<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>ELF Core on Matt Suiche</title><link>https://www.msuiche.com/tags/elf-core/</link><description>Recent content in ELF Core on Matt Suiche</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 06 Oct 2026 00:00:00 +0200</lastBuildDate><atom:link href="https://www.msuiche.com/tags/elf-core/index.xml" rel="self" type="application/rss+xml"/><item><title>Subvisor: Reading an OpenVMM Guest Without Asking It Anything</title><link>https://www.msuiche.com/posts/subvisor-reading-an-openvmm-guest-without-asking-it-anything/</link><pubDate>Tue, 06 Oct 2026 00:00:00 +0200</pubDate><guid>https://www.msuiche.com/posts/subvisor-reading-an-openvmm-guest-without-asking-it-anything/</guid><description>&lt;p&gt;&lt;em&gt;First in a series on hypervisors, microVMs, confidential computing, and agent sandboxes — the machinery we are all quietly betting on to contain untrusted code, and how well it actually holds. Expect a lot of reading memory from outside the thing that owns it, and the occasional bug that falls out when you do.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Every memory forensics tool I have written starts at the same wall: you have the bytes, but the bytes do not explain themselves. &lt;a href="https://github.com/MagnetForensics/dumpit-linux" target="_blank" rel="noopener"&gt;DumpIt&lt;/a&gt; acquires the RAM; something still has to find the kernel inside it and name what it is looking at. On Windows that something is &lt;code&gt;KdDebuggerDataBlock&lt;/code&gt;, the obfuscated structure a debugger decodes to bootstrap an analysis. On Linux, for a long time, it was &amp;ldquo;hope you have the matching &lt;code&gt;System.map&lt;/code&gt;.&amp;rdquo;&lt;/p&gt;</description></item></channel></rss>