<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SecDocs Feed for author Matthieu Suiche</title>
    <link>http://secdocs.lonerunners.net</link>
    <atom:link type="application/rss+xml" href="http://secdocs.lonerunners.net/rss/author/836-matthieu-suiche" rel="self"/>
    <description>Latest security documents RSS feed for author Matthieu Suiche</description>
    <language>en-us</language>
    <item>
      <title>[Paper] Blue Screen Of the Death is dead</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/836-matthieu-suiche"&gt;Matthieu Suiche&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/71-black-hat-usa-2010"&gt;Black Hat USA 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: This talk is introducing MoonSols Windows Memory Toolkit aims at being the ultimate memory and crash dump acquisition and conversion tool for Windows. Including live acquisition on Windows of Microsoft crash dumps, the conversion of hibernation file into crashdump, and even to get a crashdump of a running VMWare Virtual Machine without rebooting it and without any BSOD!</description>
      <pubDate>Wed, 28 Sep 2011 19:39:16 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4055-blue-screen-of-the-death-is-dead</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4055-blue-screen-of-the-death-is-dead</guid>
    </item>
    <item>
      <title>[Slides] Blue Screen Of the Death is dead</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/836-matthieu-suiche"&gt;Matthieu Suiche&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/71-black-hat-usa-2010"&gt;Black Hat USA 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: This talk is introducing MoonSols Windows Memory Toolkit aims at being the ultimate memory and crash dump acquisition and conversion tool for Windows. Including live acquisition on Windows of Microsoft crash dumps, the conversion of hibernation file into crashdump, and even to get a crashdump of a running VMWare Virtual Machine without rebooting it and without any BSOD!</description>
      <pubDate>Tue, 27 Sep 2011 20:52:23 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4054-blue-screen-of-the-death-is-dead</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4054-blue-screen-of-the-death-is-dead</guid>
    </item>
    <item>
      <title>[Video] Windows Hibernation File for Fun and Profit</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/836-matthieu-suiche"&gt;Matthieu Suiche&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/45-windows"&gt;Windows&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/42-black-hat-usa-2008"&gt;Black Hat USA 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 05 Aug 2010 16:18:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2783-windows-hibernation-file-for-fun-and-profit</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2783-windows-hibernation-file-for-fun-and-profit</guid>
    </item>
    <item>
      <title>[Audio] Windows Hibernation File for Fun and Profit</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/836-matthieu-suiche"&gt;Matthieu Suiche&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/45-windows"&gt;Windows&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/42-black-hat-usa-2008"&gt;Black Hat USA 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 05 Aug 2010 11:10:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2778-windows-hibernation-file-for-fun-and-profit</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2778-windows-hibernation-file-for-fun-and-profit</guid>
    </item>
    <item>
      <title>[Slides] Windows Hibernation File for Fun and Profit</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/836-matthieu-suiche"&gt;Matthieu Suiche&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/45-windows"&gt;Windows&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/42-black-hat-usa-2008"&gt;Black Hat USA 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 05 Aug 2010 11:10:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2779-windows-hibernation-file-for-fun-and-profit</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2779-windows-hibernation-file-for-fun-and-profit</guid>
    </item>
    <item>
      <title>[Paper] Advanced Mac OS X Physical Memory Analysis</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/836-matthieu-suiche"&gt;Matthieu Suiche&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/182-mac-os-x"&gt;Mac OS X&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/37-black-hat-dc-2010"&gt;Black Hat DC 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: In 2008 and 2009, companies and governments interests for Microsoft Windows physical memory growled significantly. Now it is time to talk about Mac OS X. This talk will describe basis of Mac OS X Kernel Internals (and not a XNU kernel creation timeline) and how to retrieve various information like machine information, mounted file systems, processes listing and extraction and threads, kernel extensions listing and extraction and Rootkit detection.</description>
      <pubDate>Mon, 24 May 2010 06:02:53 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2504-advanced-mac-os-x-physical-memory-analysis</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2504-advanced-mac-os-x-physical-memory-analysis</guid>
    </item>
    <item>
      <title>[Slides] Advanced Mac OS X Physical Memory Analysis</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/836-matthieu-suiche"&gt;Matthieu Suiche&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/182-mac-os-x"&gt;Mac OS X&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/37-black-hat-dc-2010"&gt;Black Hat DC 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: In 2008 and 2009, companies and governments interests for Microsoft Windows physical memory growled significantly. Now it is time to talk about Mac OS X. This talk will describe basis of Mac OS X Kernel Internals (and not a XNU kernel creation timeline) and how to retrieve various information like machine information, mounted file systems, processes listing and extraction and threads, kernel extensions listing and extraction and Rootkit detection.</description>
      <pubDate>Mon, 24 May 2010 06:02:50 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2503-advanced-mac-os-x-physical-memory-analysis</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2503-advanced-mac-os-x-physical-memory-analysis</guid>
    </item>
  </channel>
</rss>

