<?xml version='1.0' encoding='utf-8' ?>
<!-- Made with love by pretalx v2025.2.2. -->
<schedule>
    <generator name="pretalx" version="2025.2.2" />
    <version>0.5</version>
    <conference>
        <title>Recon 2026</title>
        <acronym>recon-2026</acronym>
        <start>2026-06-19</start>
        <end>2026-06-21</end>
        <days>3</days>
        <timeslot_duration>00:05</timeslot_duration>
        <base_url>https://cfp.recon.cx</base_url>
        <logo>https://cfp.recon.cx/media/recon-2026/img/Recon2026_VGE32Pu_1YmxA93.webp</logo>
        <time_zone_name>Canada/Eastern</time_zone_name>
        
        
    </conference>
    <day index='1' date='2026-06-19' start='2026-06-19T04:00:00-04:00' end='2026-06-20T03:59:00-04:00'>
        <room name='Grand Salon Opera' guid='0bbd3952-2f8b-5b94-bfa1-4da68fabba35'>
            <event guid='d60517e7-4ddb-5755-8612-b3dc31acc042' id='105'>
                <room>Grand Salon Opera</room>
                <title>Opening ceremony</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-06-19T10:00:00-04:00</date>
                <start>10:00</start>
                <duration>00:30</duration>
                <abstract>Opening ceremony</abstract>
                <slug>recon-2026-105-opening-ceremony</slug>
                <track></track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/7PEBYD/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/7PEBYD/feedback/</feedback_url>
            </event>
            <event guid='6b411fad-0f81-5912-9ec4-6f551bcbd583' id='55'>
                <room>Grand Salon Opera</room>
                <title>I have to use AI, so what now? A skeptic guide to vibing RE/VR</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-06-19T10:30:00-04:00</date>
                <start>10:30</start>
                <duration>00:30</duration>
                <abstract>What&apos;s a Claude? Why are we re-inventing IPCs? What&apos;s the difference between GPT-5.2 and 5.3? All great questions we will NOT answer in this presentation. Instead we will focus on how we can use AI to handle the annoying tasks while saving our time for the fun work. We&apos;ll see how we can identify binaries of interest and spicy code, create a VR harness in the age of MCP servers to automate report generation and the associated collection of necessary artifacts, and more. All-in-all, a pragmatic approach to using AI to enhance our reversing capabilities instead of deskilling ourselves.</abstract>
                <slug>recon-2026-55-i-have-to-use-ai-so-what-now-a-skeptic-guide-to-vibing-re-vr</slug>
                <track></track>
                
                <persons>
                    <person id='58'>Philippe Laulheret</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/YGP3RN/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/YGP3RN/feedback/</feedback_url>
            </event>
            <event guid='dfe508da-358d-56d1-b4ee-bb3f9ffa8af8' id='70'>
                <room>Grand Salon Opera</room>
                <title>Click Once and Stay Forever: uncovering a new abuse of the ClickOnce technology</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-06-19T11:00:00-04:00</date>
                <start>11:00</start>
                <duration>01:00</duration>
                <abstract>What if we told you there&apos;s a Windows feature that&apos;s been quietly sitting in plain sight for decades, just waiting to be weaponized in a way for which no one thought to look? Meet ClickOnce: Microsoft&apos;s well-intentioned deployment technology that lets users run, install, and automatically update applications with minimal interaction and zero admin privileges. While this feature has been simplifying software deployment for decades now, it turns out its convenience comes with some unexpected baggage.

Deep diving into this overlooked technology, we reverse engineered the ClickOnce deployment stack from the ground up, documenting for the first time how its components actually work behind the scenes. Through this process, we uncovered a new abuse of the ClickOnce technology that allows an unprivileged user to establish fileless persistence on the system. By repurposing some old tricks, threat actors can abuse an attack surface exposed by the ClickOnce components to execute their payload every time a user interacts with a ClickOnce application. No elevated privileges needed, no suspicious files left behind, and as a bonus, the malicious payload runs under a native Windows process!

In this talk, we&apos;ll demystify the ClickOnce technology by exploring its deployment scenarios and documenting how it works behind the scene. We&apos;ll walk through the journey that led to our new discovery, demonstrate the technique live, and wrap up with practical detection strategies to protect against these techniques. By the end, you&apos;ll understand how sometimes the most unexpected threats come gift-wrapped in Microsoft&apos;s most helpful features.</abstract>
                <slug>recon-2026-70-click-once-and-stay-forever-uncovering-a-new-abuse-of-the-clickonce-technology</slug>
                <track></track>
                
                <persons>
                    <person id='80'>Mathilde Venault</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/EZTMNB/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/EZTMNB/feedback/</feedback_url>
            </event>
            <event guid='5101a7cd-039e-56c5-ae8a-c2576f9a7423' id='93'>
                <room>Grand Salon Opera</room>
                <title>FAT Chungus: CVE-2025-24857 - A Journey Through U-Boot Exploitation</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-06-19T13:00:00-04:00</date>
                <start>13:00</start>
                <duration>01:00</duration>
                <abstract>Amazon Element55 unpacks CVE-2025-24857, a severe flaw they discovered in U-Boot&#8217;s FAT filesystem support that exposes unauthorized code execution. This talk will elucidate the requisite lore of our research and methodology, how Amazon responded internally, and the coordinated disclosure process.</abstract>
                <slug>recon-2026-93-fat-chungus-cve-2025-24857-a-journey-through-u-boot-exploitation</slug>
                <track></track>
                <logo>/media/recon-2026/submissions/8BJ3KP/Screenshot_2026-04-10_at_1.34.23P_xJyhj4G.webp</logo>
                <persons>
                    <person id='105'>Tim Noise</person><person id='104'>bryce case, jr./ytcracker</person>
                </persons>
                <language>en</language>
                <description>lol AI summary:

Key Topics Covered:

The Vulnerability

Root Cause: An integer underflow in U-Boot&#8217;s get_fatent() function triggered during file reads from attacker-controlled USB devices.
Impact: Bypasses secure boot, enabling arbitrary code execution on otherwise hardened devices.
Scope: Affects U-Boot versions prior to 2017.11, Qualcomm IPQ chipsets (IPQ4019, IPQ5018, etc.), and devices like Amazon eero routers.

Discovery &amp; Fuzzing

Challenge: Fuzzing a 250MB FAT32 filesystem was impractical due to size constraints.
Solution: Zombified U-Boot&#8217;s FAT reader into a Linux userland tool, embedding the entire FAT image for targeted sector fuzzing.
Breakthrough: Crashes identified within minutes by focusing on the FAT header sector.
Exploitation Chain

Triggering the Bug: Manipulating the root_cluster parameter to force fatlength &lt; startblock, causing getsize to underflow to ~UINT32_MAX.
Memory Layout: Deterministic addresses in executable RAM (0x4a900000&#8211;0x4aa00000) with disabled NX-bit.
Overflow Control: Using USB emulation (Facedancer/Cynthion) to send empty sector responses, triggering U-Boot&#8217;s recovery mode and enabling precise overflow length control.
Code Execution: Hijacking U-Boot&#8217;s environment variable hash table via overflow to redirect execution to attacker-controlled shellcode.
Payload Development

Rust Implementation: Safe, panic-handled Rust code for heap restoration, interrupt disablement, and kernel loading.
Heap Repair: Rebuilding DLMalloc linked lists and re-importing environment variables from eMMC.
Bootargs Manipulation: Enabling root shell via systemd.wants=serial-getty@ttyMSM0.service.
Responsible Disclosure &amp; Mitigation

Coordinated Response: Collaboration with CISA (Advisory ICSA-25-343-01), Qualcomm, and the U-Boot Project.
Amazon&#8217;s Action: Patched tens of millions of eero routers via automatic, cryptographically signed updates by January 2025.
Fix: Upgrade to U-Boot v2025.4 or later.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/8BJ3KP/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/8BJ3KP/feedback/</feedback_url>
            </event>
            <event guid='0bce6335-c416-5d6a-a0f5-a04cbca5219b' id='45'>
                <room>Grand Salon Opera</room>
                <title>SELECT * FROM binary &#8212; Vibe Reversing Across IDA, Ghidra, and Binary Ninja</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-06-19T14:00:00-04:00</date>
                <start>14:00</start>
                <duration>01:00</duration>
                <abstract>&quot;Vibe coding&quot; lets developers build software by describing intent to an AI agent. Can the same approach work for reverse engineering - where the analyst describes what they want to understand and the agent drives the tools?

Three tools - idasql (IDA Pro), ghidrasql (Ghidra), and bnsql (Binary Ninja) - expose the internals of each platform as live SQL virtual tables: functions, cross-references, strings, types, disassembly, and decompilation, all queryable and writable through standard SQL. The same query runs against all three tools. Because SQL is the one query language every LLM already speaks fluently, these tools turn any AI coding agent into a reverse engineering partner - no scripting, no plugins, no tool-specific API knowledge required.

We will demonstrate live &quot;vibe reversing&quot; sessions: an analyst converses naturally with an AI agent that autonomously issues SQL queries, decompiles
functions, annotates variables, recovers types, and cross-references findings across multiple binaries and multiple RE tools simultaneously. We will show side-by-side analysis of the same binary in IDA, Ghidra, and Binary Ninja, driven entirely through natural language, and transfer annotations between them.</abstract>
                <slug>recon-2026-45-select-from-binary-vibe-reversing-across-ida-ghidra-and-binary-ninja</slug>
                <track></track>
                
                <persons>
                    <person id='46'>Elias Bachaalany</person>
                </persons>
                <language>en</language>
                <description>Every major RE tool has a powerful but incompatible scripting API. Analysts must learn each one. AI agents can&apos;t easily drive them without tool-specific glue code. There is no common interface -- until now.

idasql, ghidrasql, and bnsql expose the internals of IDA Pro, Ghidra, and Binary Ninja as live SQL virtual tables -- 30+ tables covering functions, cross-references, strings, types, disassembly, and decompilation. These tables are not read-only exports: analysts and AI agents can rename functions, annotate variables, apply types, set comments, and manage bookmarks through standard SQL INSERT/UPDATE/DELETE statements. Changes are reflected live in the RE tool.

Because SQL is the one query language every LLM already speaks fluently, this turns any AI coding agent into a reverse engineering partner -- no IDAPython, no Ghidra scripts, no tool-specific plugins required.

This talk covers:

**One language, three tools.** The same SQL query runs against IDA, Ghidra, and Binary Ninja. We show how `SELECT name, size FROM funcs ORDER BY size DESC LIMIT 10` returns near-identical results across all three tools for the same binary -- and where the interesting differences are.

**The decompiler as a database.** Decompiled pseudocode, AST nodes, local variables, and call arguments are all queryable tables. We demonstrate queries like &quot;find all functions that call malloc without checking the return value&quot; expressed as pure SQL joins across decompiler and cross-reference tables.

**Read-write reverse engineering.** These tools don&apos;t just query -- they write back. We walk through a complete annotation workflow: the agent decompiles a function, renames variables to meaningful names, applies recovered struct types, adds comments explaining the logic, and bookmarks points of interest. All through SQL, all persisted to the database.

**AI-driven analysis sessions.** Live demonstration of &quot;vibe reversing&quot;: an analyst describes what they want in natural language, and the AI agent autonomously drives the RE tool. We show single-binary triage from scratch, cross-tool comparison of the same binary in IDA and Ghidra side by side, and multi-database campaigns where the agent cross-references findings across related malware samples.

**Cross-tool annotation transfer.** An agent reads the annotations, variable names, and type definitions from one tool&apos;s database and applies them in another -- bridging the gap between analysts who use different RE tools on the same project.

