OMFW 2008 reflections
It was my great privilege to participate in OMFW this past Sunday afternoon in Baltimore. Unfortunately, I wasn't able to stay for the rest of DFRWS, the program looked pretty good (more on that below) and the folks that I've talked to who were there said it was a great conference. While I love SANS conferences, the academic in me also likes traditional conferences with peer-reviewed papers. Back to OMFW. AAron was able to bring together an outstanding group of folks interested in "memory forensics" and there was some spirited discussion among the participants along with some really outstanding talks/demos (hopefully, I'll be able to update this story soon with a link to the slides from the talks). It was also great to be able to put faces to folks who until then had only been handles in IRC or names on e-mail/blog posts in the past. Next year's DFRWS (and hopefully another OMFW) will be in Montreal. Keep your eye on it, there is a lot of good research going on there and don't forget about the SANS Forensics Summit coming up in Vegas in October.
A couple of the interesting papers from DFRWS that I need to read:
http://dfrws.org/2008/proceedings/p26-dolan-gavitt.pdf
http://dfrws.org/2008/proceedings/p33-morgan.pdf
http://dfrws.org/2008/proceedings/p52-vanBaar.pdf
http://dfrws.org/2008/proceedings/p112-cohen.pdf
http://dfrws.org/2008/proceedings/p128-thonnard.pdf
Update: (2008-08-17 15:30 UTC) The slides are here, and AAron has released volatility 1.3 (see Kevin's diary story).
LINUX Incident Response and Threat Hunting | Online | US Eastern | Jan 29th - Feb 3rd 2025 |
Comments