Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
conf-presentations — Conférences de Quarkslab | Kitploit
Outils/GitHubGitHub/quarkslab/conf-presentations
Sécurité BluetoothAnalyse des VulnérabilitésRétro-ingénierieCryptographieSécurité Matériel et IoTArticles et RechercheApprentissage et ÉducationRessources OrganiséesAnalyse de Micrologiciel
GitHubquarkslab/conf-presentations

conf-presentations

Conférences de Quarkslab

318344il y a 10 joursVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Voir le dépôtSite web

Table des matières

  • Conférences et séminaires Quarkslab
  • Publications Quarkslab dans des revues ou actes de conférences et préprints
  • Publications Quarkslab dans des magazines spécialisés
  • CTF matériels Quarkslab

Conférences et séminaires Quarkslab

2026

  • 2026-08: Glitch me et glitch moi sont dans une auto 🖥️ à Barbhack 2026
  • 2026-06: SightHouse 🖥️ à PTS26
  • 2026-06: SightHouse Workshop 🖥️ atelier à PTS26
  • 2026-06: Pwning bluetooth devices in unexpected ways 🖥️ à leHack26
  • 2026-06: LeHack 117 : Permis d’illuminer toute la ville 🖥️ à leHack26
  • 2026-06: Hacking Bluetooth Low Energy Devices with WHAD 🖥️ atelier à leHack26
  • 2026-06: Introduction à l’instrumentation dynamique binaire avec QBDI 🖥️ atelier à leHack26
  • 2026-06: Apkpatcher: Reverse Engineering and Modifying Android Applications Without Rooting 🖥️ atelier à leHack26
  • 2026-05: Spyware à louer 🖥️ à RESSI 2026
  • 2026-05: Chain of Thought F's everybody 🖥️ à THCon 2026
  • 2026-04: Breaking the Backbone of Global ISP Networks 🖥️ à DefCon 2026
  • 2026-04: Breaking the Backbone of Global ISP Networks 🖥️ à Zer0con 2026
  • 2026-03: Hash All The Things / Get All the Sig(s) - Introducing Sighthouse for Seamless Function Detection 🖥️ à RE//verse 2026

2025

  • 2025-10: T'as vu mes docs ? Je les fais avec typst ! 🖥️📽️ à Volcamp
  • 2025-09: Bypassing ASLR on MIPS32 using simple mathematics 🖥️ à Wine Rump
  • 2025-09: Bluetooth Low Energy hacking with WHAD 🖥️ atelier à BruCon
  • 2025-07: Experimental Study of Binary Diffing Resilience on Obfuscated Programs 🖥️📜 à 22nd Conference on Detection of Intrusions and Malware & Vulnerability Assessment, DIMVA 2025
  • 2025-07: The Last Resort: Debugging Embedded Systems with Unconventional Methods 🖥️📽️ à Pass the SALT 2025
  • 2025-07: Bluetooth Low Energy hacking with WHAD 🖥️ atelier à Pass the SALT 2025
  • 2025-07: Wirego, a Wireshark plugin development framework 🖥️📽️ à Pass the SALT 2025

2024

  • 2024-12: Identifying Obfuscated Code through Graph-Based Semantic Analysis of Binary Code 🖥️📜 à Complex Networks 2024
  • 2024-12: Invited talk: MIFARE Classic: exposing the static encrypted nonce variant... and a few hardware backdoors 📽️ à COSIC Seminar, KUL
  • 2024-12: Faster Signatures from MPC-in-the-Head 📜 à Asiacrypt 2024
  • 2024-11: Invited talk: MIFARE Classic: exposing the static encrypted nonce variant... and a few hardware backdoors 🖥️📜📽️ à C&ESAR 2024 by DGA
  • 2024-11: Improving binary diffing through similarity and matching intricacies 🖥️📜 à CAID: Conference on Artificial Intelligence for Defense
  • 2024-11: Invited talk: MIFARE Classic: exposing the static encrypted nonce variant 🖥️📽️ à Grehack 2024
  • 2024-10: à

2023- 2023-11 : Google Apps Script - this talk requires access to your e-mails 🖥️📽️ à GreHack 2023

  • 2023-11 : Breaking Secure Boot on the Silicon Labs Gecko platform 🖥️📽️ à Ekoparty 2023
  • 2023-11 : Breaking Secure Boot on the Silicon Labs Gecko platform 🖥️📽️ à Hardwear.io NL 2023
  • 2023-11 : Dissecting the Modern Android Data Encryption Scheme 🖥️📽️ à Hardwear.io NL 2023
  • 2023-11 : On the All UR are to be considered harmful for fun and profit is the new cool trick, hackers hate it. Redux. 🖥️📽️ à Ekoparty 2023
  • 2023-10 : Intel SGX assessment methodology 🖥️ à Azure Confidential Computing 2023
  • 2023-10 : Pyrrha: navigate easily into your system binaries 🖥️📽️ à Hack.lu 2023
  • 2023-09 : Fuzzing ntop 🖥️ à

