<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Systems Security on zeishr</title><link>https://theoabel.com/categories/systems-security/</link><description>Recent content in Systems Security on zeishr</description><generator>Hugo</generator><language>en-US</language><copyright>© Théo Abel</copyright><lastBuildDate>Sun, 26 Jan 2025 23:59:38 +0000</lastBuildDate><atom:link href="https://theoabel.com/categories/systems-security/index.xml" rel="self" type="application/rss+xml"/><item><title>xenith</title><link>https://theoabel.com/projects/xenith/</link><pubDate>Sun, 26 Jan 2025 23:59:38 +0000</pubDate><guid>https://theoabel.com/projects/xenith/</guid><description>&lt;p&gt;xenith is a research-focused hypervisor for Xen-based debugging, virtual machine introspection, and automation.&lt;/p&gt;
&lt;p&gt;The project explores low-level guest inspection, debugging workflows, and scripted control around virtualized targets. It is archived, but remains useful as a reference for hypervisor-backed research tooling and VMI-oriented experiments.&lt;/p&gt;</description></item><item><title>blackpill</title><link>https://theoabel.com/projects/blackpill/</link><pubDate>Thu, 19 Sep 2024 09:10:45 +0000</pubDate><guid>https://theoabel.com/projects/blackpill/</guid><description>&lt;p&gt;blackpill is a Linux rootkit research project combining a Rust kernel module, eBPF XDP/TC networking, and a custom type-2 hypervisor.&lt;/p&gt;
&lt;p&gt;It is kept as an archived research artifact around stealth, low-level control, kernel experimentation, and hypervisor-backed security research.&lt;/p&gt;</description></item><item><title>secmalloc</title><link>https://theoabel.com/projects/secmalloc/</link><pubDate>Wed, 17 Jul 2024 12:33:53 +0000</pubDate><guid>https://theoabel.com/projects/secmalloc/</guid><description>&lt;p&gt;secmalloc is a secure allocator experiment around &lt;code&gt;malloc&lt;/code&gt;, &lt;code&gt;realloc&lt;/code&gt;, and &lt;code&gt;free&lt;/code&gt;-style semantics.&lt;/p&gt;
&lt;p&gt;It is archived as a small C implementation exercise around heap allocation behavior and allocator hardening ideas.&lt;/p&gt;</description></item><item><title>mmushell</title><link>https://theoabel.com/projects/mmushell/</link><pubDate>Sun, 14 Apr 2024 15:23:05 +0000</pubDate><guid>https://theoabel.com/projects/mmushell/</guid><description>&lt;p&gt;mmushell is a substantial fork of EURECOM&amp;rsquo;s memory-forensics proof of concept.&lt;/p&gt;
&lt;p&gt;The fork added module packaging, a Nix development shell, MkDocs documentation, and cleanup around architecture/exporter boundaries. It is archived as a research and reproducibility reference.&lt;/p&gt;</description></item><item><title>libMMU</title><link>https://theoabel.com/projects/libmmu/</link><pubDate>Mon, 11 Mar 2024 19:47:23 +0000</pubDate><guid>https://theoabel.com/projects/libmmu/</guid><description>&lt;p&gt;libMMU is a Rust crate for rebuilding virtual address spaces from memory dumps.&lt;/p&gt;
&lt;p&gt;It is inspired by OS-agnostic MMU reconstruction techniques explored in &lt;code&gt;mmushell&lt;/code&gt; and related memory-forensics research. The project is archived as a research implementation reference.&lt;/p&gt;</description></item><item><title>pyDFIRRam</title><link>https://theoabel.com/projects/pydfirram/</link><pubDate>Thu, 20 Jul 2023 12:57:16 +0000</pubDate><guid>https://theoabel.com/projects/pydfirram/</guid><description>&lt;p&gt;pyDFIRRam is a Volatility 3-based Python library for scripted and notebook-driven memory-forensics workflows.&lt;/p&gt;
&lt;p&gt;It focuses on making memory analysis easier to automate, compose, and reuse from Python rather than forcing every investigation through one-off command invocations.&lt;/p&gt;</description></item></channel></rss>