56,966 blogs · [ { "id": "01a087dd-4b22-71d8-a766-7b2dac56cfd1", "title": "On the Coming Industrialisation of Exploit Generation with LLMs", "url": "https://sean.heelan.io/2026/01/18/on-the-coming-industrialisation-of-exploit-generation-with-llms/", "published_at": "2026-01-18T20:51:55+00:00" }, { "id": "01a087dd-4b23-7290-a1ba-8c3d8b39e03e", "title": "How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation", "url": "https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation/", "published_at": "2025-05-22T10:25:30+00:00" }, { "id": "01a087dd-4b23-7290-a1ba-8c3d8bf8a1a4", "title": "Application optimisation with LLMs: Finding faster, equivalent, software libraries.", "url": "https://sean.heelan.io/2023/06/30/application-optimisation-with-llms-finding-faster-equivalent-software-libraries/", "published_at": "2023-06-30T11:33:27+00:00" }, { "id": "01a087dd-4b23-7290-a1ba-8c3d8c807772", "title": "Finding 10x+ Performance Improvements in C++ with CodeQL – Part 2/2 on Combining Dynamic and Static Analysis for Performance Optimisation", "url": "https://sean.heelan.io/2023/03/01/finding-10x-performance-improvements-in-c-with-codeql-part-2-2-on-combining-dynamic-and-static-analysis-for-performance-optimisation/", "published_at": "2023-03-01T09:05:48+00:00" }, { "id": "01a087dd-4b23-7290-a1ba-8c3d8d161095", "title": "60%+ Performance Improvements with Continuous Profiling and Library Matching – Part 1/2 on Combining Dynamic and Static Analysis for Performance Optimisation", "url": "https://sean.heelan.io/2023/02/14/combining-static-and-dynamic-analysis-in-performance-optimisation-part-1-60-improvements-with-continuous-profiling-and-library-matching/", "published_at": "2023-02-14T10:37:18+00:00" }, { "id": "01a087dd-4b23-7290-a1ba-8c3d8d6498da", "title": "Optimising an eBPF Optimiser with Prodfiler (Repost)", "url": "https://sean.heelan.io/2023/02/10/optimising-an-ebpf-optimiser-with-prodfiler-repost/", "published_at": "2023-02-10T17:32:47+00:00" }, { "id": "01a087dd-4b23-7290-a1ba-8c3d8dc7cda1", "title": "PhD Thesis: Greybox Automatic Exploit Generation for Heap Overflows in Language Interpreters", "url": "https://sean.heelan.io/2020/11/18/phd-thesis-greybox-automatic-exploit-generation-for-heap-overflows-in-language-interpreters/", "published_at": "2020-11-18T19:19:43+00:00" }, { "id": "01a087dd-4b23-7290-a1ba-8c3d8e092607", "title": "Gollum: Modular and Greybox Exploit Generation for Heap Overflows in Interpreters", "url": "https://sean.heelan.io/2019/10/30/gollum-modular-and-greybox-exploit-generation-for-heap-overflows-in-interpreters/", "published_at": "2019-10-30T11:10:30+00:00" }, { "id": "01a087dd-4b23-7290-a1ba-8c3d8f0245a5", "title": "Automation in Exploit Generation with Exploit Templates", "url": "https://sean.heelan.io/2019/03/05/automation-in-exploit-generation-with-exploit-templates/", "published_at": "2019-03-05T13:21:19+00:00" }, { "id": "01a087dd-4b23-7290-a1ba-8c3d8fa5bec8", "title": "Some Cool Projects from a Dagstuhl Seminar on SAT, SMT and CP", "url": "https://sean.heelan.io/2019/02/07/some-cool-projects-from-a-dagstuhl-seminar-on-sat-smt-and-cp/", "published_at": "2019-02-07T12:30:33+00:00" }, { "id": "01a0ca4f-e284-716e-8633-31f9521ccb7c", "title": "Fuzzing PHP’s unserialize Function", "url": "https://sean.heelan.io/2017/08/12/fuzzing-phps-unserialize-function/", "published_at": "2017-08-12T21:47:30+00:00" }, { "id": "01a0ca4f-e284-716e-8633-31f952592099", "title": "Upcoming