2026
Articles de conférence
- Practical Vulnerability Triage Under Regulatory Pressure for Modern PSIRTs. In CyberOnBoard, Hyeres, French Riviera, France, 2026. www
- Witchcraft Solver: Binary-Only Vulnerability Discovery via Symbolic Execution and Directed Fuzzing. In DEF CON Conference, Las Vegas (Nevada), United States, 2026. doi www
Divers
- Beyond Reachability: Regulatory-Driven Vulnerability Triage for Production Binaries. , ACM Student Research Competition : Finals. www
Rapports
2025
Articles de conférence
- Advances in Lightweight Cross-Architecture Procedural Debugging. In 12th IFIP International Conference on New Technologies, Mobility and Security, Paris, France, 2025. www
- Automatic Functions Annotations through Concrete Procedural Debugging and ELF Libification. In The 40th ACM/SIGAPP Symposium on Applied Computing (SAC '25), March 31-April 4, 2025, Catania, Italy, Catania, Sicily (Italy), Italy, 2025. doi www
- Unstripping Cloud Container ELF binaries. In IEEE International Conference on Emerging Technologies and Computing ICETC2025, Brest, France, 2025. www
Non publié
- [Keynote] A Tale of Oxidation and Witchcraft. , Lecture. www
2024
Articles de conférence
- Toward Partial Proofs of Vulnerabilities. In 2024 IEEE Secure Development Conference (SecDev), pages 180-182, IEEE, Pittsburgh, United States, 2024. doi www
- Introduction to Procedural Debugging through Binary Libification. In Proceedings of the 18th USENIX WOOT Conference on Offensive Technologies, pages 17-25, USENIX Association, Philadelphia, PA, United States, 2024. doi www
2020
Brevets
Articles de conférence
- ATTAQUES CONTRE LES SUPPLY CHAINS, RANSOMWARE : DE LA NECESSITE DE NOUVEAUX PROCESSUS. In CESIN : Keynote 2020, Reims, France, 2020. www
- Automotive/IoT Network Exploits: From Static Analysis to Reliable Exploits. In RSA Conference, San Francisco, United States, 2020. www
- Reverse Engineering da Morte que Mata. In RoadSec Conference 2020, Sao Paolo, Brazil, 2020. www
Divers
2019
Articles de conférence
- Hardware Backdooring is practical. In Nullcon Conference 2019, Goa, India, 2019. www
2018
2017
Articles de conférence
- Silent Protest. In Shakacon Conference 2017, Honololu, Hawaii, United States, 2017. www
- Introduction to the Witchcraft Compiler Collection. In BSides San Francisco 2017, San Francisco (CA, USA), United States, 2017. www
Divers
- [SHA217/CCC] Silent Protest: DIY wearable protest network. , Recording from the SHA217 Conference, organised by the CCC. www
2016
Livres
- Witchcraft Compiler Collection : User Manual. UBM, 2016. www
Articles de conférence
- Introduction to the Witchcraft Compiler Collection. In H2HC Conference 2016, Sao Paolo, Brazil, 2016. www
- Introduction to the Witchcraft Compiler Collection. In Intel Security Conference (iSec) 2016, Hillsboro, United States, 2016. www
- Introduction to the Witchcraft Compiler Collection. In DEFCON 24, Las Vegas, United States, 2016. www
- Introduction to the Witchcraft Compiler Collection. In DEFCON 24, Las Vegas, United States, 2016. www
- The Witchcraft Compiler Collection : Towards Self Aware Computer Programs. In Blackhat Briefings (UK) 2016, London, United Kingdom, 2016. www
Divers
2015
Articles de conférence
- XXE defence(les)s in JDK XML parsers. In Blackhat USA, Las Vegas, United States, 2015. www
- Filecry : the new age of XXE. In Blackhat USA, Las Vegas, United States, 2015. www
- SMB : Sharing more than your files... In Blackhat USA, Las Vegas, United States, 2015. www
- Hardware Backdooring is Practical. In Shakacon Conference 2015, Honololu, Hawaii, United States, 2015. www
Divers
2014
2013
Articles de conférence
- Sandboxing is (the) shit !. In Hackers to Hackers Conference (H2HC) 2013, Sao Paolo, Brazil, 2013. www
