<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SecDocs Feed for author Peter Silberman</title>
    <link>http://secdocs.lonerunners.net</link>
    <atom:link type="application/rss+xml" href="http://secdocs.lonerunners.net/rss/author/176-peter-silberman" rel="self"/>
    <description>Latest security documents RSS feed for author Peter Silberman</description>
    <language>en-us</language>
    <item>
      <title>[Slides] RAIDE: Rootkit Analysis Identification Elimination</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1201-jamie-butler"&gt;Jamie Butler&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/176-peter-silberman"&gt;Peter Silberman&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/278-rootkit"&gt;rootkit&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/96-black-hat-eu-2006"&gt;Black Hat EU 2006&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 14 Jan 2012 20:46:17 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4747-raide-rootkit-analysis-identification-elimination</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4747-raide-rootkit-analysis-identification-elimination</guid>
    </item>
    <item>
      <title>[Slides] RAIDE: Rootkit Analysis Identification Elimination v1.0</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/176-peter-silberman"&gt;Peter Silberman&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/278-rootkit"&gt;rootkit&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/95-black-hat-usa-2006"&gt;Black Hat USA 2006&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 11 Jan 2012 06:40:32 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4715-raide-rootkit-analysis-identification-elimination-v10</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4715-raide-rootkit-analysis-identification-elimination-v10</guid>
    </item>
    <item>
      <title>[Paper] A Comparison Buffer Overflow Prevention Implementations &amp; Weaknesses</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/176-peter-silberman"&gt;Peter Silberman&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/1276-richard-johnson"&gt;Richard Johnson&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/27-buffer-overflow"&gt;buffer overflow&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/88-black-hat-usa-2004"&gt;Black Hat USA 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 07 Dec 2011 21:46:04 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4506-a-comparison-buffer-overflow-prevention-implementations--weaknesses</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4506-a-comparison-buffer-overflow-prevention-implementations--weaknesses</guid>
    </item>
    <item>
      <title>[Slides] A Comparison Buffer Overflow Prevention Implementations &amp; Weaknesses</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/176-peter-silberman"&gt;Peter Silberman&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/1276-richard-johnson"&gt;Richard Johnson&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/27-buffer-overflow"&gt;buffer overflow&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/88-black-hat-usa-2004"&gt;Black Hat USA 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 07 Dec 2011 06:46:09 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4505-a-comparison-buffer-overflow-prevention-implementations--weaknesses</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4505-a-comparison-buffer-overflow-prevention-implementations--weaknesses</guid>
    </item>
    <item>
      <title>[Audio] Snort My Memory</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/176-peter-silberman"&gt;Peter Silberman&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/46-malware"&gt;malware&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/195-malware-analysis"&gt;malware analysis&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/15-black-hat-dc-2009"&gt;Black Hat DC 2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 14 Aug 2010 10:04:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2808-snort-my-memory</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2808-snort-my-memory</guid>
    </item>
    <item>
      <title>[Video] Snort My Memory</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/176-peter-silberman"&gt;Peter Silberman&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/46-malware"&gt;malware&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/195-malware-analysis"&gt;malware analysis&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/15-black-hat-dc-2009"&gt;Black Hat DC 2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 14 Aug 2010 10:04:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2810-snort-my-memory</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2810-snort-my-memory</guid>
    </item>
    <item>
      <title>[Paper] State Of Malware: Family Ties</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/176-peter-silberman"&gt;Peter Silberman&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/869-ero-carrera"&gt;Ero Carrera&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/46-malware"&gt;malware&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/195-malware-analysis"&gt;malware analysis&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/41-black-hat-eu-2010"&gt;Black Hat EU 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: Over the last few years malware has gravitated towards a few major families rather than the single or small-sized families of the past. Families of hundreds or even thousands are not uncommon. These families grouped together demonstrate the evolution of malware over time. This evolution may originate in simple bugfixes and small enhancements or entirely new sets of functionality added over an existing code base. Studying the ties between families, both within and across families, provides us with a context in which to study the development pace and technical improvements as they appear. We will examine how families grow and change amongst the mass malware and targeted attack malware. While examining how families grow and change we will attempt to identify features across all families that are both common and implemented in the same way. This could lead to quick static identification of malware features as well as signaturing these features. We hope to show how multiple families are derived from one code base, we will not just address mass malware, targeted malware but also rootkits and code sharing amongst them.</description>