**Autonomous type recovery.** The agent reads decompiler output, identifies pointer arithmetic patterns and field access offsets, and constructs struct, union, and enum definitions through SQL -- creating types, adding members, and applying them to variables and function signatures. We show how an agent recovers a multi-level struct hierarchy from raw decompiler output and applies it across all functions that reference it.

**Source recovery from binaries.** We show a complete end-to-end case: starting from a stripped binary, the agent iteratively decompiles, annotates, recovers types and structures, and produces compilable source code -- all driven by natural conversation. We also demonstrate guided recovery where the agent is given partial source code alongside a binary and reconstructs the missing pieces by correlating decompiler output against the known code.

**Malware analysis in practice.** We walk through a real-world C2 malware sample with layered complexity: an outer loader, an inner DLL, and embedded plugin blobs, each requiring extraction and independent analysis. The agent autonomously identifies the layers, extracts the embedded components, opens them in separate database sessions, cross-references between them, and produces a complete annotated teardown of the malware&apos;s architecture.

**Multi-database diffing.** With multiple databases open simultaneously, the agent compares two versions of the same binary -- identifying new functions, changed code paths, and patched vulnerabilities. This extends naturally to malware variant analysis, patch diffing, and firmware update comparison.

**Practical limits and honest lessons.** Where LLMs excel at RE tasks (pattern matching, bulk annotation, cross-referencing, structure recovery), where they still struggle (complex control flow, novel obfuscation, very large functions), and what the SQL interface cannot yet capture.

Attendees will leave with a concrete understanding of how to connect AI agents to their existing RE workflow across any of the three major platforms, and what &quot;vibe reverse engineering&quot; looks like in practice today.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/PSNDXB/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/PSNDXB/feedback/</feedback_url>
            </event>
            <event guid='dc7aaf02-0227-5aa7-8ed3-27059d9d8d74' id='56'>
                <room>Grand Salon Opera</room>
                <title>Deobfuscation in the Age of Agentic Reverse Engineering</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-06-19T15:00:00-04:00</date>
                <start>15:00</start>
                <duration>00:30</duration>
                <abstract>Agentic workflows are rapidly changing how we reverse engineer binaries. Large language models are no longer limited to explaining decompiler output or writing small helper scripts; when paired with real tooling, they can drive analysis, orchestrate workflows, and connect multiple analysis layers faster and at a larger scale than a human analyst alone. In this talk, we explore what this shift means for code deobfuscation, from deflattening, opaque-predicate removal, and string recovery to interprocedural and whole-program deobfuscation. We argue that the key advance is not that models suddenly understand obfuscated code perfectly, but that they can now coordinate the broader workflow around deobfuscation. We conclude by examining what kinds of obfuscation may remain resilient in the face of increasingly agentic reverse engineering.</abstract>
                <slug>recon-2026-56-deobfuscation-in-the-age-of-agentic-reverse-engineering</slug>
                <track></track>
                
                <persons>
                    <person id='6'>Nicol&#242; Altamura</person><person id='62'>Tim Blazytko</person>
                </persons>
                <language>en</language>
                <description>Large language models first entered reverse engineering as helpful assistants: improving decompiler output, suggesting names, answering questions about code, and generating small analysis scripts. Useful as these capabilities were, they largely remained confined to the role of a smart helper sitting next to the analyst. But reverse engineering has changed quickly. With tool-connected, agentic workflows, models are no longer limited to commenting on pseudocode. They can query disassemblers and decompilers, inspect cross-references and intermediate representations, generate custom scripts, patch binaries, rerun analyses, and iteratively refine hypotheses in a loop. The result is a fundamental shift: from LLM-assisted code reading to agentic reverse engineering.

This shift is especially significant for deobfuscation. Rather than a single clever trick, deobfuscation is usually an iterative process of recovering structure, applying transformations, and reanalyzing the result until something meaningful emerges. Agentic workflows are unusually well matched to this style of work. They can automate common simplification steps, connect different analysis layers, and keep pushing the program toward something more understandable.

Once deobfuscation becomes agentic, it also becomes more global. Instead of operating on one function at a time, agents can help identify core routines, propagate recovered semantics across the call graph, mine repeated obfuscation motifs, and apply transformations at interprocedural or whole-program scale. This changes the practical unit of work in reverse engineering: from manually attacking isolated functions to coordinating larger deobfuscation campaigns across an entire binary or malware family.

In this talk, we revisit the state of LLM-assisted reverse engineering from our earlier work and examine how the landscape has evolved. We argue that the key breakthrough is not that models suddenly understand obfuscated code perfectly, but that they can now help orchestrate the broader workflow around deobfuscation: tool usage, reasoning, scripting, patching, and iterative refinement. This naturally leads to the defensive question as well. If reverse engineering is becoming agentic, what must obfuscation look like to remain resilient against attacks that are tool-driven, scriptable, and scalable? We close by exploring the emerging design space of anti-agentic obfuscation, including intertwined and global obfuscation layers, diversification, and structures that resist clean decomposition and large-scale automation.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/A99GW9/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/A99GW9/feedback/</feedback_url>
            </event>
            <event guid='eb319fb6-804c-5601-aec0-dbfc3d6081b4' id='86'>
                <room>Grand Salon Opera</room>
                <title>Chaining Microsoft binaries to get privileged primitives in Windows kernel</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-06-19T16:00:00-04:00</date>
                <start>16:00</start>
                <duration>01:00</duration>
                <abstract>We leveraged a novel code injection to a PPL process we call &#8216;Bring Your Own Vulnerable WerFaultSecure&#8217; and then abuse Microsoft System Guard for privileged primitives in the kernel. We&#8217;ll explain how to make WerFaultSecure run arbitrary code and the vulnerabilities we found in a Microsoft driver.</abstract>
                <slug>recon-2026-86-chaining-microsoft-binaries-to-get-privileged-primitives-in-windows-kernel</slug>
                <track></track>
                
                <persons>
                    <person id='114'>Angelo Frasca Caccia</person><person id='97'>Alejandro Pinna</person>
                </persons>
                <language>en</language>
                <description>The goal of our research was to find undocumented pathways to escalate privileges to the Windows kernel while evading endpoint security solutions. For that end, we found a driver of Microsoft System Guard, which is shipped out of the box, that could be leveraged. Using it from user-space however had limitations. To overcome them, we are forced to run as PPL-WinTCB process, the highest protection level in Windows user-mode. To do that reliably, we showcase a new method to inject code into such a process.
Our novel PPL injection technique leverages the IRundown COM interface to achieve code execution within the process WerFaultSecure.exe, which runs at the highest protection level (WinTCB), and is successfully tested on the latest version of Windows 11. What inspired us to target WerFaultSecure.exe specifically was a vulnerability introduced by James Forshaw in 2018. 
The vulnerability allowed for code injection into the WinTCB-signed WerFaultSecure.exe by abusing a code path in FaultRep.dll (a WerFaultSecure.exe dependency) to enable the IRundown COM interface. This code execution primitive has been widely abused to hijack threads through the DoCallback method. Similarly, in 2023 Clement Labro took advantage of an arbitrary pointer overwrite in ntdll.dll to force PPL processes to load unsigned dynamic libraries, thus achieving code execution in the context of protected processes. In response, Microsoft introduced several countermeasures to inhibit these attacks.
During the talk we will showcase how to bypass these mitigations altogether. In particular, we will walk the audience through:
The abuse of an old vulnerable version of WerFaultSecure which has a Dll Sideloading vulnerability, which we exploit to load an old version of FaultRep, which contains the COM vulnerability. We call this technique &#8216;Bring Your Own Vulnerable WerfaultSecure&#8217;; 
The abuse of a section object which is shared by WerFaultSecure.exe and its parent process. We will show how to construct a ROP chain on the shared memory which will be executed by the DoCallback method of the IRundown interface. This ROP chain is needed in order to give our shellcode the required execute permissions.
How to retrieve and decrypt the secrets that are needed to remotely connect to the interface from PPL processes that are using this communication method. 
How to connect to the target interface and craft a ROP chain in the shared section aforementioned. This will enable us to pivot the execution from the ROP chain to custom shellcode. Last but not least, we will briefly discuss the concept of Control Flow Guard, or CFG, the need for admin privileges to disable it for the exploit to work, as well as ideas to bypass this requirement and new pathways to privilege escalation through PPL injection.
After meeting the prerequisite - executing code at PPL-WinTCB level, we continue to achieve kernel-mode (ring 3) privileges.
Microsoft System Guard is a Windows native infrastructure which validates operating system and device integrity by verifying that certain parts of kernel objects like drivers, devices, processes, threads have not been altered. It achieves this by leveraging an assertion engine running in VTL1 (SgrmEnclave_secure.dll), in combination with a kernel-mode driver - SgrmAgent.sys - which provides it with different facilities. Checks can be performed on the fields IntegrityLevel or TokenSource of the object _TOKEN owned by certain critical processes such as MsMpEng.exe for instance. This driver starts automatically at startup on every Windows 10 (and equivalent Server) release. SgrmAgent.sys enforces the following checks: 
The caller must be WinTCB-signed;
The caller service security identifier (SID) must match a SID that is hardcoded within the driver;
The driver can be initialized only once, meaning only one handle can be granted.

SgrmBroker.exe is the only process which is allowed to acquire a handle to the driver by design. This is because it runs as a protected process, and its service SID matches the one the driver expects. Hence we leveraged our novel PPL injection to make WerFaultSecure execute a shellcode which opens the broker process and steals its handle to the driver, thus bypassing the checks altogether. We then use the stolen handle to communicate with the driver.

Our research examined SgrmAgent.sys&#8217;s IOCTLs which yielded a treasure trove, subverting System Guard&#8217;s defensive purpose. We identified multiple &#8216;sub-IOCTLs&#8217; within the &#8216;OctpMailboxDispatcher&#8217; handler which enable the caller to:
read kernel virtual memory and physical memory;
map files and virtual memory of processes;
read model-specific registers.

These routines are used by the assertion engine to implement certain checks as one would expect. What is more surprising is that we also came across the thread-freezing sub-IOCTL - &#8216;OctpHandleFreezeThread&#8217; - which can halt threads indefinitely by scheduling an ad-hoc kernel Asynchronous Procedure Call. This allows not only to access sensitive processes but even to bypass tampering protections enforced by 3rd party kernel drivers.

We will run a live demo of the entire attack and discuss possible detection opportunities.

While Microsoft does not consider admin-to-kernel a security boundary due to the fact that admin users can load 3rd party drivers, our research demonstrates that it is possible to escalate to the kernel with only Microsoft binaries and without loading a driver.