2022

  • 2022-11 : Attack on Titan M, Reloaded: Vulnerability Research on a Modern Security Chip 🖥️📽️ à Ekoparty 2022
  • 2022-11 : kdigger 📽️ à DefCon Paris meetup
  • 2022-11 : Quokka - A Fast and Accurate Binary Exporter 🖥️📽️ à Grehack 2022
  • 2022-10 : From Offensive to Defensive Security 🖥️ à Les Assises 2022
  • 2022-10 : A journey of fuzzing Nvidia graphic driver leading to LPE exploitation 🖥️📽️ à Hexacon 2022
  • 2022-09 : Symbolic Execution the Swiss-Knife of the Reverse Engineering Toolbox 🖥️📽️ à KLEE Workshop 2022
  • 2022-08 : Attack on Titan M, Reloaded 🖥️📽️ à Black Hat USA 2022

2021

  • 2021-11 : Wookey: Episode VII - The Force Awakens 🖥️📽️ à GreHack 2021
  • 2021-11 : Windows kernel snapshot-based fuzzing: the good, the bad and the ugly 📽️ à GreHack 2021
  • 2021-11 : Reversing And Fuzzing The Google Titan M Chip 🖥️📜 à ROOTS 2021
  • 2021-11 : From source code to crash test-cases through software testing automation 🖥️📜 à C&ESAR 2021
  • 2021-11 : 2021: A Titan M Odyssey 🖥️📜📽️ à Black Hat Europe 2021
  • 2021-10 : EEPROM - It will all End in Tears (EN) 🖥️📽️ à Hardwear.io NL 2021

2020- 2020-11 : Vers une proposition de boîte blanche asymétrique 📜 à Journées Codage & Cryptographie 2020

  • 2020-11 : Participation au panel « RFID Hacking » 📽️ à PACSEC 2020
  • 2020-10 : Techniques d'instrumentation binaire dynamique pour contrer l'obfuscation de code natif 🖥️📜📽️ à Black Hat Asia 2020
  • 2020-09 : Anomalie de sécurité sur une JCard EAL6+ en marge d'1 CSPN inter-CESTI 📽️ à webinaire de l'OSSIR
  • 2020-08 : Attaques par collision contre les whiteboxes avec QBDI 🖥️ à Barbhack 2020
  • 2020-07 : Construire des whiteboxes : attaques et défenses 🖥️📽️ à webinaire Hardwear.io
  • 2020-06 : Pourquoi Frida et QBDI forment un excellent duo sur Android ? 🖥️📽️ à Pass the SALT 2020
  • 2020-06 : Reverse engineering de firmware brut : un outil pour démarrer 📽️ à

2019

  • 2019-11 : Cryptographie et attaques matérielles : Application à la cryptographie en boîte blanche 🖥️ à GeeksAnonymes, ULiège
  • 2019-11 : Epona and the Obfuscation Paradox: Transparent for Users and Developers, a Pain for Reverser 🖥️📜 à SPRO 2019
  • 2019-09 : When C++ Zero-Cost Abstraction Fails: how-to Fix Your Compiler 📽️ à CppCon 2019
  • 2019-08 : Breaking Samsung's ARM TrustZone 🖥️📽️ à Black Hat USA 2019
  • 2019-06 : IDArling, la première plateforme de rencontre entre reversers 🖥️📽️ à SSTIC 2019
  • 2019-05 : Grey-box attacks, four years later 🖥️ à WhibOx 2019
  • 2019-05 : DKOM 3.0: Hiding and Hooking with Windows Extension Hosts 🖥️📽️ à

2018

  • 2018-11 : ROPGenerator: practical automated ROP-Chain generation 📽️ à GreHack 2018
  • 2018-11 : Vulnerability Research - What It Takes to Keep Going and Going and Going 🖥️ à HITB 2018 Beijing
  • 2018-09 : AFL, QBDI And KSE Are on a Boat 📽️ à Ekoparty 2018
  • 2018-09 : Old New Things: An Examinsation of the Philips TriMedia Architecture 📽️ à Ekoparty 2018
  • 2018-09 : C++ In the Elvenland 📽️ à CppCon 2018
  • 2018-09 : Easy::Jit : A Just-in-Time compilation library for C++ 🖥️📽️ à CppCon 2018
  • 2018-09 : Frozen Data Structures in C++14 📽️ à CppCon 2018
  • 2018-09 : Combining obfuscation and optimizations in the real world 📜 à SCAM 2018
  • 2018-08 : The Windows Notification Facility: Peeling the Onion of the Most Undocumented Kernel Attack Surface Yet 📽️ à

2017

  • 2017-12 : Implementing an LLVM based Dynamic Binary Instrumentation framework 🖥️📽️ à 34th Chaos Communication Congress
  • 2017-12 : How to drift with any car 📽️ à 34th Chaos Communication Congress
  • 2017-11 : Flash dumping & hardware 101 🖥️ à BlackHoodie 2017 #3
  • 2017-11 : Kernel Shim Engine for fun 🖥️ à BlackHoodie 2017 #3
  • 2017-10 : Challenges building an LLVM-based obfuscator 🖥️📽️ à 2017 LLVM Developers' Meeting
  • 2017-09 : L'interpréteur Python, quel sale type 🖥️📽️ à PyConFR 2017
  • 2017-07 : LIEF: Library to Instrument Executable Formats 🖥️📽️ à RMLL 2017
  • 2017-06 : Playing with Binary Analysis: Deobfuscation of VM based software protection / Désobfuscation binaire : Reconstruction de fonctions virtualisées 🖥️ à

