<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>M-unition &#187; Black Hat</title>
	<atom:link href="http://blog.mandiant.com/archives/tag/black-hat/feed" rel="self" type="application/rss+xml" />
	<link>https://blog.mandiant.com</link>
	<description>The Ammunition You Need to Find Evil and Solve Crime</description>
	<lastBuildDate>Thu, 09 Feb 2012 14:18:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Jamie Butler named to the Black Hat Review Board</title>
		<link>https://blog.mandiant.com/archives/1760?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=black-hat-review-board</link>
		<comments>https://blog.mandiant.com/archives/1760#comments</comments>
		<pubDate>Thu, 19 May 2011 15:50:08 +0000</pubDate>
		<dc:creator>Travis Reese</dc:creator>
				<category><![CDATA[The Suite Spot]]></category>
		<category><![CDATA[Black Hat]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[malware analysis]]></category>
		<category><![CDATA[Memory analysis]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=1760</guid>
		<description><![CDATA[<p>&#160;<br />
MANDIANT would like to congratulate <a href="https://www.blackhat.com/review-board.html#Butler" target="_blank">Jamie Butler</a> on his appointment to the Black Hat Review Board.  Black Hat is one of the premier technical security conferences, and Jamie’s appointment to its board is a testament to his contributions in advancing the field of computer security. <a href="https://blog.mandiant.com/archives/1760" class="read_more">Read the rest</a></p>]]></description>
			<content:encoded><![CDATA[<p>&nbsp;<br />
MANDIANT would like to congratulate <a href="https://www.blackhat.com/review-board.html#Butler" target="_blank">Jamie Butler</a> on his appointment to the Black Hat Review Board.  Black Hat is one of the premier technical security conferences, and Jamie’s appointment to its board is a testament to his contributions in advancing the field of computer security.  Jamie has been a long-time trainer at this conference and will still be teaching <a href="http://blackhat.com/html/bh-us-11/training/bh-us-11-training_jb-mf.html">Advanced Memory Forensics in Incident Response</a> there with Peter Silberman.  MANDIANT will also be teaching <a href="https://www.blackhat.com/html/bh-us-11/training/bh-us-11-training_md-mal.html" target="_blank">Malware Analysis</a>, <a href="https://www.blackhat.com/html/bh-us-11/training/bh-us-11-training_md-4dy-advmal.html" target="_blank">Advanced Malware Analysis</a>, and <a href="https://www.blackhat.com/html/bh-us-11/training/bh-us-11-training_md-ir.html" target="_blank">Incident Response: Black Hat Edition</a> at the 2011 show.<br />
&nbsp;<br />
We look forward to the cutting-edge presentations and discussions at <a href="http://blackhat.com/html/bh-us-11/bh-us-11-home.html" target="_blank">Blackhat USA 2011</a> and hope to see you there!<br />
<br />&nbsp;<br />
<iframe src="http://www.facebook.com/plugins/like.php?app_id=156147997784697&amp;href=http%3A%2F%2Fblog.mandiant.com%2Farchives%2F1760&amp;send=true&amp;layout=standard&amp;width=450&amp;show_faces=true&amp;action=like&amp;colorscheme=light&amp;font&amp;height=80" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:450px; height:80px;" allowTransparency="true"></iframe></p>
]]></content:encoded>
			<wfw:commentRss>https://blog.mandiant.com/archives/1760/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Memoryze, Audit Viewer, and Training</title>
		<link>https://blog.mandiant.com/archives/994?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=memoryze-audit-viewer-training</link>
		<comments>https://blog.mandiant.com/archives/994#comments</comments>
		<pubDate>Sun, 06 Jun 2010 21:17:14 +0000</pubDate>
		<dc:creator>Jamie Butler</dc:creator>
				<category><![CDATA[The Armory]]></category>
		<category><![CDATA[The Suite Spot]]></category>
		<category><![CDATA[Advanced Memory Forensics in Incident Response]]></category>
		<category><![CDATA[Audit Viewer]]></category>
		<category><![CDATA[Black Hat]]></category>
		<category><![CDATA[memory forensics]]></category>
		<category><![CDATA[Memoryze]]></category>
		<category><![CDATA[MIR 1.4]]></category>
		<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=994</guid>