References:  
https://googleprojectzero.blogspot.com/2018/11/injecting-code-into-windows-protected.html 
https://x.com/GabrielLandau/status/1683854578767343619 
https://blog.scrt.ch/2023/03/17/bypassing-ppl-in-userland-again/ 
https://iamelli0t.github.io/2021/04/10/RPC-Bypass-CFG.html  
https://github.com/Slowerzs/PPLSystem
https://infocon.org/mirrors/vx%20underground%20-%202025%20June/Papers/Windows/Internals%20and%20Analysis/2022-08-02%20-%20Inside%20Windows%20Defender%20System%20Guard%20Runtime%20Monitor.pdf
https://www.microsoft.com/en-us/security/blog/2018/04/19/introducing-windows-defender-system-guard-runtime-attestation/</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/ECTXZH/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/ECTXZH/feedback/</feedback_url>
            </event>
            <event guid='d6b699d6-057e-5e5f-b4a7-bbabe35dc1f4' id='96'>
                <room>Grand Salon Opera</room>
                <title>8 Years of Reverse-Engineering Interpreters: Techniques, Automation, and One Framework</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-06-19T17:00:00-04:00</date>
                <start>17:00</start>
                <duration>01:00</duration>
                <abstract>Over the past eight years we have systematically reverse-engineered nearly ten interpreter and VM binaries, including Lua, Python, Ruby, PHP, VBScript, JScript, PowerShell, and V8, to extract their internal structures and automate that extraction at scale. This talk presents 11 concrete analysis techniques, organized around 6 foundational binary analysis approaches, for recovering interpreter internals from stripped binaries. The techniques include multiple detection logics for VM component recovery that identify their exact locations in memory, and a progressive deduction algorithm for ISA recovery that iteratively eliminates opcode ambiguity across hundreds of test traces. Together they power STAGER, our automated dynamic analysis system built on top of Intel Pin. STAGER completes a full analysis of one interpreter in at most a couple of hours, which is an order-of-magnitude improvement over manual reverse engineering that typically takes days to weeks, and keeps pace with the frequent version updates of real-world interpreter binaries. We will release STAGER as open-source at the conference.

The security payoff is direct. We use STAGER output to build script-level API tracers, which hook the interpreter&apos;s own built-in API functions (e.g., eval), enabling behavioral monitoring across diverse interpreter targets. We further leverage branch VM instruction identification and conditional flag detection to build a multi-path explorer, and use recovered ISA mappings to perform dynamic bytecode instrumentation; together these enable fine-grained analysis of evasive script malware that actively resists conventional debugging. We also combine STAGER output with fuzzing harnesses for vulnerability discovery in interpreter runtimes, and demonstrate bytecode-based process injection techniques for red team operations that bypass diverse security mechanisms. These applications are grounded in real targets and will be shown in a live demo.

Beyond the techniques themselves, we share hard-won lessons from nearly ten real-world targets: how compiler register allocation breaks memory-based variable tracking and how to compensate with register-level static analysis, how to handle interpreters layered atop other interpreters (e.g., PowerShell on .NET CLR) where execution traces interleave two VM layers, and how to suppress or work around JIT compilation interference, including the aggressive JIT behavior seen in V8. Accuracy results across all targets, including honest failure cases where our approach hits fundamental limitations, are presented per technique.

Three concrete takeaways for attendees:
1. A working mental model of interpreter internals as attack and analysis surface, grounded in nearly ten real-world targets.
2. The 11-technique framework, including VM component localization logics and a progressive ISA deduction algorithm, directly applicable to diverse interpreter binaries.
3. STAGER (open-source release) and the methods to adapt it to new interpreter targets.</abstract>
                <slug>recon-2026-96-8-years-of-reverse-engineering-interpreters-techniques-automation-and-one-framework</slug>
                <track></track>
                
                <persons>
                    <person id='107'>Toshinori Usui</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/8TZSJN/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/8TZSJN/feedback/</feedback_url>
            </event>
            <event guid='6b89eee9-1d4a-5f71-a55f-c0379764a3c1' id='104'>
                <room>Grand Salon Opera</room>
                <title>The AI Reversing Panel: Are we all powerful, or out of a job?</title>
                <subtitle></subtitle>
                <type>Panel</type>
                <date>2026-06-19T18:30:00-04:00</date>
                <start>18:30</start>
                <duration>01:00</duration>
                <abstract>It&#8217;s not every day we convene a panel at Recon.
AI affects us all, but where can we go beyond buzzwords and make it concrete?
- What actually works, how we set up our own harnesses, what constantly fails, and what works today that didn&#8217;t even a month ago? Are there limits?
- How the technology affects us daily, from attackers to defenders? We see software development sped up to the max, models finding vulnerabilities autonomously, malware being dissected by AI, and written even faster.
- Topics such as disclosure, when vulnerability in code == public, and if coordinated disclosure can survive it. Is full disclosure back?
- And lastly&#8230; are we still going to have a job in a year or two? Will there still be a need for researchers? Let&#8217;s be specific.
We will welcome surprise guests to the panel, as we cycle through topics. The topics themselves are discussion seeds only.</abstract>
                <slug>recon-2026-104-the-ai-reversing-panel-are-we-all-powerful-or-out-of-a-job</slug>
                <track></track>
                
                <persons>
                    <person id='11'>John McIntosh</person><person id='119'>Aaron Portnoy</person><person id='118'>Marion Marschalek</person><person id='117'>Gadi Evron</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/SN8MYU/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/SN8MYU/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Soprano A' guid='ed4e98db-ac63-5754-851f-baf3e8b755a3'>
            <event guid='145a94f1-1e85-5c92-a7c2-b570dabafb01' id='5'>
                <room>Soprano A</room>
                <title>Basics of .NET Exploitation</title>
                <subtitle></subtitle>
                <type>Workshop (3hrs)</type>
                <date>2026-06-19T13:00:00-04:00</date>
                <start>13:00</start>
                <duration>03:00</duration>
                <abstract>Solarwinds, Microsoft Sharepoint, Microsoft Exchange, Veeam, Veritas, any many more...
All of these products are written in .NET
If you&apos;d like to learn how to reverse engineer, find vulnerabilities and exploit .NET targets
this workshp will teach you the basics</abstract>
                <slug>recon-2026-5-basics-of-net-exploitation</slug>
                <track></track>
                
                <persons>
                    <person id='4'>Sina Kheirkhah (@SinSinology)</person>
                </persons>
                <language>en</language>
                <description>[X] Topics:

Reversing .NET targets (static analysis, debugging, patching)
Introduction to .NET vulnerabilities
Basics of deserialization exploits in .NET
Patch diffing and exploiting an Nday

[X] Requirements:

Windows 10 or 11 VM
DO NOT bring an ARM laptop (MacBook) tools will not run on this CPU
If you do not have a intel/amd laptop, try preparing a remote windows server (vps,ec2,etc)
Basic knowledge of C#
Basic of any reverse engineering is a must (x86, etc)</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/V9XUD3/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/V9XUD3/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Soprano B' guid='206dc37d-af7a-5bff-821b-42bfd62746ce'>
            <event guid='73ea4ed7-0543-5b05-a828-255d9ffc7f7f' id='59'>
                <room>Soprano B</room>
                <title>C++ Symbol and Type Recovery in Binary Ninja</title>
                <subtitle></subtitle>
                <type>Workshop (3hrs)</type>
                <date>2026-06-19T13:00:00-04:00</date>
                <start>13:00</start>
                <duration>03:00</duration>
                <abstract>One of the first steps taken during the reverse engineering process is to recover as much context as possible from a given binary, including symbols, function signatures, classes and structures associated with statically linked code. This is especially important for modern compilers and linkers that embed a plethora of boilerplate that you don&apos;t want to spend time reverse engineering. Throughout this workshop we will explore recovering this information using multiple open source tools in Binary Ninja. Our target will be a real-world malware sample written in C++ that is used to terminate EDR and antivirus technologies. The sample contains multiple components, including user-mode and kernel-mode binaries that require symbol and type information recovery for accurate analysis.</abstract>
                <slug>recon-2026-59-c-symbol-and-type-recovery-in-binary-ninja</slug>
                <track></track>
                
                <persons>
                    <person id='64'>Joshua Reynolds</person>
                </persons>
                <language>en</language>
                <description>The 3-hour workshop will contain the following sections:

- **C++ Foundation (35 minutes)**:&#160;We begin by discussing core C++ concepts, such as Object Oriented Programming, Runtime Type Information and Virtual Function Tables. We will then recover RTTI and VTable information in an example binary in Binary Ninja.
- **Malware Triage and Manual C++ Reverse Engineering (60 minutes):**&#160;This section focuses on initial analysis of the target malware binary. We will identify the malware&#8217;s compiler and libraries using metadata like the Rich Header. Then we will manually reverse engineer **C Runtime (CRT)**&#160;boilerplate, argument parsing logic (```wmain```, ```lstrcmpiW```), and the &quot;install&quot; and &quot;uninstall&quot; execution paths for the malware. In addition we will analyze malware&apos;s techniques for establishing persistence, Windows service registration process and signal handling.
- **Automated Context Recovery with WARP (30 minutes):**&#160;In contrast to the manual reversing process, you will learn how to use specialized tools for type identification and recovery. We will demonstrate how to identify standard C++ library functions (like those for ```std::vector``` and exception handling) and how to match the malware&#8217;s compilation environment to generate high-quality WARP analysis signatures&#160;based on C++ templates that automatically recover and rename these complex functions.
- **Fuzzy Function Matching with BinDiff (35 minutes):**&#160;We conclude by leveraging binary diffing to fill the remaining gaps. You will see how the BinDiff&#160;tool and its fuzzy matching algorithms are used to compare the unknown malware against a known, clean reference binary. This technique allows more lenient matching of function names, data structures, and class types, allowing us to recover information that WARP has missed. We will also demonstrate porting missing types from the example compiled binary to the malware database using Binary Ninja type archives.
- **Q&amp;A and Resources (20 minutes):**&#160;Final thoughts and time for questions on integrating these techniques into your professional workflow.

By the end of this session, you will learn robust, multi-faceted strategies for symbol and type recovery to assist with reverse engineering C++ malware in Binary Ninja with open source tools. All attendees will receive the workshop manual, slides, the sample binaries, pre-built WARP signatures, Bindiff files and a reference cheat sheet for the techniques covered.

#### Prerequisites &amp; Preparation

Attendees should have basic familiarity with x86/x64 assembly and have Binary Ninja installed (a free license is sufficient). Prior malware analysis experience is helpful but not required. As we will be working with malware, please install Binary Ninja and BinDiff within a Virtual Machine for this workshop.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/YACFKE/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/YACFKE/feedback/</feedback_url>
            </event>
            
        </room>
        
    </day>
    <day index='2' date='2026-06-20' start='2026-06-20T04:00:00-04:00' end='2026-06-21T03:59:00-04:00'>
        <room name='Grand Salon Opera' guid='0bbd3952-2f8b-5b94-bfa1-4da68fabba35'>
            <event guid='4f32d91d-f4db-5bcb-b6b5-fbb3b4f5f6e7' id='94'>
                <room>Grand Salon Opera</room>
                <title>Beyond XNU: Anatomy of the Secure Kernel &amp; Exclaves on Apple Silicon</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-06-20T10:00:00-04:00</date>
                <start>10:00</start>
                <duration>01:00</duration>
                <abstract>Apple&#8217;s platform security story is shifting. Security critical functionality is increasingly moving out of the traditional XNU kernel into the guarded world, an Apple Silicon proprietary secure execution mode. Initially used for the Secure Page Table Monitor (SPTM) and the Trusted Execution Monitor (TXM), it now also hosts a separate CL4 microkernel, the Secure Kernel, which runs Exclaves. Exclaves are isolated components that XNU can communicate with through defined interfaces.

This talk is a deep technical tour of the Secure Kernel and the Exclave ecosystem as it exists on modern iOS and macOS. We will build a clear mental model of component roles, privilege separation, IPC patterns, shared memory data flows, and the choke points where validation and policy decisions occur. From there, we will show how to identify endpoints, recover message formats, map memory and permissions, and instrument execution so you can turn black box components into something you can actually audit.

The goal is to leave attendees with concrete strategies for finding vulnerabilities and mitigation bypass opportunities in this new Apple security perimeter.</abstract>
                <slug>recon-2026-94-beyond-xnu-anatomy-of-the-secure-kernel-exclaves-on-apple-silicon</slug>
                <track></track>
                
                <persons>
                    <person id='106'>Stefan Esser</person>
                </persons>
                <language>en</language>
                <description>Apple Silicon introduced a guarded world alongside XNU. That environment started with SPTM and TXM, and today it also includes a CL4 microkernel, the Secure Kernel, which hosts Exclaves. Exclaves are isolated components that XNU can communicate with through defined interfaces, and that boundary is where a lot of interesting engineering decisions and security relevant behavior lives.