- Hardware Backdooring is Practical. In AusCERT, Brisbane (AU), Australia, 2013. www
- Katsuni理论介绍以及在沙盒和软件仿真方面的应用. In Syscan 360 2013, Beijing (China), China, 2013. www
- An introduction to the Katsuni theorem and its application to sandboxing and software emulation. In Syscan Beijing, Beijin, Chine, China, 2013. www
- Malware, Sandboxing and You : How Enterprise Malware and 0day detection is about to fail (again). In RUXCON Conference 2013, Melbourne (AUS), Australia, 2013. www
Divers
2012
Articles de conférence
- Hardware Backdooring is practical. In DEFCON 20, Las Vegas, United States, 2012. www
- Hardware Backdooring is Practical. In No Such Conference 2012, Paris, France, 2012. www
- Proprietary Protocols RCE : Research leads. In RUXCON Conference Sydney Monthly 2012, Sydney (AUSTRALIA), Australia, 2012. www
- Hardware Backdooring is practical. In Blackhat Briefings (USA) 2012, Las Vegas, United States, 2012. www
- Hardware Backdooring is practical. In Blackhat Briefings (USA) 2012, Las Vegas, United States, 2012. www
- Hardware Backdooring is practical. In RUXCON Conference 2012, Melbourne (AUS), Australia, 2012. www
- Hardware Backdooring is Practical. In Nullcon Conference 2012, Goa, India, 2012. www
- Hardware Backdooring is Practical. In Intel Security Conference (iSec) 2012, Hillsboro, United States, 2012. www
- Hardware Backdooring is Practical. In Blackhat USA, Las Vegas, United States, 2012. www
- Post Memory Corruption Memory Analysis. In Chaos Communication Congress 2012, Berlin (DE), Germany, 2012. www
Divers
2011
Articles de conférence
- Post Memory Corruption Memory Analysis. In RUXCON Conference 2011, Melbourne (AUS), Australia, 2011. www
- Post Memory Corruption Memory Analysis. In Kiwicon New Zealand 2011, Wellington, New Zealand, New Zealand, 2011. www
- Post Memory Corruption Memory Analysis. In HITB Conference Kuala-Lumpur 2011, Kuala Lumpur, Malaysia, 2011. www
- Post Memory Corruption Memory Analysis. In Blackhat USA, Las Vegas, United States, 2011. www
Divers
Rapports
- Beyond Fuzzing : Exploit Automation with PMCMA. Technical Report, HITB, 2011.
2010
Articles de conférence
- Breaking virtualization by any means. In HITB Conference Kuala-Lumpur 2010, Kuala Lumpur, Malaysia, 2010. www
- Generic exploitation of invalid memory writes. In Hackers to Hackers Conference (H2HC) 2010, Sao Paolo, Brazil, 2010. www
- Breaking Virtualization by switching the CPU to 8086 mode. In Hackito Ergo Sum 2010, Paris, France, 2010. www
- Breaking Virtualization Software by switching the cpu to Virtual 8086 mode. In Hack In the Box Malaysia, Kuala Lumpur (Malaysia), Malaysia, 2010. www
- Breaking virtualization by switching the cpu to virtual 8086 mode. In RUXCON Conference 2010, Melbourne (AUS), Australia, 2010. www
- Breaking Virtualization by switching the CPU to 8086 mode. In HITB Conference Kuala-Lumpur 2010, Kuala Lumpur, Malaysia, 2010. www
- Breaking Virtualization by switching to Virtual 8086 mode. In HITB Conference Amsterdam 2010, Amsterdam (NETHERLANDS), Netherlands, 2010. www
2009
Articles de conférence
- PreBoot Authentication Password Cracking on a budget. In Hackers to Hackers Conference (H2HC) 2009, Sao Paolo, Brazil, 2009. www
- Zero crypto attacks against preboot authentication passwords. In Telecomix Conference 2009, Goteberg, Sweden, 2009. www
Divers
2008
Articles de conférence
- Reverse Engineering for exploit writers. In ClubHack, Pune, India, India, 2008. www
- Bypassing pre-boot authentication passwords by instrumenting the BIOS keyboard buffer. In DEFCON 16, Las Vegas, United States, 2008. www
- Bypassing pre-boot authentication passwords by instrumenting the BIOS keyboard buffer. In DEFCON 16, Las Vegas, United States, 2008. www