2016

  • 2016-12 : Practical Attacks Against White-Box Crypto Implementations 🖥️ à Séminaire de Cryptographie, Université de Rennes 1
  • 2016-11 : Arybo : Manipulation, Canonicalization and Identification of Mixed Boolean-Arithmetic Symbolic Expressions 📜📽️ à GreHack 2016
  • 2016-11 : How Triton can help to reverse virtual machine based software protections 🖥️📽️ à CSAW 2016
  • 2016-11 : Ghost in the PLC: Designing an Undetectable Programmable Logic Controller Rootkit via Pin Control Attack 🖥️📜📽️ à Black Hat Europe 2016
  • 2016-10 : Defeating MBA-based Obfuscation 🖥️📜 à SPRO 2016
  • 2016-10 : Binary Permutation Polynomial Inversion and Application to Obfuscation Techniques 📜 à

2015- 2015-10 : Building, Testing and Debugging a Simple out-of-tree LLVM Pass 🖥️📽️ à LLVM dev meeting

  • 2015-09 : Some technical & scientific challenges I'd like to have working solutions for 🖥️ à SAS 2015
  • 2015-06 : IRMA : Incident Response and Malware Analysis 🖥️📜📽️ à SSTIC 2015
  • 2015-06 : Analyse de sécurité de technologies propriétaires SCADA 🖥️📜📽️ à SSTIC 2015
  • 2015-06 : Quatre millions d'échanges de clés par seconde 🖥️📜📽️ à SSTIC 2015
  • 2015-06 : Triton: Concolic Execution Framework 🖥️📜📽️ à

2014

  • 2014-10 : USB Fuzzing : approaches and tools 🖥️ à Hack.lu 2014
  • 2014-07 : Software obfuscation: know your enemy 🖥️📽️ à RMLL 2014
  • 2014-06 : Désobfuscation de DRM par attaques auxiliaires 🖥️📜 à SSTIC 2014
  • 2014-06 : Obfuscation de code Python : amélioration des techniques existantes 🖥️📜 à SSTIC 2014
  • 2014-06 : Reconnaissance réseau à grande échelle : port scan is not dead 📜 à SSTIC 2014
  • 2014-06 : Recherche de vulnérabilités dans les piles USB : approches et outils 🖥️📜📽️ à

2013

  • 2013-10 : How Apple Can Read Your iMessages and How You Can Prevent It 🖥️📽️ à HITB 2013 Kuala Lumpur
  • 2013-06 : Sécurité des applications Android constructeurs et réalisation de backdoors sans permission 🖥️📜 à SSTIC 2013
  • 2013-06 : UEFI and Dreamboot 🖥️📜 à SSTIC 2013
  • 2013-04 : Dreamboot - A UEFI Bootkit 📽️ à HITB 2013 Amsterdam

2012

  • 2012-10 : Pwn@Home: An Attack Path to jailbreaking your home router 🖥️ à HITB 2012 Kuala Lumpur
  • 2012-05 : WinRT: The Metro-politan Museum of Security 📽️ à HITB 2012 Amsterdam
  • 2012-06 : WinRT 🖥️📜 à SSTIC 2012
  • 2012-06 : 10 ans de SSTIC 🖥️ à SSTIC 2012

Publications Quarkslab dans des revues ou actes de conférences et preprints

2026

  • 2026-04 : Deobfuscation as a GNN-Based Graph-Edit Problem by Reinforcement Learning 📜

2025

  • 2025-09 : Identifying obfuscated code through graph-based semantic analysis of binary code 📜
  • 2025-07 : Experimental Study of Binary Diffing Resilience on Obfuscated Programs 📜

2024

  • 2024-12 : Identifying Obfuscated Code through Graph-Based Semantic Analysis of Binary Code 📜
  • 2024-12 : Faster Signatures from MPC-in-the-Head 📜
  • 2024-11 : Improving binary diffing through similarity and matching intricacies 📜
  • 2024-08 : MIFARE Classic: exposing the static encrypted nonce variant 📜
  • 2024-02 : Short Signatures from Regular Syndrome Decoding, Revisited 📜

2023

  • 2023-06 : Rétro-ingénierie et détournement de piles protocolaires embarquées, un cas d'étude sur le système ESP32 📜
  • 2023-06 : Exploring OpenSSL Engines to Smash Cryptography 📜
  • 2023-05 : ESPwn32: Hacking with ESP32 System-on-Chips 📜
  • 2023-05 : PASTIS - A Collaborative Approach to Combine Heterogeneous Software Testing Techniques 📜

2022

  • 2022-06 : TPM is not the holy way 📜
  • 2022-04 : Building a Commit-level Dataset of Real-world Vulnerabilities 📜(alt📜)