Public Training: 4 Days of Advanced Tool Development with SMT Solvers (London, Nov ’17)", "url": "https://sean.heelan.io/2017/07/31/upcoming-public-training-4-days-of-advanced-tool-development-with-smt-solvers-london-nov-17/", "published_at": "2017-07-31T11:37:38+00:00" }, { "id": "01a0ca4f-e284-716e-8633-31f9526e399a", "title": "Tracking Down Heap Overflows with rr", "url": "https://sean.heelan.io/2016/05/31/tracking-down-heap-overflows-with-rr/", "published_at": "2016-05-31T13:38:12+00:00" }, { "id": "01a0ca4f-e284-716e-8633-31f952cbc3c0", "title": "Fuzzing Language Interpreters Using Regression Tests", "url": "https://sean.heelan.io/2016/04/26/fuzzing-language-interpreters-using-regression-tests/", "published_at": "2016-04-26T10:21:33+00:00" }, { "id": "01a0ca4f-e284-716e-8633-31f95303a536", "title": "Some Early-Stage Work on Statistical Crash Triage", "url": "https://sean.heelan.io/2016/04/13/some-early-stage-work-on-statistical-crash-triage/", "published_at": "2016-04-13T09:15:29+00:00" }, { "id": "01a0ca4f-e284-716e-8633-31f953f26e62", "title": "Training Dates Confirmed (Plus a Contest for Students)", "url": "https://sean.heelan.io/2016/03/29/nyc-london-training-dates-a-contest-for-students/", "published_at": "2016-03-29T21:47:32+00:00" }, { "id": "01a0ca4f-e284-716e-8633-31f953f5134a", "title": "Public Edition of “Advanced Tool Development with SMT Solvers” Coming Soon!", "url": "https://sean.heelan.io/2016/02/25/public-edition-of-advanced-tool-development-with-smt-solvers-coming-soon/", "published_at": "2016-02-25T17:45:01+00:00" }, { "id": "01a0ca4f-e284-716e-8633-31f954cee76d", "title": "Rust Compiler Plugins: A Simple Example", "url": "https://sean.heelan.io/2015/11/19/rust-compiler-plugins-a-simple-example/", "published_at": "2015-11-19T12:50:58+00:00" }, { "id": "01a0ca4f-e284-716e-8633-31f954fa9f98", "title": "Moving location!", "url": "https://sean.heelan.io/2012/12/05/moving-location/", "published_at": "2012-12-05T15:44:57+00:00" }, { "id": "01a0ca4f-e284-716e-8633-31f95586e198", "title": "SMT Solvers for Software Security (USENIX WOOT’12)", "url": "https://sean.heelan.io/2012/07/27/smt-solvers-for-software-security-usenix-woot12/", "published_at": "2012-07-27T12:27:13+00:00" }, { "id": "01a0ca50-1773-7033-9545-7d44abef1ba7", "title": "Better Interpreter Fuzzing with Clang", "url": "https://sean.heelan.io/2012/07/10/better-interpreter-fuzzing-with-clang/", "published_at": "2012-07-10T20:02:40+00:00" }, { "id": "01a0ca50-1773-7033-9545-7d44acaa9a7b", "title": "Anatomy of a Symbolic Emulator, Part 3: Processing Symbolic Data & Generating New Inputs", "url": "https://sean.heelan.io/2012/03/23/anatomy-of-a-symbolic-emulator-part-3-processing-symbolic-data-generating-new-inputs/", "published_at": "2012-03-23T11:57:03+00:00" }, { "id": "01a0ca50-1773-7033-9545-7d44ad7ae504", "title": "Anatomy of a Symbolic Emulator, Part 2: Introducing Symbolic Data", "url": "https://sean.heelan.io/2012/03/23/anatomy-of-a-symbolic-emulator-part-2-introducing-symbolic-data/", "published_at": "2012-03-23T11:56:37+00:00" }, { "id": "01a0ca50-1773-7033-9545-7d44ad9521a4", "title": "Anatomy of a Symbolic Emulator, Part 1: Trace Generation", "url": "https://sean.heelan.io/2012/03/23/anatomy-of-a-symbolic-emulator-part-1-trace-generation/", "published_at": "2012-03-23T11:55:56+00:00" }, { "id": "01a0ca50-1773-7033-9545-7d44ae698e4b", "title": "SAT/SMT Summer School 2011 Summary (Days 5 & 