This talk goes in depth on how the Secure Kernel and Exclaves actually work on modern iOS and macOS. We will cover the execution model and privilege separation, how communication is structured (IPC plus shared memory), and which parts of the stack tend to be responsible for validation and policy decisions. The goal is to make the system understandable enough that you can reason about it like any other target, rather than treating it as an opaque blob.

Topics include:
	&#8226;	Secure Kernel internals (task model, isolation, lifecycles)
	&#8226;	Tightbeam (endpoints, transports, message formats)
	&#8226;	XRT scheduler messages
	&#8226;	Exclave resources and Conclaves
	&#8226;	IPC + shared memory semantics (ownership, lifetimes, validation points)
	&#8226;	Security implications: bug classes and mitigation bypass angles</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/HARHBR/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/HARHBR/feedback/</feedback_url>
            </event>
            <event guid='d3990ba5-fbdd-5dbc-af27-22db3d72cb02' id='79'>
                <room>Grand Salon Opera</room>
                <title>Prism Internals: Reversing Microsoft&apos;s x86-to-ARM64 Binary Translator</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-06-20T11:00:00-04:00</date>
                <start>11:00</start>
                <duration>01:00</duration>
                <abstract>Prism is Microsoft&apos;s binary translator on Windows on ARM, JIT-compiling x86 and x64 to ARM64 at runtime. Five binaries, ~11K functions, no symbols. We reversed the full JIT pipeline, the CHPE/ARM64X hybrid loading mechanism, and the undocumented `.jc` translation cache format. Along the way we found that the x64se variant runs CRC32C integrity verification on translated code while x86 does not. The cache has no integrity checks on x86 translations: four structural checks, then arbitrary ARM64 executes verbatim. We release `prism-cache-parser` and demonstrate cache poisoning on Snapdragon X: drop a crafted `.jc` file, hijack translations for any DLL, survive reboots, invisible to every default detection layer.</abstract>
                <slug>recon-2026-79-prism-internals-reversing-microsoft-s-x86-to-arm64-binary-translator</slug>
                <track></track>
                
                <persons>
                    <person id='88'>Hugo</person>
                </persons>
                <language>en</language>
                <description>Every Windows on ARM machine ships Prism, a binary translator that JIT-compiles x86 and x64 to ARM64 at runtime. Five binaries, ~11K functions, no symbols, no documentation. We reversed all of it: the translation pipeline from opcode decoding to ARM64 emission, the CHPE/ARM64X hybrid loading mechanism that ties the two JIT engines together across architectures, and the undocumented `.jc` translation cache format (validated against 341 real files from a Snapdragon X install).

We found that the x64se &quot;strict&quot; variant runs CRC32C integrity checks on translated code while the x86 variant does not, and that the cache service validates `.jc` files with four structural checks and nothing else. We demonstrate cache poisoning: drop a crafted file, hijack function translations, survive reboots, invisible to every default security layer. We release `prism-cache-parser`, detection rules, and annotated RE artifacts for all five Prism binaries.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/V3THYR/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/V3THYR/feedback/</feedback_url>
            </event>
            <event guid='44710998-ed3a-5868-9588-4e6f77146ab6' id='68'>
                <room>Grand Salon Opera</room>
                <title>ROM Dump, Descrambling and Decryption using RE Only: the Fully Analytical MEthod (FAME), no FIB, no Guesses&#8230;</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-06-20T13:00:00-04:00</date>
                <start>13:00</start>
                <duration>01:00</duration>
                <abstract>From quite manual to semi-automated, these are targeting the conversion of pictures into a proper binary that can then be analyzed using the usual tools.
One issue that is reportedly described is the presence of scrambling within the memory array making converting the pictures to something sensical a task involving trial and errors that can lead in the worst case scenario to a project halt if the scrambling scheme is not trivial.
Furthermore, when encryption is used, there is no obvious option to try solving it. This is generally where fully invasive techniques become the method of choice, involving a much more equipped lab with an FIB and micro-probing station but also the need to analyze digital circuit and to  potentially bypass counter-measures such as security shields for example.
This lecture aims at showing that ROM dumps including descrambling and decryption can be done using a fully analytical methods where pictures of all of the layers of the memory including control circuitry, row and column decoders can be converted into a HDL langage which make it possible to simulate the memory to retrieve its content independent of internal scrambling schemes. By extension, the description will be pushed to decryption circuitry which is another bloc of logic that can be modeled and simulated accurately. 
The lecture will include demonstrations of the method using simple to professional setups so as to clearly outline their benefits and limitations.</abstract>
                <slug>recon-2026-68-rom-dump-descrambling-and-decryption-using-re-only-the-fully-analytical-method-fame-no-fib-no-guesses</slug>
                <track></track>
                
                <persons>
                    <person id='78'>Olivier THOMAS - Texplained</person>
                </persons>
                <language>en</language>
                <description>The talk will start with the context introduction and a classification of the ROM dump feasibility and difficulty from non-encrypted, non-scrambled to fully encrypted and scrambled.
Then, the usual dump techniques will be reviewed quickly to introduce the proposed method which is generic to the various cases discussed previously. 
The talk will include demos that are showing how the method can be accomplished using simple and affordable tools. A second demo will show how professional tools do the job in a blink of an eye. These two demos will be used to outline potential limitations and use cases.
As the method does not require expensive FIB, micro-probing station and other custom lab equipment, it will benefit to a wide range of Reverse-Engineer from &#8220;hobbyist&#8221; to &#8220;professional&#8221; of the sector.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/BCKMJA/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/BCKMJA/feedback/</feedback_url>
            </event>
            <event guid='ea9561d3-3273-5b0e-b0b7-12c02af20289' id='54'>
                <room>Grand Salon Opera</room>
                <title>Failure Is Not an Option: A Reliable Process to Exploit STM32F2/F4 Microcontrollers</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-06-20T14:00:00-04:00</date>
                <start>14:00</start>
                <duration>01:00</duration>
                <abstract>The STM32 family of microcontrollers is deployed in billions of embedded systems, making them desirable, high-value targets. In particular, the STM32F2 and STM32F4 series have been heavily scrutinized due to their use in popular cryptocurrency hardware wallets like the KeepKey, Trezor One, and Trezor Model T. Previous research has shown that fault injection can bypass protection mechanisms and enable flash memory extraction. However, those techniques can lead to device corruption or permanent loss of data.

In this talk, Joe and Lennert present three years of work refining and extending these attacks into a more repeatable and reliable process for extracting protected flash memory from STM32F2 and STM32F4 devices. They will discuss the practical engineering behind the work, including failures, breakthroughs, and new attack strategies. Using these techniques, they have recovered the cryptocurrency recovery seeds from dozens of customer-owned hardware wallets with a 100% success rate.</abstract>
                <slug>recon-2026-54-failure-is-not-an-option-a-reliable-process-to-exploit-stm32f2-f4-microcontrollers</slug>
                <track></track>
                <logo>/media/recon-2026/submissions/QTLDLF/Joe_Grand_STM32_Hack_REcon_2026_e_sEPoQZv.webp</logo>
                <persons>
                    <person id='59'>Joe Grand</person><person id='61'>Lennert Wouters</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/QTLDLF/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/QTLDLF/feedback/</feedback_url>
            </event>
            <event guid='74c8078a-6952-5a08-8100-8c7ea537e774' id='50'>
                <room>Grand Salon Opera</room>
                <title>Paper Werewolf&apos;s Toolbox: Reversing XLL Delivery, EchoGather, and a WinRAR Exploit Chain Targeting Russia</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-06-20T15:00:00-04:00</date>
                <start>15:00</start>
                <duration>00:30</duration>
                <abstract>Most threat intelligence treats Russia as a source of attacks. This talk examines Russia as a target. Paper Werewolf (aka GOFFEE) is a cyberespionage group with a sustained focus on Russian defense-industry and government organizations, and despite the group&apos;s activity level, it still flies under the radar. This talk presents a full technical teardown of a recent campaign, from the initial delivery mechanism to the implant, the exploitation chain, and the infrastructure that ties it to prior Paper Werewolf operations.

The loading mechanism is an XLL add-in, a delivery format that is not new but is rarely dissected in public research. We walk through the loader&apos;s DLL export structure, its time-delay sandbox evasion logic, and the unpacking chain leading to EchoGather, a backdoor we uncovered. We reverse EchoGather&apos;s XOR-encrypted string handling, C2 protocol, and command handler architecture. A parallel delivery chain exploits CVE-2025-8088, a WinRAR path traversal bug that abuses NTFS alternate data streams to silently drop a persistence script into the Windows Startup folder.

Beyond the binaries, the campaign has two details worth examining in their own right. The decoy documents impersonating the Russian Ministry of Industry and Trade contain clear AI-generated artifacts, offering a fingerprinting angle on how threat actors are incorporating generative AI into their operations. And to accelerate our own infrastructure analysis, we built a lightweight script on top of the Validin API using Claude Code, turning a manual correlation process into a systematic one. We will share the script, the methodology, and previously undisclosed indicators discovered after our public blog post.</abstract>
                <slug>recon-2026-50-paper-werewolf-s-toolbox-reversing-xll-delivery-echogather-and-a-winrar-exploit-chain-targeting-russia</slug>
                <track></track>
                <logo>/media/recon-2026/submissions/AAPSD9/Screenshot_2026-03-12_at_17.04.05_quQmnFM.webp</logo>
                <persons>
                    <person id='53'>Nicole Fishbein</person>
                </persons>
                <language>en</language>
                <description>There is a persistent blind spot in public threat intelligence: the overwhelming focus on Russia as the origin of attacks leaves little analysis of groups targeting Russian targets. Paper Werewolf, also tracked as GOFFEE, is a cyberespionage actor that has been quietly running operations against Russian defense-industry and government organizations for years. It occasionally surfaces in Russian-language security reporting but receives almost no attention in Western research, which means its tooling, techniques, and infrastructure evolution are largely undocumented in English. This talk is a detailed technical examination of a recent Paper Werewolf campaign and an attempt to close some of that gap.

The campaign begins with an XLL add-in submitted to VirusTotal from Ukraine and Russia in late October 2025, with filenames referencing enemy targeting data in Russian. XLL abuse is not a new concept; Excel add-ins have been weaponized for years, but public reversing walkthroughs of XLL-based campaigns in the wild are genuinely rare. This sample is a clean, mature example of the format being used by a capable actor. We start with how Excel loads and executes the DLL exports that make an XLL work, then move on to the specifics of this loader: the time-delay evasion technique designed to outlast sandbox execution windows and the unpacking chain that leads to the embedded payload.

That payload is EchoGather, a backdoor we named. We reverse it in full: the XOR-based string decryption routine, the C2 communication protocol, and the command handler table. We cover what each handler does and discuss how the implant is designed for the operational requirements of a long-running espionage campaign rather than a smash-and-grab intrusion.

A separate delivery chain discovered during analysis introduces a different technical angle. A RAR archive exploits CVE-2025-8088, a path-traversal vulnerability in WinRAR that exploits NTFS alternate data stream handling to write files outside the intended extraction path. The actor uses this to place a batch script directly in the Windows Startup folder, achieving persistence with no additional execution step required. We walk through the exploit mechanics at the file system level and connect it to the group&apos;s documented prior use of CVE-2025-6218, a related WinRAR vulnerability, showing how the exploitation tradecraft has evolved while the operational intent has stayed consistent.