2021

  • 2021-11 : From Source Code to Crash Test-Case through Software Testing Automation 📜
  • 2021-11 : Reversing and Fuzzing the Google Titan M Chip 📜
  • 2021-08 : SSE and SSD : Page-Efficient Searchable Symmetric Encryption 📜(alt📜)
  • 2021-06 : Unlinkable and Invisible γ-Sanitizable Signatures 📜(alt📜)
  • 2021-06 : Exploitation du graphe de dépendance d'AOSP à des fins de sécurité 📜
  • 2021-06 : EEPROM : It Will All End in Tears 📜
  • 2021-11 : 2021 : A Titan M Odyssey 📜
  • 2021-08 : Greybox Program Synthesis : A New Approach to Attack Obfuscation 📜

2020

  • 2020-07 : Toward an Asymmetric White-Box Proposal 📜
  • 2020-06 : Fuzz and Profit with WHVP 📜
  • 2020-06 : Inter-CESTI : Methodological and Technical Feedbacks on Hardware Devices 📜
  • 2020-02 : QSynth - A Program Synthesis based approach for Binary Code Deobfuscation 📜

2019

  • 2019-11 : Epona and the Obfuscation Paradox : Transparent for Users and Developers, a Pain for Reversers 📜
  • 2019-10 : White-Box Cryptography : Don't Forget About Grey-Box Attacks 📜

2018

  • 2018-09 : Combining obfuscation and optimizations in the real world 📜
  • 2018-07 : Quadratic Time Algorithm for Inversion of Binary Permutation Polynomials 📜(alt📜)
  • 2018-06 : Attacking serial flash chip : case study of a black box device 📜
  • 2018-06 : Symbolic Deobfuscation : From Virtualized Code Back to the Original 📜(alt📜)
  • 2018-04 : Easy::Jit : compiler assisted library to enable just-in-time compilation in C++ codes 📜

2017

  • 2017-06 : Reconstruction de fonctions virtualisées 📜

2016

  • 2016-11 : Arybo : Manipulation, Canonicalization and Identification of Mixed Boolean-Arithmetic Symbolic Expressions 📜
  • 2016-10 : Binary Permutation Polynomial Inversion and Application to Obfuscation Techniques 📜(alt📜)
  • 2016-10 : Defeating MBA-based Obfuscation 📜(alt📜)
  • 2016-11 : Ghost in the PLC: Designing an Undetectable Programmable Logic Controller Rootkit via Pin Control Attack 📜
  • 2016-08 : Differential computation analysis: Hiding your white-box designs is not enough 📜
  • 2016-08 : Collecting relations for the Number Field Sieve in $GF(p^6)$ 📜
  • 2016-06 : Design de cryptographie white-box : et à la fin, c'est Kerckhoffs qui gagne 📜
  • 2016-02 : NFLlib: NTT-Based Fast Lattice Library 📜

2015

  • 2015-06 : IRMA : Incident Response and Malware Analysis 📜
  • 2015-06 : Analyse de sécurité de technologies propriétaires SCADA 📜
  • 2015-06 : Triton: Concolic Execution Framework 📜
  • 2015-06 : Quatre millions d'échanges de clés par seconde 📜

2014

  • 2014-06 : Désobfuscation de DRM par attaques auxiliaires 📜
  • 2014-06 : Obfuscation de code Python : amélioration des techniques existantes 📜
  • 2014-06 : Reconnaissance réseau à grande échelle : port scan is not dead 📜
  • 2014-06 : Recherche de vulnérabilités dans les piles USB : approches et outils 📜

2013

  • 2013-06 : Sécurité des applications Android constructeurs et réalisation de backdoors sans permission 📜
  • 2013-06 : UEFI and Dreamboot 📜

2012

  • 2012-06 : WinRT 📜

Publications Quarkslab dans des magazines spécialisés

  • 2024-03 : Comprendre et manipuler les mécanismes d’isolation des conteneurs 📜 Dans MISC Numéro 132
  • 2023-05 : Bug Bounty, Quand les hackers deviennent chasseurs de primes ! 📜 Dans MISC Numéro 127
  • 2023-03 : Comment attaquer un port USB ? 📜 Dans MISC Numéro 126 (en accès libre)
  • 2023-01 : Dossier: Web 2023, Les nouvelles surfaces d'attaques ! 📜 Dans MISC Numéro 125
  • 2022-11 : Découverte de Fuchsia et analyses préliminaires du Google Nest Hub 📜 Dans MISC Numéro 124
  • 2022-10 : Isoler ses ressources MS Azure 📜 Dans MISC Numéro HS 26
  • 2022-10 : Les nouveautés de sécurité de Kubernetes 📜 Dans MISC Numéro HS 26
  • 2022-10 : Bienvenue chez les cLoud 📜 Dans MISC Numéro HS 26
  • 2022-03 : La compilation statique démythifiée - Une plongée dans les entrailles de mon compilo 📜 Dans MISC Numéro 120 (en accès libre)
  • 2021-09 : Comment analyser un programme : du statique au dynamique jusqu'à l'instrumentation 📜 Dans MISC HS Numéro 24
  • 2021-09 : Introduction au reverse hardware 📜 Dans MISC HS Numéro 24 (en accès libre)
  • 2021-09 : De l'extraction de firmware à l'exécution de code sur la carte SD FlashAir 📜 Dans MISC HS Numéro 24

CTFs matériels Quarkslab- 2025-05 : Hardware CTF v7 🖥️ à Hardwear.io USA 2025. Résultats sur CTFtime.

