For people who wasn’t (or was :)) at PacSec the last week. Slides of Sandman lecture can be found in Japanese[PPT] or in English (updated – last version) [PDF].
[JP] http://www.msuiche.net/pres/psj07ruffsuiche-jp.pdf
[EN] http://www.msuiche.net/pres/PacSec07-slides-0.4.pdf
An overview of hibernation file format is explained and the forensics library we called Sandman is introduced.
Sandman status is reachable here :
http://sandman.msuiche.net/
I’ll be very interested to see how this develops, particularly into something that can be used for forensic analysis…
Thanks!
Harlan
You can see the progress of Sandman here:
http://sandman.msuiche.net/
lol du geek au bureaucrate. :)
ca paye decidement de se chier sa scolarité :D
A chacun ses finalités.