      <pubDate>Mon, 21 Jun 2010 06:02:36 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2569-state-of-malware-family-ties</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2569-state-of-malware-family-ties</guid>
    </item>
    <item>
      <title>[Slides] State Of Malware: Family Ties</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/176-peter-silberman"&gt;Peter Silberman&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/869-ero-carrera"&gt;Ero Carrera&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/46-malware"&gt;malware&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/195-malware-analysis"&gt;malware analysis&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/41-black-hat-eu-2010"&gt;Black Hat EU 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: Over the last few years malware has gravitated towards a few major families rather than the single or small-sized families of the past. Families of hundreds or even thousands are not uncommon. These families grouped together demonstrate the evolution of malware over time. This evolution may originate in simple bugfixes and small enhancements or entirely new sets of functionality added over an existing code base. Studying the ties between families, both within and across families, provides us with a context in which to study the development pace and technical improvements as they appear. We will examine how families grow and change amongst the mass malware and targeted attack malware. While examining how families grow and change we will attempt to identify features across all families that are both common and implemented in the same way. This could lead to quick static identification of malware features as well as signaturing these features. We hope to show how multiple families are derived from one code base, we will not just address mass malware, targeted malware but also rootkits and code sharing amongst them.</description>
      <pubDate>Mon, 21 Jun 2010 02:12:24 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2568-state-of-malware-family-ties</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2568-state-of-malware-family-ties</guid>
    </item>
    <item>
      <title>[Slides] Metasploit Autopsy: Reconstructing the Crime Scene</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/176-peter-silberman"&gt;Peter Silberman&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/500-steve-davis"&gt;Steve Davis&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/80-metasploit"&gt;Metasploit&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/30-black-hat-usa-2009"&gt;Black Hat USA 2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 19 Sep 2009 20:21:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1308-metasploit-autopsy-reconstructing-the-crime-scene</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1308-metasploit-autopsy-reconstructing-the-crime-scene</guid>
    </item>
    <item>
      <title>[Paper] Metasploit Autopsy: Reconstructing the Crime Scene</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/176-peter-silberman"&gt;Peter Silberman&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/500-steve-davis"&gt;Steve Davis&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/80-metasploit"&gt;Metasploit&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/30-black-hat-usa-2009"&gt;Black Hat USA 2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 19 Sep 2009 20:19:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1307-metasploit-autopsy-reconstructing-the-crime-scene</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1307-metasploit-autopsy-reconstructing-the-crime-scene</guid>
    </item>
    <item>
      <title>[Slides] Snort My Memory</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/176-peter-silberman"&gt;Peter Silberman&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/46-malware"&gt;malware&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/195-malware-analysis"&gt;malware analysis&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/15-black-hat-dc-2009"&gt;Black Hat DC 2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 02 Mar 2009 01:32:00 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/407-snort-my-memory</link>
      <guid>http://secdocs.lonerunners.net/documents/details/407-snort-my-memory</guid>
    </item>
    <item>
      <title>[Paper] Snort My Memory</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/176-peter-silberman"&gt;Peter Silberman&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/46-malware"&gt;malware&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/195-malware-analysis"&gt;malware analysis&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/15-black-hat-dc-2009"&gt;Black Hat DC 2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 02 Mar 2009 00:59:00 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/406-snort-my-memory</link>
      <guid>http://secdocs.lonerunners.net/documents/details/406-snort-my-memory</guid>
    </item>
  </channel>
</rss>