The decoy documents dropped alongside EchoGather deserve their own section. Both impersonate official communications from the Russian Ministry of Industry and Trade, and both contain artifacts that point clearly to AI-assisted generation: a double-headed eagle emblem rendered with visible distortion errors, Cyrillic characters systematically substituted with visually similar Latin equivalents in ways a native speaker would never produce, and register inconsistencies throughout the text. We treat these documents as forensic artifacts and compare them against decoys from a previously reported Paper Werewolf campaign, showing how recurring mistakes and impersonation patterns function as a durable attribution signal even when the malware family or infrastructure rotates. The AI-generation angle is also worth discussing on its own terms: what does it tell us about how this actor is operationalizing generative AI, and what fingerprints does that leave behind?

On the analyst side, we used VirusTotal file relationship graphs and submission metadata to surface related samples and a broader campaign picture. For infrastructure correlation, we relied on Validin, using passive DNS records, banner hashes, and header fingerprints to connect domains and identify links to past Paper Werewolf activity. To make this repeatable, we built a lightweight script on top of the Validin API using Claude Code that systematizes the correlation process. We will show the tool, explain how it was built, and discuss how researchers can adapt the same approach for their own investigations. This is also a small but concrete illustration of using AI-assisted development to quickly build custom research tooling, something that is increasingly practical yet underutilized in the threat research community.
The talk will include previously undisclosed indicators and infrastructure findings developed after our public blog post, and all tools, YARA rules, and scripts used in the investigation will be shared with attendees.</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/AAPSD9/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/AAPSD9/feedback/</feedback_url>
            </event>
            <event guid='b5d08ffd-88d4-54db-acb0-cecd8c4d8a84' id='47'>
                <room>Grand Salon Opera</room>
                <title>From Bus Wires to Badges: Breaking Into FERMAX Through RFID</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-06-20T16:00:00-04:00</date>
                <start>16:00</start>
                <duration>01:00</duration>
                <abstract>When reverse engineering the proprietary DUOX PLUS intercom system dubbed the &#8216;most secure in world&#8217; by Fermax, previously Kirils &amp; friends focused on its digital 2-wire signalling and employed such tools like oscilloscopes, logic analyzers and breadboards.

While these attacks are important as they shine light on the internal workings on the system, their application in the field is limited as one would need to acquire access to the 2-wire bus, which is only possible from the inside of the building.

Then we noticed something that was right in front of our eyes - access control panels! These things are out there just on the perimeter! And, when installed on multi-tenant buildings, they have RFID reader modules installed. Fermax offers modules doing EM4100, MIFARE Classic, and MIFARE Desfire.

In this talk we give an overview of previous research and expand on it by exploring the possibilities of entering the perimeter by attacking the RFID dimension of these systems, and exploring card cloning, implanting, and cryptographic attacks together with Iceman. 

Attendees will gain insight into decoding and interacting with closed digital protocols, exposing vulnerabilities in real-world access control systems. They also get practically applying RFID attacks to real world systems in use right now.</abstract>
                <slug>recon-2026-47-from-bus-wires-to-badges-breaking-into-fermax-through-rfid</slug>
                <track></track>
                
                <persons>
                    <person id='49'>Iceman</person><person id='48'>Kirils Solovjovs</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/QQZNHF/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/QQZNHF/feedback/</feedback_url>
            </event>
            <event guid='dec6272f-beeb-5675-8211-bf73b13a3915' id='29'>
                <room>Grand Salon Opera</room>
                <title>Breaking the Backbone of Global ISP Networks</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-06-20T17:00:00-04:00</date>
                <start>17:00</start>
                <duration>01:00</duration>
                <abstract>This talk presents a practical end-to-end attack chain against modern fiber access networks. By chaining multiple pre-authentication Remote Code Execution vulnerabilities, an attacker can compromise a GPON Optical Line Terminal and then pivot to the ISP&#8217;s cloud-based management platform. This escalation enables centralized and persistent control over all deployed OLTs. Such an attack can lead to large-scale service disruption, long-term unauthorized network access, customer traffic interception, and mass surveillance. The scenario mirrors real-world incidents involving nation-state actors targeting telecommunications providers. Technical details are being responsibly disclosed to the vendor and will be fully revealed at the conference, along with a demonstration video.</abstract>
                <slug>recon-2026-29-breaking-the-backbone-of-global-isp-networks</slug>
                <track></track>
                
                <persons>
                    <person id='28'>Mathieu Farrell</person>
                </persons>
                <language>en</language>
                <description>In this talk, we present a practical, end-to-end attack chain against modern
fiber access networks, demonstrating how multiple pre-authenticated Remote Code
Execution (RCE) vulnerabilities can be chained to fully compromise an ISP
infrastructure.

We begin by exploiting three pre-authenticated RCE vulnerabilities on a GPON
Optical Line Terminal (OLT), gaining initial access to a device that sits at a
critical point of ISP networks and directly handles customer traffic. From
the compromised OLT, we pivot into the ISP&#8217;s cloud-based fleet management
platform via an additional pre-authenticated RCE, ultimately obtaining
centralized and persistent control over all deployed OLTs managed by the
provider.

In large-scale deployments, OLTs are remotely administered through centralized
management platforms, making them highly attractive targets. By chaining
vulnerabilities between exposed edge devices and their associated cloud
management systems, an attacker can escalate from a single-device compromise to
full control over the access network infrastructure.

This attack path enables high-impact outcomes, including large-scale service
disruption, long-term unauthorized access to ISP networks, customer traffic
interception, and mass surveillance capabilities. These scenarios closely mirror
recent real-world disclosures involving nation-state actors covertly
compromising telecommunications providers in Western countries, where control
over ISP infrastructure has been leveraged for strategic intelligence collection
and population-scale monitoring.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/TXLWRK/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/TXLWRK/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Soprano A' guid='ed4e98db-ac63-5754-851f-baf3e8b755a3'>
            <event guid='07445557-b232-5a74-b112-3155d88c0fb1' id='74'>
                <room>Soprano A</room>
                <title>Adapting Ghidra and its Decompiler to new languages</title>
                <subtitle></subtitle>
                <type>Workshop (2hrs)</type>
                <date>2026-06-20T13:00:00-04:00</date>
                <start>13:00</start>
                <duration>02:00</duration>
                <abstract>A binary in a new language that suspiciously looks like it&apos;s designed to foil your static analysis tools:
A new string format that breaks references and readability, virtual dispatch that masks which function is called where and a reference counting garbage collector so you can&apos;t even tell which object ends up where.

Participants will learn how to leverage Ghidra and P-Code to tackle the challenges that pop up when analyzing compiled high level languages.
The focus will be on the iterative workflow of assisting the decompiler: Understanding why it fails,
assisting it with a custom analysis script that uses the P-Code emitted by the decompiler,
and feeding the resulting information back to Ghidra and the decompiler via the right APIs,
so that the decompiler can continue doing the heavy lifting, and provides better P-Code to tackle the next challenge.

By the end, participants will have a transferable toolbox for adapting Ghidra&apos;s decompiler to unfamiliar language runtimes by identifying runtime patterns, writing P-Code-driven analysis scripts or to feeding recovered types and dispatch targets back to the decompiler.</abstract>
                <slug>recon-2026-74-adapting-ghidra-and-its-decompiler-to-new-languages</slug>
                <track></track>
                
                <persons>
                    <person id='85'>Florian Magin</person>
                </persons>
                <language>en</language>
                <description>Ghidra&apos;s decompiler is powerful, but it needs help with unfamiliar language runtimes. Common issues are a wall of unnamed functions, new string formats, opaque indirect calls through some kind of dynamic dispatch, or noise from reference counting. And the decompiler doesn&apos;t know what any of it means.

This workshop teaches the basic toolbox for fixing that. Participants work through a series of modules, each targeting a specific failure mode of the decompiler and resolving it with a Ghidra script. Parsing metadata, to setup classes and layouts. Install call fixups to eliminate GC noise. Identify sources of type information, and feed it into the dataflow analysis. Analyze dataflow through P-Code to resolve virtual dispatch targets. Each module visibly improves the decompiler&apos;s output before moving to the next &#8212; and each builds on the results of the previous one.

The emphasis is not on the specific runtime but on the tools and techniques that transfer: understanding _why_ the decompiler produces bad output, identifying what information it&apos;s missing, extracting that information from P-Code, and feeding it back through the right Ghidra APIs so the decompiler can do the heavy lifting.

With LLMs it has become easy to generate Ghidra scripts, but you still need to know what to ask for &#8212; which API is the right one, what the decompiler actually needs, and where it expects the information to be. 

Prerequisites: Familiarity with Ghidra&apos;s UI and basic reverse engineering. No prior P-Code experience with needed. Bring a laptop with Ghidra 11+ and Java 21.

Materials: https://github.com/fmagin/pcode-workshop/releases/tag/recon2026</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/PYUVVA/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/PYUVVA/feedback/</feedback_url>
            </event>
            <event guid='51a01dd4-881a-5825-820e-46234fbfaa86' id='88'>
                <room>Soprano A</room>
                <title>MIPS Malware Reverse Engineering</title>
                <subtitle></subtitle>
                <type>Workshop (2hrs)</type>
                <date>2026-06-20T16:00:00-04:00</date>
                <start>16:00</start>
                <duration>02:00</duration>
                <abstract>Curious about expanding your reverse engineering skills to another architecture? Lets go learn MIPS! Both x86-64 and ARM reverse engineering knowledge transfer really well to MIPS, and with some basics and an instruction cheat sheet we&apos;re on our way in no time. We&apos;ll analyze AcidRain, a piece of MIPS-32 malware, a Russian wiper malware none the less. The sample is stripped, and we&apos;ll learn how to quickly recover essential libc functions, to then reconstruct the malware&apos;s code flow.</abstract>
                <slug>recon-2026-88-mips-malware-reverse-engineering</slug>
                <track></track>
                
                <persons>
                    <person id='99'>Marion Marschalek</person>
                </persons>
                <language>en</language>
                <description>Workshop outline (45 min lecture / 45 min lab / 30 min discussion of solutions):

- MIPS architecture 101 and a brief history
- The MIPS pipeline
- Delay slots
- Instruction categories
- MIPS registers and their purpose
- The MIPS stack
- The O32 calling convention 
- Syscall calling convention and numbering
- Function prologues/epilogues
- Other MIPS architectures and their calling conventions, briefly
- Hands on: AcidRain
-- Challenge 1: Understand daemonization
-- Challenge 2: Reconstruct wiping code flow</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/3LERJG/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/3LERJG/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Soprano B' guid='206dc37d-af7a-5bff-821b-42bfd62746ce'>
            <event guid='24e60812-aa31-5d30-8436-1ddd3bda08aa' id='10'>
                <room>Soprano B</room>
                <title>Agentic Reverse Engineering: Building Custom AI &quot;Skills&quot; with Coding Agents</title>
                <subtitle></subtitle>
                <type>Workshop (3hrs)</type>
                <date>2026-06-20T13:00:00-04:00</date>
                <start>13:00</start>
                <duration>03:00</duration>
                <abstract>Agent Skills are now an open format and the latest evolution in agentic workflows, enabling coding agents to execute multi&#8209;step reverse&#8209;engineering tasks with high accuracy and minimal prompting. This workshop teaches participants to design, build, and iterate custom Skills using coding agents such as Claude Code, OpenCode, and Mistral Vibe. Through guided exercises, attendees will build a multi&#8209;platform driver&#8209;analysis Skill that automates IOCTL mapping, platform&#8209;specific dispatch analysis, code&#8209;flow analysis, and workflow capture across Windows, macOS, and Linux. The workshop blends conceptual foundations with extensive hands&#8209;on practice, ensuring participants leave with both the understanding and practical experience needed to implement agentic RE Skills in their own workflows.</abstract>
                <slug>recon-2026-10-agentic-reverse-engineering-building-custom-ai-skills-with-coding-agents</slug>
                <track></track>
                <logo>/media/recon-2026/submissions/SHYHKM/1_6xZaAj3lxnx8dbWF-GwSPA_H27YpGD__6lBDoRm.webp</logo>
                <persons>
                    <person id='11'>John McIntosh</person>
                </persons>
                <language>en</language>
                <description># **Description**  
Agentic reverse engineering blends interactive reversing with autonomous agent workflows. Building on last year&#8217;s RECON workshop on MCP&#8209;based Ghidra integration, this session introduces Agent Skills - structured bundles of instructions, scripts, and resources that coding agents can discover and execute. Skills introduce workflow capture and progressive disclosure, enabling agents to perform complex RE tasks with far less context overhead.