  • 2024-10 : Hardware CTF v7 🖥️ à Hardwear.io NL 2024. Résultats sur CTFtime.
  • 2024-05 : Hardware CTF v6 🖥️ à Hardwear.io USA 2024. Résultats sur CTFtime.
  • 2023-11 : Hardware CTF v6 🖥️ à Hardwear.io NL 2023. Résultats sur CTFtime.
  • 2023-06 : Hardware CTF v5 🖥️ à Hardwear.io USA 2023. Résultats sur CTFtime.
  • 2022-10 : Hardware CTF v5 🖥️ à Hardwear.io NL 2022. Résultats sur CTFtime.
  • 2022-09 : Hardware CTF v4 🖥️ à Nullcon Goa 2022. Résultats sur CTFtime.
  • 2022-06 : Hardware CTF v4 🖥️ à Hardwear.io USA 2022. Résultats sur CTFtime.
  • 2021-10 : Hardware CTF v4 🖥️ à . Résultats sur .
Télécharger l’outil
  • 2025-07: Apkpatcher: Reverse Engineering and Modifying Android Applications Without Rooting 🖥️ atelier à Pass the SALT 2025
  • 2025-06: Abusing Domestic EV Chargers through Bluetooth and USB 🖥️ à Recon.cx 2025
  • 2025-06: Apkpatcher: Reverse Engineering and Modifying Android Applications Without Rooting 🖥️ atelier à LeHack 2025
  • 2025-06: The Last Resort: Debugging Embedded Systems with Unconventional Methods 🖥️ à LeHack 2025
  • 2025-06: Fun with watches: hacking a 12€ smartwatch with Bluetooth Low Energy and 3 wires 🖥️ à LeHack 2025
  • 2025-06: Pyrrha & Friends: Diving into Firmware Cartography 🖥️📽️ à SSTIC 2025
  • 2025-06: We Have A Deal: we provide the lego bricks, you build cool wireless attacks 🖥️📜📽️ à SSTIC 2025
  • 2025-06: Wirego - Un framework de développement de plugins Wireshark 🖥️📜📽️ à SSTIC 2025
  • 2025-06: apkpatcher : Fast analysis and modification to Android applications without root access or emulation 🖥️📽️ à SSTIC 2025
  • 2025-05: Spyware for Rent & The World of Offensive Cyber 🖥️📽️ à Off-by-One 2025
  • 2025-05: S.H.I.E.L.D: Scudo Heap Implementation Exploits, Leaks, and Defenses 🖥️📽️ à Off-by-One 2025
  • 2025-04: Test your Cryptographic Primitives with Crypto-Condor 🖥️ à Real World Cryptography Paris Meetups
  • 2025-04: One for all and all for WHAD: wireless shenanigans made easy ! 🖥️📽️ à THCon 2025
  • 2025-03: 0day in CTF is cool, no? (Writeup PwnMe 2025) 🖥️ à Meetup Hack The Box France
  • 2025-03: Streamlining Firmware Analysis with Inter-Image Call Graphs and Decompilation 🖥️📽️ à RE/verse.io 2025
  • Bluetooth Low Energy GATT Fuzzing: from specification to implementation 🖥️
    📜
    📽️
    Hardwear.io NL 2024
  • 2024-10: MIFARE Classic: exposing the static encrypted nonce variant 🖥️📽️ à Hardwear.io NL 2024
  • 2024-10: Spyware for Rent 🖥️ à Les Assises 2024
  • 2024-08: De 'branch' en 'branch' : récupération d'un FW d'ECU sur une mémoire FAT 'nettoyée' 🖥️ à Barbhack 2024
  • 2024-08: One for all and all for WHAD: wireless shenanigans made easy ! 🖥️📽️ à DEF CON 32
  • 2024-08: Attacking Samsung Galaxy A * Boot Chain, and Beyond 🖥️ à Black Hat USA 2024
  • 2024-07: Prism, a light BEAM disassembler 🖥️ à LeHack 2024
  • 2024-07: Analysing malicious documents and files with oletools 🖥️📽️ à Pass the SALT 2024
  • 2024-07: Rump: Passbolt: a bold use of HaveIBeenPwned 🖥️📽️ à Pass the SALT 2024
  • 2024-07: Rump: How to download large datasets of files using CommonCrawl 🖥️📽️ à Pass the SALT 2024
  • 2024-07: Hydradancer, using USB3 to improve USB hacking with Facedancer 🖥️📽️ à Pass the SALT 2024
  • 2024-07: Test your cryptographic primitives with crypto-condor 🖥️📽️ à Pass the SALT 2024
  • 2024-07: Prism, a light BEAM disassembler 🖥️📽️ à Pass the SALT 2024
  • 2024-06: Attacking the Samsung Galaxy Boot Chain 🖥️ à Off-by-One 2024
  • 2024-06: Belenios: the Certification Campaign 🖥️📜📽️ à SSTIC 2024
  • 2024-06: Tame the (q)emu: debug firmware on custom emulated board 🖥️📜📽️ à SSTIC 2024