6)", "url": "https://sean.heelan.io/2011/06/21/satsmt-summer-school-2011-summary-days-5-6/", "published_at": "2011-06-21T04:04:27+00:00" }, { "id": "01a0ca50-1773-7033-9545-7d44aed58db8", "title": "SAT/SMT Summer School 2011 Summary (Days 3 & 4)", "url": "https://sean.heelan.io/2011/06/16/satsmt-summer-school-2011-summary-days-3-4/", "published_at": "2011-06-16T21:57:01+00:00" }, { "id": "01a0ca50-1773-7033-9545-7d44af884fa9", "title": "SAT/SMT Summer School 2011 Summary (Day 2)", "url": "https://sean.heelan.io/2011/06/15/satsmt-summer-school-2011-summary-day-2/", "published_at": "2011-06-15T04:54:00+00:00" }, { "id": "01a0ca50-1773-7033-9545-7d44b0875317", "title": "SAT/SMT Summer School 2011 Summary (Day 1)", "url": "https://sean.heelan.io/2011/06/13/satsmt-summer-school-2011-summary/", "published_at": "2011-06-13T03:53:21+00:00" }, { "id": "01a0ca50-1773-7033-9545-7d44b15e930c", "title": "Infiltrate 2011 Slides", "url": "https://sean.heelan.io/2011/05/10/infiltrate-2011-slides/", "published_at": "2011-05-10T03:11:11+00:00" }, { "id": "01a0ca50-1773-7033-9545-7d44b1c33944", "title": "Finding Optimal Solutions to Arithmetic Constraints", "url": "https://sean.heelan.io/2011/05/08/finding-optimal-solutions-to-arithmetic-constraints/", "published_at": "2011-05-08T20:33:15+00:00" }, { "id": "01a0ca50-3091-725f-821d-250f6cea456a", "title": "Exploit Necromancy in TCMalloc – Reviving the 4-to-N Byte Overflow Primitive with Insert to FreeList[X]", "url": "https://sean.heelan.io/2011/04/14/exploit-necromancy-in-tcmalloc-reviving-the-4-to-n-byte-overflow-primitive-with-insert-to-freelistx/", "published_at": "2011-04-14T04:38:52+00:00" }, { "id": "01a0ca50-3091-725f-821d-250f6dca478d", "title": "Heap Scripts for TCMalloc with GDB’s Python API", "url": "https://sean.heelan.io/2011/03/30/heap-scripts-for-tcmalloc-with-gdbs-python-api/", "published_at": "2011-03-30T23:28:51+00:00" }, { "id": "01a0ca50-3091-725f-821d-250f6e81da6a", "title": "Misleading the Public for Fun and Profit", "url": "https://sean.heelan.io/2010/12/07/misleading-the-public-for-fun-and-profit/", "published_at": "2010-12-07T03:32:49+00:00" }, { "id": "01a0ca50-3091-725f-821d-250f6f694393", "title": "Augment your Auditing with a Theorem Prover", "url": "https://sean.heelan.io/2010/11/05/augment-your-auditing-with-a-theorem-prover/", "published_at": "2010-11-05T03:17:04+00:00" }, { "id": "01a0ca50-3091-725f-821d-250f6f6add2b", "title": "Code Analysis Carpentry (Ruxcon 2010)", "url": "https://sean.heelan.io/2010/10/27/code-analysis-carpentry-ruxcon-2010/", "published_at": "2010-10-27T01:52:42+00:00" }, { "id": "01a0ca50-3091-725f-821d-250f7058a6e8", "title": "Determining variable ranges (Part I)", "url": "https://sean.heelan.io/2010/10/15/determining-variable-ranges-part-i/", "published_at": "2010-10-15T04:58:36+00:00" }, { "id": "01a0ca50-3091-725f-821d-250f70a212e8", "title": "Validity, Satisfiability and Code Semantics", "url": "https://sean.heelan.io/2010/10/02/validity-satisfiability-and-instruction-semantics/", "published_at": "2010-10-02T04:28:42+00:00" }, { "id": "01a0ca50-3091-725f-821d-250f7164b98e", "title": "Applying Taint Analysis and Theorem Proving to Exploit Development", "url": "https://sean.heelan.io/2010/07/17/applying-taint-analysis-and-theorem-proving-to-exploit-development/", "published_at": "2010-07-17T02:20:37+00:00" }, { "id": "01a0ca50-3091-725f-821d-250f725592d2", "title": "Finding use-after-free bugs with static