		<description><![CDATA[<p>For those who are not on our mailing list for <a href="http://www.mandiant.com/products/free_software/memoryze/">Memoryze</a> or <a href="http://www.mandiant.com/products/free_software/mandiant_audit_viewer/">Audit Viewer</a>, we released a new version a little over a week ago. The new version of the software includes all of the memory analysis features that are available in the newly released <a href="http://www.mandiant.com/products/core/intelligent_response">MANDIANT Intelligent Response (MIR) 1.4.</a> <a href="https://blog.mandiant.com/archives/994" class="read_more">Read the rest</a></p>]]></description>
			<content:encoded><![CDATA[<p>For those who are not on our mailing list for <a href="http://www.mandiant.com/products/free_software/memoryze/">Memoryze</a> or <a href="http://www.mandiant.com/products/free_software/mandiant_audit_viewer/">Audit Viewer</a>, we released a new version a little over a week ago. The new version of the software includes all of the memory analysis features that are available in the newly released <a href="http://www.mandiant.com/products/core/intelligent_response">MANDIANT Intelligent Response (MIR) 1.4.</a><br />&nbsp;</p>
<p>So what is included in Memoryze and Audit Viewer 1.4? Well, here is the short of it.<br />&nbsp;</p>
<p><strong>Memoryze:</strong></p>
<ul>
<li>Support for Windows 2003 x64 SP2</li>
<li>Improved support of Vista SP1 and SP2 including port enumeration and a better installer</li>
<li>Enumeration of digital signatures for all loaded modules in a processes&#8217; address space, hooked and hooking drivers, and all drivers found by driver signature scans</li>
<li>Enumeration of MD5/SHA1/SHA256 hash on disk for all loaded modules in a process&#8217; address space and all drivers found by driver signature scans</li>
<li>Updated documentation</li>
<li>Single installer for 64-bit and 32-bit versions</li>
</ul>
<p>&nbsp;<br />
<strong>Audit Viewer:</strong></p>
<ul>
<li>Improvements to the Malware Rating Index (MRI)</li>
<li>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Report visualization of MRI results</li>
<li>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;MRI rule editors that will allow users to graphically edit the MRI rule file</li>
<li>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Handle Trust view to help identify suspicious handles</li>
<li>Ability to search results within a specific process</li>
<li>Multi-select with copy</li>
<li>Multi-select and export to a CSV file</li>
</ul>
<p>&nbsp;<br />
Those who attended the CanSecWest Training in March have already been enjoying many of these features in beta form for months, and we are committed to ensuring that those who attend the <a href="http://bit.ly/cn8Pca">Advanced Memory Forensics in Incident Response class</a> at <strong>Black Hat</strong> will get early access to the next version of Memorzye, which will support <strong>Windows 7 64-bit</strong>.<br />
&nbsp;<br />
As for the <a href="http://bit.ly/cn8Pca">Black Hat training</a>, there is a lot of <strong>new and updated content</strong> for 2010.</p>
<ul>
<li>Coverage of 64-bit operating systems</li>
<li>New section on malware covering different malware techniques and how they stand out in memory</li>
<li>Four new case studies ranging from real Advanced Persistent Threat (APT) incidents, to spear phishing attacks, and everything in between</li>
<li><strong>Student receive early access Memoryze and Audit Viewer for Windows 7 64-bit</strong></li>
<li>Students receive the only free tool to analyze Windows Vista</li>
<li>Students receive the only free tool to analyze Windows 2003 64-bit</li>
<li>Better data collection to help identify processes and drivers as malicious or not</li>
<li>Added the Malware Rating Index (MRI), which helps automatically identify many malware behaviors discussed in the class. Through a simple user interface, students learn how to write rules to identify malware in their own work environments. MRI then uses those rules to score processes as suspicious or not.</li>
</ul>
<p>&nbsp;<br />
I would like to thank James Long who pointed out an issue with the batch scripts* and Peter Villadsen who worked so hard to improve the build process and installation for Memoryze. Peter and I would also like to thank all our loyal users. We appreciate all your feedback, and we hope to see you in Las Vegas.<br />
<br />&nbsp;<br />
* When specifying an output directory from the command line with the batch scripts in Memoryze, the directory must already exist.</p>
]]></content:encoded>
			<wfw:commentRss>https://blog.mandiant.com/archives/994/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

