RVAsec Deep Dive - August
by RVAsec Security Community
About
**{You must be registered to attend this event.}** Last month we took over the ECPI auditorium with [Nguyen Nguyen](https://www.linkedin.com/in/nguyen-nguyen-ca). This month we’re back home at **Ours** with a double feature, and both talks live on the forensics side of the house. First up: [Malachi Walker](https://www.linkedin.com/in/malachijwalker), Senior Security Advisor at DomainTools, coming down from the DC area with “*DNS as Forensic Gold.*” DNS is ubiquitous, it’s available, it holds domains and IP addresses, and it’s one of the earliest signals of traffic you’ll get in an investigation. Malachi will make the case for why it’s forensic gold, then put it to work with a walkthrough of a real malware investigation, one as recent as he can get his hands on before the 13th. His background runs from DNS to crime and conflict in cyberspace to security governance and program design, with prior stops at FTI Consulting’s cybersecurity practice and WhiteHawk. He holds a Master’s from Virginia Tech with a concentration in Cybersecurity Management. Then: [Hala Ali](https://www.linkedin.com/in/hala-ali-585716172) presents “*Post-Incident Runtime SBOM Generation from Python Memory.*” SBOMs built from package metadata, source files, or build artifacts don’t always match what actually loads and runs, especially in a dynamic ecosystem like Python. Hala will walk through MEM-SBOM, a memory forensics framework that generates runtime SBOMs directly from Python process memory: recovering loaded modules, resolving package versions, reconstructing dependency relationships, and performing function-level vulnerability reachability analysis, tested against 51 real-world Python applications. Hala completed her Ph.D. in Computer Science at VCU, where her research covers memory forensics, malware analysis, and software supply chain security. She’s a Best Paper Award winner at DFRWS USA 2025, a U.S. Cyber Command Defender Award recipient, and has presented at DEF CON AI Village, Black Hat Arsenal, PyCon US, BSides LV, and WiCyS. As always, we’ll leave time for questions and open discussion. Come learn something, meet some people, and hang out with RVAsec! **Location**: • Ours (2309 W Main St) **Agenda**: • 6:00 PM – Doors open, socializing & refreshments • 6:30 PM – Malachi Walker: DNS as Forensic Gold • 7:20 PM – Break • 7:30 PM – Hala Ali: Post-Incident Runtime SBOM Generation from Python Memory • 8:30 PM – Wrap up and open conversation **Capacity**: We expect roughly 40 seats. If you sign up, please show up; if something comes up, no problem, but cancel or update ASAP so someone else can take the spot.