Andrew Case's personal page for research, software projects, and speaking events. This website serves as a central location for all of my research, software projects, and speaking events. If you are interested in taking one of the training courses I teach or in having me speak at your event then please see the Contact page. An interview on my background and path into forensics can be found on Eric Huber's blog, A Fistful of Dongles. I am the Director of Research at Volexity. Read more about
FEATURES
ALTERNATIVES
An intentionally insecure Android app designed to teach developers and security professionals about common app vulnerabilities.
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.
Hands-on cybersecurity training and testing platform with 1800+ labs
A repository of cybersecurity conference presentation slides from Black Hat, Offensivecon, and REcon.
A blog post discussing the differences between Solaris Zones, BSD Jails, VMs, and containers, with the author arguing that containers are not a real thing.
Comprehensive cheat sheet for SQLite SQL injection techniques and payloads.
Best practices for corporate network segmentation to protect against basic targeted attacks
Curated list of acronyms and terms related to cyber security landscape with explanations beyond buzzwords.
PINNED

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

PTJunior
An AI-powered penetration testing platform that autonomously discovers, exploits, and documents vulnerabilities while generating NIST-compliant reports.

CTIChef.com Detection Feeds
A tiered cyber threat intelligence service providing detection rules from public repositories with varying levels of analysis, processing, and guidance for security teams.

ImmuniWeb® Discovery
ImmuniWeb Discovery is an attack surface management platform that continuously monitors an organization's external digital assets for security vulnerabilities, misconfigurations, and threats across domains, applications, cloud resources, and the dark web.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.