  • 2024-06: PyAxml 🖥️📽️ à SSTIC 2024
  • 2024-06: When Samsung meets Mediatek: the story of a small bug chain 🖥️📜📽️ à SSTIC 2024
  • 2024-06: QBinDiff: A modular differ to enhance binary diffing and graph alignment 🖥️📽️ à SSTIC 2024
  • 2024-06: Testez vos primitives cryptographiques avec crypto-condor 🖥️📽️ à SSTIC 2024
  • 2024-05: Numbat/Pyrrha: Naviguez facilement dans les binaires de votre système 🖥️ à ESIEA Secure Edition 2024
  • 2024-05: Finding low-hanging fruits vulnerabilities in a commercial antivirus 🖥️ à StHack 2024
  • 2024-05: Attacking the Samsung Galaxy A * Boot Chain 🖥️📽️ à OffensiveCon 2024
  • 2024-04: PASTIS: Fuzzing tool competition 🖥️ à SBFT 2024
  • 2024-03: Finding low-hanging fruits vulnerabilities in a commercial antivirus 🖥️ à HackSecuReims 2024
  • 2024-03: How automatisation can improve firmware analysis? 🖥️ à Forum InCyber 2024
  • 2024-03: Spyware for Rent 🖥️📽️ à NullCon 2024
  • 2024-01: FCSC Chaussette - A Triton showcase 🖥️ à Ambrosia 2024
  • 📽️
    ntopconf 2023
  • 2023-08 : Introduction au CarHacking Comment construire sa “Car-in-a-box” 🖥️ atelier à Barbhack 2023
  • 2023-08 : Emulation de périphérique USB-ETH pour l'audit IoT/Automotive 🖥️ à Barbhack 2023
  • 2023-07 : Map your Firmware! 🖥️📽️ à Pass the SALT 2023
  • 2023-07 : For Science! - Using an Unimpressive Bug in EDK II To Do Some Fun Exploitation 🖥️📽️ à Pass the SALT 2023
  • 2023-07 : Vulnerabilities in the TPM 2.0 reference implementation code 🖥️📽️ à Pass the SALT 2023
  • 2023-06 : Parasitizing servers for fun and profit 🖥️📽️ à LeHack 2023
  • 2023-06 : Vulnerabilities in the TPM 2.0 Reference Implementation Code 🖥️📽️ à Troopers 2023
  • 2023-06 : Google Apps Script 🖥️ à ESIEA Secure Edition 2023
  • 2023-06 : Who evaluates the evaluators ? 🖥️📜 à WRACH 2023
  • 2023-06 : Dissecting the Modern Android Data Encryption Scheme 🖥️📽️ à Recon 2023
  • 2023-06 : Trace-based approach to compiler debugging 🖥️ à GDR GPL National Days 2023
  • 2023-06 : Exploring OpenSSL Engines to Smash Cryptography 🖥️📜📽️ à SSTIC 2023
  • 2023-06 : peetch: an eBPF based Networking Tool 🖥️📽️ à SSTIC 2023
  • 2023-06 : Rétro-ingénierie et détournement de piles protocolaires embarquées 🖥️📜📽️ à SSTIC 2023
  • 2023-05 : ESPwn32: Hacking with ESP32 System-on-Chips 🖥️📜📽️ à WOOT 2023
  • 2023-05 : Emulating RH850 for fun and vulnerability research 🖥️ à QPSS2023
  • 2023-05 : PASTIS - A Collaborative Approach to Combine Heterogeneous Software Testing Techniques 🖥️📜 à SBFT2023
  • 2023-05 : For Science! - Using an Unimpressive Bug in EDK II To Do Some Fun Exploitation 🖥️📽️ à StHack 2023
  • 2023-05 : Trying to break randomness with statistics in less than 5minutes 🖥️ à StHack 2023
  • 2023-04 : Reflections on Supply chain security 🖥️ à CERT Vendor Conference 2023
  • 2023-04 : Weaponizing ESP32 RF Stacks 🖥️📽️ à THCon 2023
  • 2023-03 : Whatever Pown2own 🖥️📽️ à Insomni'hack 2023
  • 2023-03 : Traceability of the compilation process 🖥️ à CLAP-HiFi-LVP 2023
  • 2022-07 : kdigger - Kubernetes focused container assessment and context discovery tool for penetration testing 🖥️📽️ à Pass the SALT 2022
  • 2022-07 : Binbloom Reloaded 🖥️📽️ à Pass the SALT 2022
  • 2022-07 : Mattermost End-to-End Encryption Plugin 🖥️📽️ à Pass the SALT 2022
  • 2022-06 : Attack on Titan M: Vulnerability Research on a Modern Security Chip 🖥️📽️ à Troopers 2022
  • 2022-06 : So you hacked a WiFi router, and now what? 📽️ à LeHack 2022
  • 2022-06 : Augmenter votre résistance aux malwares en recyclant vos vielles machines en stations blanches et plus si affinités 📽️ à FIC 2022