**Sign up**: [Agentic RE Skills Workshop Recon 2026 Sign up](https://l.clearseclabs.com/agentic-re-skills-recon2026)

Participants will learn how coding agents operate through iterative loops (generate &#8594; execute &#8594; inspect &#8594; refine) and how Skills plug directly into these loops to automate analysis. The workshop emphasizes practical application: attendees will build a multi&#8209;platform driver&#8209;analysis Skill that supports IOCTL enumeration, platform&#8209;specific dispatch&#8209;flow analysis (Windows IRPs, Linux file operations, macOS IOKit user&#8209;client methods), code&#8209;flow analysis, and reproducible workflow capture.

---

# **Learning Objectives**  
By the end of this workshop, participants will be able to:

- Understand the Agent Skills framework and how it extends MCP concepts  
- Build custom reverse&#8209;engineering Skills using coding agents  
- Create interactive, agent&#8209;driven workflows for multi&#8209;platform driver analysis  
- Implement progressive disclosure to reduce context size and improve agent performance  
- Capture expert RE heuristics and encode them into reusable Skills  
- Integrate Skills with existing RE tools and workflows  

---

# **Outline**

### **1. Foundations of Agentic Reverse Engineering**
- Skills framework vs. MCP  
- Coding agent capabilities (Claude Code, OpenCode, Mistral Vibe)  
- Environment setup  
- Workflow capture and progressive disclosure  
- How Skills integrate into agent loops  

### **2. Skill Building: Architecture, Workflows, and Iteration**
- Designing RE Skill architecture and folder structure  
- Implementing analysis workflows  
- Adding domain knowledge, heuristics, and resources  
- Designing structured output schemas  
- Testing and validating Skills  
- Improving agent performance and reducing unnecessary context  

### **3. Hands&#8209;On Build: Driver Analysis Skill**
- Multi&#8209;platform driver analysis: Windows `.sys`, macOS `.kext`, Linux modules  
- IOCTL enumeration and mapping  
- Dispatch&#8209;flow analysis (IRPs, file ops, IOKit)  
- Code&#8209;flow analysis using callgraphs and xrefs  
- Applying workflow capture in a real Skill  
- Scaffolding and integrating Skill components  

### **4. Interactive RE with Agent Automation**
- Combining manual reversing with agentic automation  
- Offloading repetitive tasks and validating hypotheses  

### **5. Extending and Iterating Skills**
- Adding workflows, tests, and examples  
- Integrating tutorials, blog posts, and prior research  
- Strategies for long&#8209;term Skill evolution  

### **6. Wrap&#8209;Up**
- Review of completed Skill  
- Next steps for building agentic RE automation  

---

# **Requirements**  
Participants must bring a laptop capable of running at least one of:

- OpenCode: https://opencode.ai/docs/  
- Claude Code: https://code.claude.com/docs/en/overview  

Additional requirements:

- Ability to `git clone` workshop materials  
- Basic familiarity with reverse engineering concepts  

---

#### **Prior Work / References**
- *Offensive Security Tool Development with Ghidra &amp; MCP* (RECON 2025) - https://www.clearseclabs.com/blog/offensive-security-tool-development-with-ghidra-recon-2025 

- *Supercharging Ghidra: Build Your Own Private Local LLM RE Stack* (Ringzer0 2025)  - https://www.clearseclabs.com/blog/supercharging-ghidra-re-llms-ringzer0-countermeasure-2025

- Agent Skills specification  
  [https://agentskills.io/home](https://agentskills.io/home)

### Target Audience

This workshop is designed for:
- Reverse engineers looking to automate their workflows
- Security researchers interested in AI-assisted analysis
- Tool developers wanting to understand agentic AI capabilities
- Anyone who attended last year&apos;s MCP workshop and wants to explore the next evolution


---</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/SHYHKM/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/SHYHKM/feedback/</feedback_url>
            </event>
            
        </room>
        
    </day>
    <day index='3' date='2026-06-21' start='2026-06-21T04:00:00-04:00' end='2026-06-22T03:59:00-04:00'>
        <room name='Grand Salon Opera' guid='0bbd3952-2f8b-5b94-bfa1-4da68fabba35'>
            <event guid='7f753de7-696c-55ef-a3a4-0149d740130a' id='48'>
                <room>Grand Salon Opera</room>
                <title>SmallWorld</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-06-21T10:00:00-04:00</date>
                <start>10:00</start>
                <duration>01:00</duration>
                <abstract>Have you ever wanted to just run that damn code you are looking at in IDA Pro? You are not alone. Even assuming you can find a working emulator for the required processor, execution requires setting up enough of a complete initial runtime environment and that is by no means easy. There are many puzzle pieces to assemble and put in the right places including register and memory contents, operating system information, libraries, and peripheral models. SmallWorld is designed to make all of that easy, in addition to supporting popular dynamic analysis platforms like Unicorn, angr and others for dynamic analysis. You can even readily move machine state between such platforms. In short, SmallWorld makes code harnessing and dynamic analysis fast and easy. We will explain all of this in detail and present three demonstrations of common but juicy use cases.</abstract>
                <slug>recon-2026-48-smallworld</slug>
                <track></track>
                <logo>/media/recon-2026/submissions/PDEBQ8/SmallWorld_CP0BwLC.svg</logo>
                <persons>
                    <person id='50'>Andy</person><person id='51'>William Janelle</person>
                </persons>
                <language>en</language>
                <description>Dynamic analysis often breaks down precisely where it&#8217;s needed most: code that can&#8217;t be easily executed because its runtime environment is unknown or incomplete. SmallWorld is a framework built to close that gap. At the heart of the problem is the need for an execution environment &#8212; everything besides your code that it depends on to run, such as the operating system, system libraries, peripherals, or initial memory state.

SmallWorld lets you construct that environment incrementally, specifying only what the code actually needs. By separating environment modeling from analysis tooling, it enables dynamic analysis of previously unreachable binary code in a tool-agnostic way. SmallWorld, furthermore, lets you run *just* the code you care about, starting execution arbitrarily deep in a binary and stubbing out or modeling functions or code snippets that you don&apos;t care to submit to analysis.

The framework currently supports 13 ISAs and integrates with 5 dynamic analysis tools, making it practical for everything from reverse engineering to vulnerability research. It contains models for a healthy fraction of libc and POSIX. Further, SmallWorld&apos;s notion of the concrete state used to initialize an emulator prior to beginning execution works as a lingua franca, allowing one to move state between dynamic analysis worlds. You can start analyzing in Unicorn, transfer state at some point to angr for symbolic execution, and later return the state to pick up emulation in Unicorn, etc.

In the first half of this talk, we&#8217;ll walk through the design and implementation of SmallWorld as well as explaining how it enables analyses that were previously infeasible. The second half of the talk will be demonstrations of salient use cases: harnessing and fuzzing of code from an embedded system, harnessing of firmware unpacking code let loose on a corpus of firmware downloads, and interactive type recovery of input parsing code.

ISAs supported include:
&#8226;	aarch64
&#8226;	amd64
&#8226;	arm32
&#8226;	i386
&#8226;	la64
&#8226;	m68k (coming soon)
&#8226;	mips32r2
&#8226;	mips64r2
&#8226;	msp430
&#8226;	ppc32
&#8226;	ppc64
&#8226;	riscv64
&#8226;	xtensa

Supported Dynamic Analysis Tools:
&#8226;	Unicorn
&#8226;	angr
&#8226;	PANDA-ng
&#8226;	Ghidra
&#8226;	AFL++

SmallWorld is open source and available at https://github.com/smallworld-re/smallworld.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/PDEBQ8/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/PDEBQ8/feedback/</feedback_url>
            </event>
            <event guid='0cd0e288-a8fe-54d6-a64a-903a0b732fc5' id='80'>
                <room>Grand Salon Opera</room>
                <title>How real-world malware disables EDR systems</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-06-21T11:00:00-04:00</date>
                <start>11:00</start>
                <duration>01:00</duration>
                <abstract>Endpoint Detection and Response (EDR) solutions are widely considered a cornerstone of modern enterprise defense. However, recent malware campaigns show adversaries increasingly focus on actively disabling security controls. Disabling EDR systems is not a trivial task, as adversaries must bypass and evade multiple detection and protection layers before they can successfully neutralize them.

This talk examines a recent intrusion chain associated with the Qilin ransomware ecosystem, where a dedicated EDR killer is deployed early in the attack lifecycle. The analyzed malware is able to identify and disable hundreds of EDR drivers from multiple vendors, effectively removing visibility and response capabilities from the target environment. The initial execution relies on DLL sideloading of a trojanized msimg32.dll, which acts as a PE loader for the EDR killer payload. The execution flow is deliberately convoluted using SEH/VEH-based control flow manipulation, effectively breaking linear disassembly and complicating static analysis. The sample further minimizes its user-mode footprint by dynamically resolving APIs and selectively switching to direct and indirect syscalls to evade userland hooks commonly used by EDR solutions. In parallel, it tampers with ETW providers to degrade telemetry visibility.

Attendees will gain a deep understanding of how modern EDR killers are engineered, including their use of undocumented APIs, kernel object manipulation, and advanced obfuscation strategies. The talk will bridge low-level reverse engineering insights with practical detection opportunities, highlighting weaknesses in current defensive models and offering concrete ideas for improving resilience against malware that targets the defenders themselves. The race is on.</abstract>
                <slug>recon-2026-80-how-real-world-malware-disables-edr-systems</slug>
                <track></track>
                
                <persons>
                    <person id='89'>Holger Unterbrink</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/GG7SEM/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/GG7SEM/feedback/</feedback_url>
            </event>
            <event guid='4479a72e-4948-554c-8657-3f512a66fb45' id='67'>
                <room>Grand Salon Opera</room>
                <title>Forgotten TEE keys in plain sight</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-06-21T13:00:00-04:00</date>
                <start>13:00</start>
                <duration>01:00</duration>
                <abstract>How safe is the data on your phone? On modern Android phones, all OS data except a minimal boot image is encrypted on the flash memory in a way that is device-bound, so that if we take out the flash and dump it we get nothing of interest. But encrypted with what?

This talk presents our research on cold-storage security on Android against an attacker with physical access. In the process, we uncovered a decade-old vulnerability on Mediatek-based Android phones (CVE-2026-20435), which allows us to recover the PIN and all user data (including Keystore content) from the flash memory of a switched-off phone. Depending on the models, it only takes a USB access and a few minutes, which we will demonstrate during the talk.</abstract>
                <slug>recon-2026-67-forgotten-tee-keys-in-plain-sight</slug>
                <track></track>
                
                <persons>
                    <person id='76'>Florent TARDIF</person>
                </persons>
                <language>en</language>
                <description>For this research, we investigated the security behind the &quot;device binding&quot; encryption on Android, on a Mediatek phone where a trusted execution environment (TEE) is used for security.

