2026-09-24 –, Main Track
Traditional reverse engineering of edge networking firmware frequently stall at the system emulation layer due too proprietary headers, missing vendor kernel sources, and strict dependencies on physical hardware controllers. This presentation demonstrates applied User-Mode Emulation and Environment Spoofing techniques via PRoot and QEMU-ARM-Static to execute, debug, and dynamically analyse malicious edge-device implants without a native kernel. By systematically bypassing hardware configuration dependencies through virtual memory reservation, RAM capacity spoofing, and writable system-file topology bind-mounting. Researchers should be able too successfully stabilise and interrogate volatile system management daemons reliably for reverse engineering and remediation.
A Security Engineer with Advanced Practices at Google. He primarily supports frontline intelligence operations and incident response investigations.