  • 2022-06 : TPM is not the holy way 🖥️📜📽️ à SSTIC 2022
  • 2022-06 : Binbloom v2 - Ceci est une (r)evolution 🖥️📽️ à SSTIC 2022
  • 2022-05 : Hackers, Reprenez Le Contrôle Des Objets Connectés ! 📽️ à Mixit 2022
  • 2022-05 : When eBPF meets TLS! 🖥️ à CanSecWest 2022
  • 2022-05 : kdigger - A Context Discovery Tool for Kubernetes Penetration Testing 🖥️ à Black Hat Asia 2022
  • 2022-04 : Can you park a car in a classroom? 📽️ à Hardwear.io webinar
  • 2022-04 : Building a Commit-level Dataset of Real-World Vulnerabilities 🖥️📜📽️ à CODASPY 2022
  • 2021-08 : SSE and SSD : Page-Efficient Searchable Symmetric Encryption 📜📽️ à CRYPTO 2021
  • 2021-08 : Greybox Program Synthesis: A New Approach to Attack Dataflow Obfuscation 🖥️📜📽️ à Black Hat USA 2021
  • 2021-07 : Meet Piotr, a firmware emulation tool for trainers and researchers 🖥️📽️ à Pass the SALT 2021
  • 2021-06 : Unlinkable and Invisible γ-Sanitizable Signatures 📜 à Applied Cryptography and Network Security ACNS 2021
  • 2021-06 : Exploitation du graphe de dépendance d'AOSP à des fins de sécurité 🖥️📜📽️ à SSTIC 2021
  • 2021-06 : EEPROM - It Will All End in Tears 🖥️📜📽️ à SSTIC 2021
  • 2021-06 : QBDL - QuarkslaB Dynamic Loader 🖥️📽️ à SSTIC 2021
  • webinaire Hardwear.io
  • 2020-06 : Inter-CESTI : retours méthodologiques et techniques sur les évaluations de dispositifs matériels 🖥️📜📽️ à SSTIC 2020
  • 2020-06 : Fuzz and Profit with WHVP 🖥️📜📽️ à SSTIC 2020
  • 2020-02 : QSynth - Une approche de synthèse de programmes pour la désobfuscation de code binaire 🖥️📜 à Binary Analysis Research (BAR) Workshop 2020
  • 2020-02 : Sauvegardes de serveur auto-hébergées pour les paranoïaques 📽️ à FOSDEM 2020
  • Infiltrate 2019
  • 2019-04 : Fuzzing de binaires à l'aide de l'instrumentation dynamique 🖥️ à French-Japan cybersecurity workshop 2019
  • 2019-04 : Techniques de whitebox basées sur des tables appliquées à la cryptographie sur réseaux : vers une proposition de boîte blanche asymétrique ? 🖥️ à WRACH 2019
  • 2019-03 : Old New Things: An examination of the Philips TriMedia architecture 🖥️📽️ à Troopers 2019
  • 2019-01 : Contrôle de passes à grain fin pour l'obfuscation de code 🖥️ à Journées de la Compilation 2019
  • Black Hat USA 2018
  • 2018-07 : Quadratic Time Algorithm for Inversion of Binary Permutation Polynomials 📜 à ICMS 2018
  • 2018-07 : Instrumentation statique basée sur les formats de fichiers exécutables 🖥️📽️ à Pass the SALT 2018
  • 2018-06 : Désobfuscation symbolique : du code virtualisé vers l'original 🖥️📜 à 15th Conference on Detection of Intrusions and Malware & Vulnerability Assessment, DIMVA 2018
  • 2018-06 : Instrumentation statique basée sur les formats de fichiers exécutables 🖥️📽️ à Recon 2018
  • 2018-06 : Attacking Serial Flash Chip: Case Study of a Black Box 📜📽️ à SSTIC 2018
  • 2018-04 : Implementing an LLVM based Dynamic Binary Instrumentation framework 📽️ à Euro LLVM dev meeting
  • 2018-04 : Easy::Jit : Compiler-assisted library to enable Just-In-Time compilation for C++ codes 🖥️📽️ à Euro LLVM dev meeting
  • 2018-04 : DragonFFI: Foreign Function Interface and JIT using Clang/LLVM 🖥️📽️ à Euro LLVM dev meeting
  • 2018-04 : Automatizing vulnerability research to better face new software security challenges 🖥️ à Cisco Innovation & Research Symposium 2018
  • 2018-02 : Surviving in an Open Source Niche: the Pythran case 📽️ à FOSDEM 2018
  • 2018-02 : Literate Programming meets LLVM Passes 📽️ à FOSDEM 2018
  • 2018-02 : Easy::jit : just-in-time compilation for C++ 🖥️📽️ à FOSDEM 2018
