Philippe Ombredanne

I am a passionate FOSS hacker; lead maintainer of ScanCode, PurlDB and VulnerableCode; and on a mission to enable easier and safer to reuse of FOSS code with best-in-class open source Software Composition Analysis (SCA) tools for open source discovery and license and security compliance at https://aboutcode.org . I am also a co-founder of SPDX and the creator of Package-URL (PURL), a de-facto standard to identify packages in SBOMs, along with SCA tools and a vulnerability database used throughout the industry.


Session

10-22
14:15
30min
Open source is a virus
Philippe Ombredanne

Discover how we hacked YARA and built rules to effectively detect open source software sources and binaries as if it were malware, using rules that you can generate on demand for fun and profit, and integrate software composition analysis with malware hunting!

topic: CTI
Europe