<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>M-unition &#187; peter silberman</title>
	<atom:link href="http://blog.mandiant.com/archives/tag/peter-silberman/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.mandiant.com</link>
	<description>The Ammunition You Need to Find Evil and Solve Crime</description>
	<lastBuildDate>Wed, 21 Jul 2010 23:16:51 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>MindSniffer, Updated Audit Viewer released</title>
		<link>http://blog.mandiant.com/archives/263</link>
		<comments>http://blog.mandiant.com/archives/263#comments</comments>
		<pubDate>Thu, 19 Feb 2009 23:04:07 +0000</pubDate>
		<dc:creator>Peter Silberman</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Audit Viewer]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[Memoryze]]></category>
		<category><![CDATA[mindsniffer]]></category>
		<category><![CDATA[peter silberman]]></category>
		<category><![CDATA[Snort My Memory]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=263</guid>
		<description><![CDATA[I&#8217;m currently writing this blog post from my hotel room at Blackhat Federal. Jamie and I wrapped up our &#8220;Advanced Memory Forensics in Incident Response&#8221; class on Tuesday. It went very well and we are both looking forward to teaching it again in Las Vegas. I just finished giving my talk &#8220;Snort my Memory.&#8221; I [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m currently writing this blog post from my hotel room at Blackhat Federal. Jamie and I wrapped up our <em>&#8220;Advanced Memory Forensics in Incident Response&#8221;</em> class on Tuesday. It went very well and we are both looking forward to teaching it again in Las Vegas. I just finished giving my talk<em> &#8220;Snort my Memory.&#8221;</em> I detailed the talk in a previous <a href="http://blog.mandiant.com/archives/133">blog post</a>. This post now includes links to available software. MindSniffer is available <a title="MindSniffer" href="http://www.mandiant.com/software/mms.htm">here</a>. If you have any questions comments suggestions please feel free to contact me peter.silberman@mandiant.com.<br />
Following the release of MindSniffer I am thrilled to announce a NEW version of Audit Viewer. This version includes the following features:</p>
<ul>
<li>Process are marked in red if they have injected dlls</li>
<li>View imports/exports of PE files in memory. This can be done by right clicking on memory sections</li>
<li> Signature Manager built into Audit Viewer to support py files generated by MindSniffer</li>
<li>Added sections and semaphore handle types</li>
<li>Memoryze Launcher &#8211; this a GUI wrapping Memoryze and allowing you to configure Memoryze all from a user interface. No more batch scripts or xml files. To utilize Memoryze Launcher, click &#8220;Launch Memoryze.&#8221; You can configure multiple jobs to run at once once they will all run, then the results are auto loaded into Audit Viewer for easier integration. This is a huge feature and I&#8217;m very excited to get feed back on it.</li>
<li> Numerous bug fixes</li>
<li>Updated documentation</li>
</ul>
<p>Grab the new audit viewer at its new location <a title="Audit Viewer 1.0.0.8" href="http://www.mandiant.com/software/mav.htm">Audit Viewer</a><br />
Please feel free to e-mail comments suggestions ideas and anything else you think I should know regarding Audit Viewer.<br />
Enjoy,<br />
Peter</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mandiant.com/archives/263/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
