Subvisor: Reading an OpenVMM Guest Without Asking It Anything
An offline tool that turns an OpenVMM snapshot into a debugger-readable memory image, recovering the guest kernel's symbols from memory with no agent and no supplied symbol file.
Hello! My name is Matt Suiche. I work on AI Security at Tolmo, and I also experiment with side projects in AI Safety (Weightless, etc.) and Emulation & Operating System Research (WASM PSX, WASM NanoKrnl, etc.). I recently discussed cyberwar in the age of AI, Iran’s cyber capabilities, and how AI is reshaping hacking on Bloomberg’s Odd Lots and the National Security Lab podcast.
Previously, I founded OnDB Inc., a data infrastructure startup for the agentic economy, and co-founded CloudVolumes (acquired by VMware in 2014) and Comae Technologies (acquired by Magnet Forensics in 2022), where I later served as Head of Detection Engineering. I also founded the cybersecurity community project OPCDE.
My path into technology started in reverse engineering as a teenager, and has since spanned memory forensics, operating systems, virtualization, blockchain, and now AI infrastructure.
An offline tool that turns an OpenVMM snapshot into a debugger-readable memory image, recovering the guest kernel's symbols from memory with no agent and no supplied symbol file.
Structural detection for four libheif memory-safety defects reachable through HEIF and AVIF item graphs, and how they show up in the container before any pixel is decoded
DeepSeek V4.1 refuses in two voices: a Western premise-refusal skeleton on active-conflict topics and a state-line register on sovereignty topics, five times denser than its own previous generation. A 12-feature stylistic fingerprint across …