Andrew Case is a Director of Research with 13 years of hands-on experience leading incident response, threat intelligence, and proactive threat hunting at Volexity. Based in Metairie, Louisiana, he blends deep kernel and memory-forensics expertise—demonstrated by substantial contributions to the Volatility and Volatility3 projects—with practical operational leadership. He teaches and liaises in academia as an adjunct and industry liaison at LSU, translating research into real-world defensive improvements. A frequent trainer at BlackHat and technical advisor to startups, he has a track record of uncovering intrusions that evade traditional tools. His background in kernel memory analysis, reverse engineering, and DFIR gives him a rare mix of low-level technical depth and strategic threat insight. He holds a Master’s in Computer Science from the University of New Orleans and consistently channels open-source work into better enterprise detection and response.
14 years of coding experience
5 years of employment as a software developer
High Scool, High Scool at Archbishop Rummel High School
Master’s Degree Computer Science, Master’s Degree Computer Science at University of New Orleans
Contributions:794 commits, 13 PRs, 226 pushes in 8 years 1 month
Contributions summary:Andrew primarily contributed to the advanced memory forensics framework, focusing on Linux kernel analysis. Their commits show code modifications for parsing kernel memory structures, specifically related to process memory management, including work on the heap, stack, and system call tables. They also updated parsing logic and added support for features like identifying and dumping information about the kernel modules loaded in memory.
Contributions:364 reviews, 141 commits, 148 PRs in 4 years 5 months
Contributions summary:Andrew made numerous code changes primarily focused on improving the functionality and stability of Volatility 3. Their contributions included fixing bugs in the `get_path_file` call, enhancing the `lsof` plugin to print names properly, and addressing ASLR-related issues. They also updated the use of symbols, objects and modules classes, and they implemented a series of updates to the kernel memory analysis by adding new plugins and fixing the calculation of ASLR shifts.
memoryrampythonincident-responseforensics
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.