVP | @TribeOfHackers | 🦋@nathanmcnulty.com
Zöe @Zoe_r_Jay
816 Followers 6K Following Economist. Techie. Geek. 🏳️⚧️ https://t.co/ORywUXz1ZI @CyberSec916
mathew @mathew_dev
3K Followers 1K Following technologist, systems architect (code, data, infrastructure and networking). infantry (ret.) hobbies: RF Radio, Motorcycles. pronouns: boss/chief/sir/top
Kali 🅅 🏳️�... @RadicalKjax
2K Followers 643 Following 🪴👩🏼💻🧘🏼♀️🏳️⚧️🔮✨🌕🐇| She/Her | weeb | nerd | goober | hack-a-doodler | smartest airhead | https://t.co/Edx234I8sK
Ⓥ Schmoo's Inclusiv... @inclusiveunicrn
4K Followers 1K Following Human. Wife. Mother. Girlfriend. Daughter. Sister. Friend. Pansexual. Unicorn. 🏳️⚧️ Ally. Infosec adjacent for 20 years. & I stand against genocide always 🍉
The Wheres Wally Podc... @TheWheresWally
19 Followers 138 Following Intel, warfare, hacking and the weird corners of geopolitics. Hosted by a USMC vet & intel pro deployed to Iraq, Afg, & Africa. YouTube: @thewhereswallypodcast
Skylando Bloom @SkylerJEgert
454 Followers 82 Following Native American, 25M co-founder of @EvilRabbitSec 13+ Years of software development Orlando Bloom lookalike My tweets are my own.
Michael Lenz Jr @jr_lenz27968
19 Followers 22 Following
TheMagician @31337Magician
1K Followers 846 Following I'm The Magician, I pick locks, social engineer folks, & test pens. I only know #dadjokes. Built in Rick Roll. #Pentester #ADHD #ActuallyAutistic #Cyborg
Edna (they/them) 🅅 @ednas
1K Followers 1K Following Black Badge WWHF '25 | @DEATHCon2025 Orlando Site organizer | @BsidesORL Vol Coordinator | DEF CON Group Orlando | Malware analyst
Talking Sasquach @TalkingSasquach
2K Followers 97 Following An actual Talking Sasquach teaching tech stuff to skids and kids of all ages! Check me out on YouTube!! https://t.co/hYb3aVI5Gy
Jackie O. @gat0rg1rl
933 Followers 548 Following Cloud Security Eng & sometimes runner. Miami born and raised, NYC trained me for life🦾. She/Her/Ella #GoGators #LatinaInTech
coruscant ventures @coruscant_ven
5 Followers 16 Following
TRΛVIS 🚀 @DreamFighter22
1K Followers 1K Following ICS/OT Cybersecurity 🏭 | avgeek 🚀 | All views mine.
normalhuman @normalhumanfun
170 Followers 272 Following we’re all just normal humans. cyber. advisor to execs. techno-humanist. private AI tamer.
Jenn @_nextjenn
1K Followers 356 Following Black Badge @DEFCON, Social Engineering | Private Investigator | Locksmith | Offensive Security Consultant
Dustin @dmissp
722 Followers 4K Following Hubby, Daddy, Company Fella. #BlackLivesMatter #PurpleTeam, #InfoSecWhiskey, #TeamDuck @[email protected]
sudox @kmcnam1
12K Followers 3K Following CCIEx2 #50931 and a bunch of random paper. Opinions are my own and not the company I work. I guess I'm Green Arrow's daughter or something...
Maxie Reynolds @__maxreynolds
4K Followers 84 Following
Hollie Hennessy @HollieHennessy
5K Followers 737 Following Lead Analyst covering IoT and OT Cybersecurity. London. Foodie. Classicist. Views are my own.
Chi-en (Ashley) Shen ... @ashl3y_shen
4K Followers 1K Following Security researcher @TalosSecurity / Ex-Google TAG / Black Hat USA & HITCON Review Board / Organizer of @rhacklette41. My tweets are my own opinion.
Alphabet Soup @Alph4betSoup
912 Followers 219 Following Abandoning privacy should not be a prerequisite for achieving security | data/privacy/security nerd | Just some chick
rekdt @rekdt
11K Followers 714 Following // principal cybersecurity anarchist // unethical hacker // ex aws, wn, else // @redteamvillage_ & @sec_defcon daemon // take sincerely at your own risk
Bug Bounty Village @BugBountyDEFCON
8K Followers 580 Following Official X account for the Bug Bounty Village @DEFCON. Founded by @infinitelogins and @arl_rose.
medusfour Ⓥ @medus4_cdc
27K Followers 7K Following I exist, but at what cost? privacy nerd, maker of cursed art, hacking the world for chaotic good. all nodes are equal.
ic3qu33n @nikaroxanne
2K Followers 206 Following reverse engineer | hacker | vx artist | malware witch | my artistic process is a daemon process. @[email protected]
LeighTrinity @LeighGi66657535
9K Followers 1K Following Board of directors: Malware village/World cyber health. Hacker. Assembly/Bash/Python/C. Exploit development, Malware analysis, reverse engineering. Hiker/Foodie
solst/ICE @IceSolst
21K Followers 2K Following Pentester turned seceng turned meeting canceller - https://t.co/5hHG2R5lRS (-13$ ARR)
Maddy 🐝 @Cyb3rMaddy
27K Followers 264 Following Cyber Security Content Creator 🛜 Technical Tutorials 🚨 Security News 📺 100k+ on YouTube 👇
National Cyber Securi... @AUCyberSecCoord
10K Followers 27 Following Coordinating 🇦🇺 cyber security policy, incident response capability & incident preparedness.
alden @birchb0y
3K Followers 2K Following sr threat researcher @ huntress • re/malware enjoyer • macOS security
Pirate Software @PirateSoftware
287K Followers 312 Following Game Dev - Streamer 💛 Go Make Games - https://t.co/IfsqGOr7jG 💜 Ferret Rescue - https://t.co/r761eUgXNe 💛 Business: [email protected]