The talk is about how we reversed the Mediatek bootchain and the third party TEE (Trustonic&apos;s Kinibi, used on most Mediatek phones), but also Mediatek proprietary USB flashing protocol. This allowed us to establish exactly what the TEE uses as cryptographic root and what it does with it. This means that, from this root, we can cryptographically derive everything that needs a device binding in the TEE: flash decryption keys (metadata &amp; FBE keys), PIN encryption mechanism and the Android Keystore.

We still need to get this root, and we found out the following vulnerability: we can just ask the phone for all the data required to derive the cryptographic root with the Mediatek flashing protocol via USB, without any authentication. This impacts most Mediatek phones with a TEE.

Now, we also need an initial read of the (encrypted) flash for getting the data, which we can always do the hard way by opening the phone and reading the flash with special tooling, or for some models we can find &quot;download agents&quot; (DAs) which are Mediatek flash software addons that can readback the flash (which is supposedly harmless since it is encrypted).

Since we found a DA for our research phone, we were able to develop a PoC that, with only a USB access and a few minutes, is able to compute the cryptographic root, decrypt the flash, bruteforce the user PIN and access all the data of the phone.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/KZCARU/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/KZCARU/feedback/</feedback_url>
            </event>
            <event guid='b3d47339-9278-5376-a7c8-659080bc5d57' id='65'>
                <room>Grand Salon Opera</room>
                <title>IRON GIANT: When The Vault Becomes The Victim</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-06-21T14:00:00-04:00</date>
                <start>14:00</start>
                <duration>00:30</duration>
                <abstract>The Local Security Authority Subsystem Service (LSASS) sits at the core of Windows security, handling critical functions like authentication, credential management, and security policy enforcement. Despite the sensitive nature of the data it guards, the LSASS exposes a surprisingly wide attack surface through various legacy and modern interfaces. This talk presents the results of a comprehensive research campaign targeting three distinct vectors against this &quot;Iron Giant&quot;.</abstract>
                <slug>recon-2026-65-iron-giant-when-the-vault-becomes-the-victim</slug>
                <track></track>
                
                <persons>
                    <person id='74'>Erik Egsgard</person>
                </persons>
                <language>en</language>
                <description>First, we examine the Security Support Provider Interface (SSPI). Applications rely on SSPI for security features, such as authentication, and use the interface to send requests to the LSASS. This opens up a large attack surface for malicious applications and has been the source of  several security vulnerabilities over the years. We will dissect the architecture of these providers and reveal several new memory corruption vulnerabilities. 

Second, we explore the risks of the LSASS acting as a client. Server applications often trigger outgoing connections in scenarios that are frequently overlooked. We will demonstrate how forcing a target server to connect to a malicious endpoint exposes the SSPI client handshake code to attack. The presentation will detail these connection triggers and unveil two new Denial of Service (DoS) bugs that allow unauthenticated attackers to exhaust server resources.

Finally, we target the Remote Procedure Call (RPC) interfaces exposed within domain networks. While many of the RPC endpoints require authentication, several remain exposed to anonymous or unprivileged users. We will analyze these open interfaces and deep-dive into CVE-2025-33056, a logic vulnerability that allows unprivileged accounts to modify LSA database permissions.

In summary, we will map the diverse vulnerability surface that the LSASS exposes in modern environments, covering five distinct findings: two local memory corruptions, two remote DoS primitives, and one reliable remote Elevation of Privilege. Ultimately, we demonstrate that even the most hardened process in Windows can still be toppled if you know exactly where to push.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/LAWUEN/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/LAWUEN/feedback/</feedback_url>
            </event>
            <event guid='4b280b42-450d-585a-b1a5-bde807b89835' id='103'>
                <room>Grand Salon Opera</room>
                <title>Putting the Genie Back in the Bottle: Agentic Reverse Engineering of Claude&apos;s Security Architecture</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-06-21T14:30:00-04:00</date>
                <start>14:30</start>
                <duration>01:00</duration>
                <abstract>The proliferation of AI agents is quickly becoming one of the foremost concerns of security teams. Engineering teams are clamoring for the increase in velocity afforded by AI coding agents. Non-technical teams have noticed, and employees of all job types are asking for agentic AI tools to facilitate their work. Security teams need to have a clear understanding of how these tools operate, what their security features are, and where the security failures lie. Armed with this knowledge, security teams can enable these new agentic work paradigms while protecting all the things.

This talk presents the complete reverse engineering of Anthropic&apos;s Claude Code, Claude Desktop, and Claude Cowork. The recent release of Claude Cowork provides the LLM agent with extraordinary host privileges -- spawning VMs, mounting host directories, taking screenshots, typing into terminals, automating browsers and applications -- all decided by a language model one prompt injection away from hostile intent. We take a look at the two personalities of Claude Cowork. One component of Cowork is Claude Code, running inside a Linux VM using multiple isolation strategies to constrain LLM agent access to user resources, and another is Claude with agentic access to dive the desktop user interface, with capabilities for reading and interacting with anything on the screen.

In this talk, we also present the power of agent-assisted research and development for not only understanding the features and attack surface of these Claude agents, but we demonstrate newly-discovered vulnerabilities in components of Claude. We also identify attack surfaces that in some cases are obvious to see, and other attack surfaces that are completely surprising to discover.

We investigate binaries spanning multiple languages, including Swift, Rust, Go; two JavaScript runtimes; recovering the complete VM hardware configuration from decompiled Swift; the full vsock RPC protocol from a stripped Go guest agent; examine Claude&apos;s cloud based and local configuration systems; perform analyses of the Linux VM container isolation strategies; and uncover a hidden BLE hardware companion protocol that provides auto-approve capabilities (effectively &apos;dangerous permission mode&apos;) for every tool request the model makes. We present confirmed vulnerabilities in multiple subsystems.

Finally, we draw some conclusions about the security architecture of Claude Desktop as a whole, identifying some glaring gaps in which threats the architecture prioritizes, and which seem to have been woefully ignored. We investigate strategies for improving isolation of the agent, and consider where these might fall short.</abstract>
                <slug>recon-2026-103-putting-the-genie-back-in-the-bottle-agentic-reverse-engineering-of-claude-s-security-architecture</slug>
                <track></track>
                <logo>/media/recon-2026/submissions/DZUQYU/Todd-Manning-REcon-Title-Image_qG_cDXVzvU.webp</logo>
                <persons>
                    <person id='111'>Todd Manning</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/DZUQYU/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/DZUQYU/feedback/</feedback_url>
            </event>
            <event guid='a1bf8257-4609-5c61-a8f9-0e0b1e966bc8' id='90'>
                <room>Grand Salon Opera</room>
                <title>Black-box deobfuscation: reverse engineering binaries with your eyes closed (or almost)</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-06-21T16:00:00-04:00</date>
                <start>16:00</start>
                <duration>00:30</duration>
                <abstract>Reverse engineering is fun and profitable, but can become tedious when the code is obfuscated, especially if done by hand. Under strong obfuscation, even automated analyses based on taint or symbolic reasoning fail, becoming quickly too imprecise. Fortunately, a new hope arises with black-box deobfuscation. This is an emerging paradigm for automated deobfuscation that leverages program synthesis to simplify local, highly obfuscated code snippets. Black-box deobfuscation is especially promising because it is not affected by the syntactic complexity introduced by obfuscation. Hence, it scales to strong obfuscation, where taint or symbolic reasoning would typically fail. The Xyntia framework is the state-of-the-art of black-box deobfuscation. It is backed by recent publications in international academic conferences (ACM CCS 2021 &amp; 2025). This presentation will provide an overview of its internals and describe practical examples of successful deobfuscation with Xyntia. In particular, we will show how Xyntia can be used to deobfuscate virtual machine handlers or MBA expressions found in real code (e.g., Snapchat).</abstract>
                <slug>recon-2026-90-black-box-deobfuscation-reverse-engineering-binaries-with-your-eyes-closed-or-almost</slug>
                <track></track>
                
                <persons>
                    <person id='101'>Gr&#233;goire Menguy</person>
                </persons>
                <language>en</language>
                <description>This presentation is based on publications that are joint works with Gr&#233;goire Menguy (presenter), S&#233;bastien Bardin, Vidal Attias, Nicolas Bellec, Jean-Yves Marion, Richard Bonichon and Cauim de Souza Lima.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/3WVX3F/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/3WVX3F/feedback/</feedback_url>
            </event>
            <event guid='de7c482c-0f6a-58dc-b735-897ffefeada5' id='107'>
                <room>Grand Salon Opera</room>
                <title>Mixed Boolean-Arithmetic Obfuscation: What We Build, What We Break, and What We Can&#8217;t</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-06-21T16:30:00-04:00</date>
                <start>16:30</start>
                <duration>00:30</duration>
                <abstract>Mixed Boolean-Arithmetic (MBA) obfuscation has drawn substantial work in both construction and simplification. Yet the conversation often conflates distinct problems: linear MBA results read as general, restricted-operator techniques read as full-space solutions, benchmarks built by the same techniques they evaluate. Progress is real, but much of it has happened inside a narrow region of a much larger design space.

This talk is a benevolent rant: an attempt to map the space well enough to ask the right questions, including ones whose answers may be unwelcome (infeasibility, hard limits). It organizes the discussion around three: what we build, what we break, what we don&#8217;t know (and probably can&#8217;t), and argues the third is larger than the literature treats it.

On the construction side, we attempt to lay out a formal hierarchy of expressions, separate the operators used to build an expression from those targeted by simplification, and look at how identity equivalences are generated (iteratively, compositionally, otherwise).

On the simplification side, once an MBA expression is in hand, much of what real binaries contain is reachable with existing tools: not because the problem is solved, but because constructions in the wild align with how current attacks decompose them. The real difficulty lies in expression retrieval: MBA split across blocks or functions, destructured by optimizers, mangled by lifters, and in general entangled with virtualization and other obfuscation transformations.

We close on foundational obstacles: normal forms, what &#8220;simpler&#8221; even means. We observe that stronger constructions sit in the unexplored part of the map (with no reason to expect current tools would handle them), and ask what we&#8217;d need to push past that, with some opinionated takes on directions worth pursuing.</abstract>
                <slug>recon-2026-107-mixed-boolean-arithmetic-obfuscation-what-we-build-what-we-break-and-what-we-can-t</slug>
                <track></track>
                
                <persons>
                    <person id='120'>Arnau G&#224;mez i Montolio</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/SZE7UX/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/SZE7UX/feedback/</feedback_url>
            </event>
            <event guid='98b4bdc9-7430-5190-a3bc-63ce149ca83f' id='106'>
                <room>Grand Salon Opera</room>
                <title>Closing ceremony</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-06-21T17:00:00-04:00</date>
                <start>17:00</start>
                <duration>00:30</duration>
                <abstract>Closing ceremony</abstract>
                <slug>recon-2026-106-closing-ceremony</slug>
                <track></track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/DGELBZ/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/DGELBZ/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Soprano A' guid='ed4e98db-ac63-5754-851f-baf3e8b755a3'>
            <event guid='539aa85f-a6f4-5863-aa6e-17addc8bad22' id='38'>
                <room>Soprano A</room>
                <title>Reversing Framework Mobile Applications with Open Source Tools</title>
                <subtitle></subtitle>
                <type>Workshop (3hrs)</type>
                <date>2026-06-21T13:00:00-04:00</date>
                <start>13:00</start>
                <duration>03:00</duration>
                <abstract>As malware authors shift tactics, they increasingly hide malicious functionality within popular mobile application frameworks, allowing them to evade static and dynamic analysis. This workshop will introduce participants to some of the more popular frameworks used in App development as well as techniques leveraging open source tools to approach reverse engineering said mobile applications for malware analysis and defensive threat intelligence.

