<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>M-unition &#187; peter silberman</title>
	<atom:link href="http://blog.mandiant.com/archives/tag/peter-silberman/feed" rel="self" type="application/rss+xml" />
	<link>https://blog.mandiant.com</link>
	<description>The Ammunition You Need to Find Evil and Solve Crime</description>
	<lastBuildDate>Thu, 09 Feb 2012 14:18:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>MindSniffer, Updated Audit Viewer released</title>
		<link>https://blog.mandiant.com/archives/263?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=mindsniffer-updated-audit-viewer-released</link>
		<comments>https://blog.mandiant.com/archives/263#comments</comments>
		<pubDate>Thu, 19 Feb 2009 22:04:07 +0000</pubDate>
		<dc:creator>Peter Silberman</dc:creator>
				<category><![CDATA[The Armory]]></category>
		<category><![CDATA[Audit Viewer]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[Memoryze]]></category>
		<category><![CDATA[mindsniffer]]></category>
		<category><![CDATA[peter silberman]]></category>
		<category><![CDATA[Snort My Memory]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=263</guid>
		<description><![CDATA[<p>I&#8217;m currently writing this blog post from my hotel room at Blackhat Federal. Jamie and I wrapped up our <em>&#8220;Advanced Memory Forensics in Incident Response&#8221;</em> class on Tuesday. It went very well and we are both looking forward to teaching it again in Las Vegas. <a href="https://blog.mandiant.com/archives/263" class="read_more">Read the rest</a></p>]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m currently writing this blog post from my hotel room at Blackhat Federal. Jamie and I wrapped up our <em>&#8220;Advanced Memory Forensics in Incident Response&#8221;</em> class on Tuesday. It went very well and we are both looking forward to teaching it again in Las Vegas. I just finished giving my talk<em> &#8220;Snort my Memory.&#8221;</em> I detailed the talk in a previous <a href="http://blog.mandiant.com/archives/133">blog post</a>. This post now includes links to available software. MindSniffer is available <a title="MindSniffer" href="http://www.mandiant.com/software/mms.htm">here</a>. If you have any questions comments suggestions please feel free to contact me peter.silberman@mandiant.com.<br />
Following the release of MindSniffer I am thrilled to announce a NEW version of Audit Viewer. This version includes the following features:</p>
<ul>
<li>Process are marked in red if they have injected dlls</li>
<li>View imports/exports of PE files in memory. This can be done by right clicking on memory sections</li>
<li> Signature Manager built into Audit Viewer to support py files generated by MindSniffer</li>
<li>Added sections and semaphore handle types</li>
<li>Memoryze Launcher &#8211; this a GUI wrapping Memoryze and allowing you to configure Memoryze all from a user interface. No more batch scripts or xml files. To utilize Memoryze Launcher, click &#8220;Launch Memoryze.&#8221; You can configure multiple jobs to run at once once they will all run, then the results are auto loaded into Audit Viewer for easier integration. This is a huge feature and I&#8217;m very excited to get feed back on it.</li>
<li> Numerous bug fixes</li>
<li>Updated documentation</li>
</ul>
<p>Grab the new audit viewer at its new location <a title="Audit Viewer 1.0.0.8" href="http://www.mandiant.com/software/mav.htm">Audit Viewer</a><br />
Please feel free to e-mail comments suggestions ideas and anything else you think I should know regarding Audit Viewer.<br />
Enjoy,<br />
Peter</p>
]]></content:encoded>
			<wfw:commentRss>https://blog.mandiant.com/archives/263/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