analysis", "url": "https://sean.heelan.io/2009/11/30/finding-bugs-with-static-analysis/", "published_at": "2009-11-30T04:29:21+00:00" }, { "id": "01a0ca50-3091-725f-821d-250f72f6db0a", "title": "Game Over! Thank you for playing Academia", "url": "https://sean.heelan.io/2009/09/06/game-over-thank-you-for-playing-academia/", "published_at": "2009-09-06T15:44:07+00:00" }, { "id": "01a0ca50-5565-7141-8ecb-b8c842ddaae6", "title": "Exploit generation, a specialisation of testing?", "url": "https://sean.heelan.io/2009/09/06/exploit-generation-a-specialisation-of-testing/", "published_at": "2009-09-06T15:21:30+00:00" }, { "id": "01a0ca50-5565-7141-8ecb-b8c84300db53", "title": "Automatic exploit generation: Lessons learned so far", "url": "https://sean.heelan.io/2009/07/05/automatic-exploit-generation-lessons-learned-so-far/", "published_at": "2009-07-05T20:13:14+00:00" }, { "id": "01a0ca50-5565-7141-8ecb-b8c84333c2b7", "title": "Extending to new vulnerability classes", "url": "https://sean.heelan.io/2009/06/21/extending-to-new-vulnerability-classes/", "published_at": "2009-06-21T19:25:41+00:00" }, { "id": "01a0ca50-5565-7141-8ecb-b8c843394be9", "title": "Gathering constraints from conditional branches", "url": "https://sean.heelan.io/2009/06/19/gathering-constraints-from-conditional-branches/", "published_at": "2009-06-19T21:57:55+00:00" }, { "id": "01a0ca50-5565-7141-8ecb-b8c843c37a51", "title": "Morphing shellcode using CFGs and SAT", "url": "https://sean.heelan.io/2009/06/02/model-checking-smt-solving-and-morphing-shellcode/", "published_at": "2009-06-02T16:15:12+00:00" }, { "id": "01a0ca50-5565-7141-8ecb-b8c8445dcc20", "title": "Fun uses for an SMT solver", "url": "https://sean.heelan.io/2009/06/01/fun-uses-for-an-smt-solver/", "published_at": "2009-06-01T21:47:47+00:00" }, { "id": "01a0ca50-5565-7141-8ecb-b8c844ccd394", "title": "Pin problem solved!", "url": "https://sean.heelan.io/2009/05/20/pin-problem-solved/", "published_at": "2009-05-20T17:48:07+00:00" }, { "id": "01a0ca50-5565-7141-8ecb-b8c8459b0c6c", "title": "The romance is over…", "url": "https://sean.heelan.io/2009/05/15/the-romance-is-over/", "published_at": "2009-05-15T20:37:31+00:00" }, { "id": "01a0ca50-5565-7141-8ecb-b8c8468efdc2", "title": "Not all shellcode locations are made equal", "url": "https://sean.heelan.io/2009/05/13/not-all-shellcode-locations-are-made-equal/", "published_at": "2009-05-13T17:16:21+00:00" }, { "id": "01a0ca50-5565-7141-8ecb-b8c847537121", "title": "Difficulties in taint data propagation without an IR", "url": "https://sean.heelan.io/2009/05/11/difficulties-in-taint-data-propagation-without-an-ir/", "published_at": "2009-05-11T15:28:48+00:00" }, { "id": "01a0ca50-7113-73ee-b6bb-a358fa1c5013", "title": "Granular instrumentation with Pin", "url": "https://sean.heelan.io/2009/05/11/granular-instrumentation-with-pin/", "published_at": "2009-05-11T15:05:26+00:00" }, { "id": "01a0ca50-7113-73ee-b6bb-a358faca2699", "title": "Blackhat USA paper", "url": "https://sean.heelan.io/2009/05/06/blackhat-usa-paper/", "published_at": "2009-05-06T23:36:27+00:00" }, { "id": "01a0ca50-7113-73ee-b6bb-a358fb457cb3", "title": "ISSA Ireland seminar", "url": "https://sean.heelan.io/2009/05/06/issa-ireland-seminar/", "published_at": "2009-05-06T23:18:40+00:00" } ] posts Claim your blog
Back to sean.heelan.io
Blog · corpus.blog/blogs/sean.heelan.io/posts

sean.heelan.io

sean.heelan.io

2026

2025

2023

2020

2019

2017

2016

2015

2012

2011

2010

2009