About This Workshop
Modern digital forensic investigations often lead analysts to suspicious software artifacts, such as binaries recovered during incident response. In IoT environments, this frequently involves firmware images extracted from embedded devices. While identifying such artifacts is well-supported, determining their root cause – particularly how known vulnerabilities manifest within compiled firmware binaries – remains a challenging task, especially in the absence of source code and complex analysis tooling.
In this workshop, we present an interactive system that enables analysts to express and evaluate forensic hypotheses as high-level queries over static data flow. Participants will engage in a hands-on exercise centered on cross-binary n-day vulnerabilities drawn from the NIST CVE database, focusing on vulnerabilities embedded within IoT firmware.
Framed as a post-incident investigation, attendees will be given a known CVE and a redacted exploit (PoC), and tasked with identifying the precise instruction-level paths within the firmware binary that enabled the attack. Through guided queries, participants will locate root-cause instructions and trace the propagation of attacker-controlled data across firmware components, demonstrating how abstracted dataflow analysis can support practical forensic workflows in embedded devices.
- Lead Instructor(s): Anthony Andreoli
- Bio: Anthony Andreoli is a Ph.D. researcher at Concordia University’s Security Research Center in Montreal, Quebec, Canada. His work focuses on binary code understanding and pattern detection for vulnerability analysis, detection, and prevention. An experienced teacher and communicator of ideas, he has been teaching computer science related material for over 5 years to students at both the undergraduate and graduate levels. He spends his free time composing instrumentals, endlessly inquiring about the nature of existence and human behaviour, and has an extremely shrunken perception of time.
- Social Media:
- Audience Skill Level: All skill levels
- Format: In-person is favoured, however the entire workshop can be followed virtually.
- Workshop Requirements: Come with an open mind ready to learn new ways to think about the vulnerability landscape.
- Workshop Preparation Material: Nothing to prepare. Everything you need will be provided on the spot… But bring a laptop. We will be taking the pulse of the room around the topic of AI in your particular field(s), so gather your thoughts beforehand.
- Short Sales Pitch for Audience. LLMs are reshaping vulnerability detection — and you can too. Join this four-part DFRWS workshop for a crash course on AI in the vuln. detection landscape, a threat brief on the resurrection of end-of-life devices, hands-on root-cause analysis of exploited network gear (feat. LLMs), and a closing session on mind expansion — how to think past the obvious.
Workshop Speakers