The workshop will comprise two sections, one for Flutter and Unity. Both will begin with a quick foundational overview of the respective framework, including the basics on the Dart and Unity programming languages as well as a high-level overview of the Dart VM, its compilation models, and the resulting &quot;snapshot&quot; artifacts that analysts encounter. We then explain how both frameworks present unique obstacles for reverse engineering and walk through different techniques and tools (Il2CPPDumper and Blutter) used to produce higher-level code, as well as their shortcomings and limitations.

Students attending will get hands-on practice reversing In-the-Wild Android malware built with each respective framework, and be exposed to more advanced anti-analysis techniques employed by framework malware to impede dynamic analysis.</abstract>
                <slug>recon-2026-38-reversing-framework-mobile-applications-with-open-source-tools</slug>
                <track></track>
                
                <persons>
                    <person id='38'>Nick Anderson, Roy Tu</person><person id='77'>Roy Tu</person>
                </persons>
                <language>en</language>
                <description>Students attending this workshop should come prepared with a laptop (Linux, or Windows + WSL/Ubuntu) with the following tools installed:
- A working terminal
- Git
- Ghidra
- Blutter: https://github.com/worawit/blutter
- il2cppdumper: https://github.com/Perfare/Il2CppDumper
- ilspy/dnspy: https://github.com/dnSpy/dnSpy 
- Maybe Python if you&apos;re feeling scripty.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/U3DWWA/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/U3DWWA/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Soprano B' guid='206dc37d-af7a-5bff-821b-42bfd62746ce'>
            <event guid='2a651af8-a650-59a5-9714-9cb700583ed4' id='15'>
                <room>Soprano B</room>
                <title>Orchestrating Chaos: Defeating Guloader&apos;s VEH and Obfuscation with Unicorn</title>
                <subtitle></subtitle>
                <type>Workshop (3hrs)</type>
                <date>2026-06-21T13:00:00-04:00</date>
                <start>13:00</start>
                <duration>03:00</duration>
                <abstract>Standard sandboxes and automated scanners fall short when faced with the modern state of **Guloader**. Its reliance on **Vectored Exception Handling (VEH)** to redirect control flow through intentional exceptions creates a &quot;black box&quot; for traditional debuggers and linear disassemblers. This 3 hour workshop bypasses the basics and dives straight into the heavy lifting of modern malware deobfuscation.

We will perform a deep-dive dissection of a multi-stage infection chain, moving rapidly through PowerShell loaders into the core of the matter: **multi-layered shellcode**. Participants will reverse-engineer the &quot;exception soup&quot; of Guloader, mapping out how it uses various CPU instructions and a custom handler to mask its code flow.

The highlight of the session is a transition from manual analysis to **programmatic automation**. We will leverage the **Unicorn emulator framework** to build a custom configuration extractor capable of reconstructing non-contiguous encrypted payloads that stay hidden from static analysis.</abstract>
                <slug>recon-2026-15-orchestrating-chaos-defeating-guloader-s-veh-and-obfuscation-with-unicorn</slug>
                <track></track>
                
                <persons>
                    <person id='14'>Mark Lim</person>
                </persons>
                <language>en</language>
                <description>**Key Technical Deep-Dives:**

* **The VEH Maze:** Bypassing exception-based control flow flattening.  
* Extracting secrets hidden via **Constant Unfolding**  
* **Emulation-Based Solution:** Using Python and Unicorn to automate the extraction of C2 and multiple encrypted strings from obfuscated DWORDS.  
* **Indirect Syscalls:** Identifying and neutralizing EDR-evasion techniques within shellcode.

## Workshop Focus

* **Recent variants of real-world malware samples**: Unlike theoretical exercises, this workshop utilizes live, updated malware samples of **Guloader**. This immersive approach ensures that participants gain experience with the actual challenges posed by modern threats.  
* **Chained Attack Scenarios**: The workshop will simulate a multi-stage attack where **Guloader** acts as the initial entry vector, deploying and executing payload. This chained scenario highlights how different malware types collaborate in complex attacks, providing a holistic view of the threat landscape.  
* **Practical, Hands-On Experience**: The entire workshop is fundamentally practical. Attendees will actively engage in analyzing malware, utilizing industry-standard tools and techniques. This hands-on methodology fosters deep understanding and skill development.  
* **The ratio of presentation to hands-on training**: **90% hands-on**

## Workshop Outline

1. **Phase 1: Shellcode Extraction &amp; Context Reconstruction**  (10 min)  
* **Recon-Exclusive:** PowerShell obfuscation analysis is **removed**. Attendees are provided a de-obfuscated script solely to extract the shellcode.  
* **Vector Isolation:** Isolate the specific Windows callback and their parameters used for execution transfer to replicate the initial register state for the loader.


2. **Phase 2: Defeating Indirect Syscalls &amp; Loader Internals** (30min)  
* **Heuristic Analysis:** Identifying and bypassing &quot;Hell&apos;s Gate&quot; and related indirect syscall techniques used to blind EDRs.  
* **Gadget Hunting:** Manually locating the &quot;gadgets&quot; the loader uses to construct syscalls, rather than relying on automated tool output.  
* **Opaque Predicates:** Analyzing and defeating the unpacking loops that guard the next-stage shellcode, preparing the binary for the core VEH analysis.

Break (10 min)

3. **Phase 3: Windows Internals &amp; The VEH State Machiner** (60 min)  
     
   *This section represents the core &quot;Delta&quot; from previous workshops, focusing on undocumented Windows structures.*  
     
   * **Manual Traversal of Windows 10 Structure:** Instead of relying on conventional debugger commands, participants will manually locate the registered Vector Exception Handler (VEH) function. This involves writing an IDA script to walk the undocumented `_LdrpVectorHandlerList` structure in memory and overcoming pointer encoding challenges.  
   * **Reversing `AddVectoredExceptionHandler`:** A deep dive into the kernel32 implementation of exception registration to understand how Guloader hijacks this mechanism.  
   * **Context Manipulation &amp; RIP Hijacking:** Analyzing how the handler modifies the `PCONTEXT` structure (specifically `Eip`/`Rip`) to &quot;skip&quot; variable-length junk bytes and resume execution at dynamically calculated offsets.  
   * **Anti-Debug Logic:** Decompiling the handler&#8217;s logic to see how it inspects Hardware Breakpoints (DR0-DR7) within the context record to detect analysis tools.  
     

Break (10 min)

4. **Phase 4: Advanced Emulation &amp; Custom Instrumentation** (60 min)  
   *Moving beyond &quot;using Unicorn,&quot; this phase focuses on &quot;fixing Unicorn&quot; to handle hostile code.*  
   * **Solving the Halting Problem:** Participants will write a custom Unicorn harness that handles `UC_MEM_READ_UNMAPPED` and `UC_HOOK_INTR` events to emulate the OS loader&apos;s exception dispatching behavior.  
   * **Configuration Extraction:** Automating the decryption of non-contiguous strings and C2 configurations, effectively bypassing the need for a fully functional debugger.  
   * **Optimization:** mitigating the performance penalties of Python-based emulation when handling millions of instructions.  
     

Detailed explanations and working solutions will be provided for all exercises to support attendees&apos; learning.

## Take away from this workshop

* **A Weaponized Emulation Harness:** Walk away with a robust, custom-built Python-Unicorn harness specifically engineered to bridge the gap between static emulation and dynamic Windows Exception Handling (VEH). You will own the code to simulate complex OS-level callbacks that standard emulators fail on.  
* **Automated Deobfuscation Logic:** Master the implementation of a custom hook management within Unicorn to trace, intercept, and defeat junk code and control-flow flattening without touching the debugger.  
* **Genericizing the Solution:** Learn how to transform a specific Guloader solution into a reusable methodology for defeating other exception-based obfuscators (like those found in modern Dridex or Ursnif variants) by leveraging purely emulated execution traces.

## What audience needs to bring to this workshop

* Laptops that have at least **8GB RAM** and **100GB of free SSD space**  
* Due to EULA of various software. Each student is to set up a Windows 10 VM prior to the workshop. This VM has to contain the following tools:  
  * Latest version of Visual Studio Code with Powershell extension (from Microsoft)  
  * IDA Free 9.2+ (Note: All scripts utilized in this workshop have been strictly tested to work on IDA Pro and Free 9.2+).  
  * Python 3.13 (x64)  
  * Unicorn Framework python module ([https://www.unicorn-engine.org/](https://www.unicorn-engine.org/))  
  * SystemInformer (for dumping memory pages)  
  * Decompiler will not be necessary for this workshop

## Target Audience

* Mid to senior-level cybersecurity practitioners  
* Malware analysts, incident responders, threat hunters  
* Professionals seeking hands-on malware analysis skills

## Skills required

* **Fluent x86/x64 Assembly:** Must be comfortable manually tracing control flow, stack operations, and register states without relying exclusively on decompilers (as the obfuscation renders Hex-Rays/Ghidra ineffective).  
* **Intermediate Python Scripting:** Ability to write functional scripts using external libraries. Familiarity with Python&apos;s `struct` module or memory mapping concepts is critical for the emulation phase.  
* **Windows Internals Fundamentals:** A conceptual understanding of how Windows handles exceptions (VEH/SEH), Context Records, and hardware breakpoints is highly recommended.  
* **IDA Pro Proficiency:** Standard navigation skills (following cross-references, patching bytes, defining code/data) are assumed.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/Y7Z98G/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/Y7Z98G/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Soprano C' guid='d7b91d51-8c8b-549d-b307-f47264645402'>
            <event guid='1b351a67-dae3-5ca3-ba69-5d35fe5e2420' id='113'>
                <room>Soprano C</room>
                <title>BNSQL/IDASQL/GhidraSQK hands on: Agentic and automatic reverse engineer</title>
                <subtitle></subtitle>
                <type>Workshop (3hrs)</type>
                <date>2026-06-21T13:00:00-04:00</date>
                <start>13:00</start>
                <duration>03:00</duration>
                <abstract>Why have to reverse engineer by hand anymore? It is now a waste of time to use any user interfaces?
In this age and era, it is not important at all, just focus on prompting, work on your instruction files and custom skills.
Join me in this hands on session on how to setup and configure the tool of your choice IDASQL (AI), BNSQL (Binary Ninja), or GhidraSQL (for Ghidra).
I will teach you how to use these xSQL tools with your coding harness of choice.</abstract>
                <slug>recon-2026-113-bnsql-idasql-ghidrasqk-hands-on-agentic-and-automatic-reverse-engineer</slug>
                <track></track>
                
                <persons>
                    <person id='135'>Elias</person>
                </persons>
                <language>en</language>
                <description>Why have to reverse engineer by hand anymore? It is now a waste of time to use any user interfaces?
In this age and era, it is not important at all, just focus on prompting, work on your instruction files and custom skills.
Join me in this hands on session on how to setup and configure the tool of your choice IDASQL (AI), BNSQL (Binary Ninja), or GhidraSQL (for Ghidra).
I will teach you how to use these xSQL tools with your coding harness of choice.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.recon.cx/recon-2026/talk/B7GUGA/</url>
                <feedback_url>https://cfp.recon.cx/recon-2026/talk/B7GUGA/feedback/</feedback_url>
            </event>
            
        </room>
        
    </day>
    
</schedule>