  • 2018-02 : DragonFFI Foreign Function Interface and JIT using Clang/LLVM 🖥️📽️ à FOSDEM 2018
  • 📜
    📽️
    SSTIC 2017
  • 2017-04 : LIEF: Library to Instrument Executable Formats 🖥️ à Third French Japanese Meeting on Cybersecurity
  • 2017-04 : Ma vie, mon œuvre, et le cyber 🖥️ à 92ème séminaire d’intelligence économique
  • 2017-03 : Playing with Binary Analysis: Deobfuscation of VM based software protection 📽️ à THCon 2017
  • SPRO 2016
  • 2016-10 : GAST, Daou Naer - AST pour Python 2 et 3 📽️ à PyConFR 2016
  • 2016-09 : C++ Costless Abstractions: the compiler view 🖥️📽️ à CppCon 2016
  • 2016-08 : Differential computation analysis: Hiding your white-box designs is not enough 🖥️📜📽️ à CHES 2016
  • 2016-07 : Practical Attacks Against White-Box Crypto Implementations 🖥️ atelier à ECRYPT-NET Workshop on Cryptography Design for the IoT
  • 2016-07 : Binmap: scanning file systems with Binmap 🖥️📽️ à RMLL Security track 2016
  • 2016-06 : Design de cryptographie white-box : et a la fin, c'est Kerckhoffs qui gagne 🖥️📜📽️ à SSTIC 2016
  • 2016-04 : Dynamic Binary Analysis and Obfuscated Codes 🖥️ à StHack 2016
  • 2016-03 : Building, Testing and Debugging a Simple out-of-tree LLVM Pass 🖥️📽️ à Euro LLVM 2016
  • 2016-03 : Hiding your White-Box Designs is Not Enough 🖥️📽️ à Troopers 2016
  • SSTIC 2015
  • 2015-05 : Supervising the Supervisor: Reversing Proprietary SCADA Tech. 📜 à HITB 2015 Amsterdam
  • 2015-03 : Dynamic Binary Analysis and Instrumentation Covering a function using a DSE approach 🖥️ à StHack 2015
  • 2015-01 : Dynamic Binary Analysis and Instrumentation Covering a function using a DSE approach 🖥️📽️ à Security Day 2015
  • 2015-01 : Keynote 📽️ à Security Day 2015
  • SSTIC 2014
  • 2014-05 : Port scan is not for pussies, Know yourself, know your enemy 🖥️ à HITB 2014 Amsterdam
  • 2021-09 : La compilation : du code au binaire... et retour ! 📜 Dans MISC HS Numéro 24 (en accès libre)
  • 2021-09 : Vulnérabilités, Binary Diffing et Crashs 📜 Dans MISC Numéro 117
  • 2021-07 : Un EDR sous Android ? 📜 Dans MISC Numéro 116 (en accès libre)
  • 2021-03 : Découverte de la puce Titan M a.k.a Citadel 📜 Dans MISC Numéro 114 (en accès libre)
  • 2020-11 : Orchestration d'analyse 📜 Dans MISC Numéro 112 (en accès libre)
  • 2020-11 : Grandeur et décadence de Kubernetes : attaquer le futur Cloud OS 📜 Dans MISC Numéro 112 (en accès libre)
  • 2020-05 : Introduction à QBDI et ses bindings Python 📜 Dans MISC Numéro 109
  • 2020-05 : Faciliter la création d'exploits avec DragonFFI : le cas de CVE-200977-18 📜 Dans MISC Numéro 109 (en accès libre)
  • 2019-07 : Exploitation du CVE-200977-18 dans le noyau Windows 📜 Dans MISC Numéro 104
  • 2019-03 : Analyse du contournement de KTRR 📜 Dans MISC Numéro 102 (en accès libre)
  • 2017-09 : Voyages en C++ie : les symboles 📜 Dans MISC Numéro 93 (en accès libre)
  • 2017-07 : Anti-RE 101 📜 Dans MISC Numéro 92
  • Hardwear.io NL 2021
    CTFtime
  • 2020-03 : Hardware CTF v3 🖥️ à Nullcon Goa 2020. Résultats sur CTFtime.
  • 2019-09 : Hardware CTF v3 🖥️ à Hardwear.io NL 2019. Résultats sur CTFtime.
  • 2019-06 : Hardware CTF v2 🖥️ à Hardwear.io USA 2019. Résultats sur CTFtime.
  • 2019-03 : Hardware CTF v2 à Nullcon Goa 2019. Résultats sur CTFtime.
  • 2018-09 : Hardware CTF v2 🖥️ à Hardwear.io NL 2018. Résultats sur CTFtime.
  • 2018-04 : Hardware CTF v1 à HITB Amsterdam 2018. Résultats sur CTFtime.
  • 2018-03 : Hardware CTF v1 à Nullcon Goa 2018. Résultats sur CTFtime.
  • 2017-09 : Hardware CTF v1 🖥️ à Hardwear.io NL 2017. Résultats sur CTFtime.