RE-Thinking: Modernizing the Malware Analyst

Joseph Edwards

BSides NYC 2024 · Day 1 · Tech - Red

Joseph Edwards' talk, "RE-Thinking: Modernizing the Malware Analyst," delves into the evolving landscape of malware analysis, highlighting critical gaps in current educational approaches and professional practices. Edwards, an Incident Responder and Forensic Tools Developer at SentinelOne, draws upon his five to six years of experience to advocate for a significant shift in how analysts are trained and equipped to handle sophisticated threats. The core of his presentation centers on the need for greater flexibility, customizability, and deep system introspection in malware analysis tools, moving beyond traditional, GUI-centric methods.

AI review

Edwards identifies a real and underappreciated problem — the GUI-tool mindset baked into foundational malware analysis education — and proposes a sensible tooling hierarchy: emulation for shellcode, DBI for behavioral inspection, malleable sandboxes for production. The content is competent and the framing is honest, but the talk covers ground that experienced analysts already know, and the 'demo' amounts to two screenshots. Solid for a BSides audience, forgettable at anything larger.

Watch on YouTube