My next class:
LINUX Incident Response and Threat HuntingOnline | US EasternJan 29th - Feb 3rd 2025

OMFW 2008 reflections

Published: 2008-08-15. Last Updated: 2008-08-17 15:34:30 UTC
by Jim Clausing (Version: 2)
0 comment(s)

It was my great privilege to participate in OMFW this past Sunday afternoon in Baltimore.  Unfortunately, I wasn't able to stay for the rest of DFRWS, the program looked pretty good (more on that below) and the folks that I've talked to who were there said it was a great conference.  While I love SANS conferences, the academic in me also likes traditional conferences with peer-reviewed papers.  Back to OMFW.  AAron was able to bring together an outstanding group of folks interested in "memory forensics" and there was some spirited discussion among the participants along with some really outstanding talks/demos (hopefully, I'll be able to update this story soon with a link to the slides from the talks).  It was also great to be able to put faces to folks who until then had only been handles in IRC or names on e-mail/blog posts in the past.  Next year's DFRWS (and hopefully another OMFW) will be in Montreal.  Keep your eye on it, there is a lot of good research going on there and don't forget about the SANS Forensics Summit coming up in Vegas in October.

 

A couple of the interesting papers from DFRWS that I need to read:

http://dfrws.org/2008/proceedings/p26-dolan-gavitt.pdf

http://dfrws.org/2008/proceedings/p33-morgan.pdf

http://dfrws.org/2008/proceedings/p52-vanBaar.pdf

http://dfrws.org/2008/proceedings/p112-cohen.pdf

http://dfrws.org/2008/proceedings/p128-thonnard.pdf

 Update: (2008-08-17 15:30 UTC) The slides are here, and AAron has released volatility 1.3 (see Kevin's diary story).

 

0 comment(s)
My next class:
LINUX Incident Response and Threat HuntingOnline | US EasternJan 29th - Feb 3rd 2025

Comments


Diary Archives