BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Clew: Untangling Evasive Malware with Per-Sample Fuz
 zing Seeds\n   Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team 
 | Malware |\n   DEF CON Demo Labs\n   When: Saturday\, Aug 8\, 11:00 - 11:
 45 PDT\n   Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - [1]Map\n
 \n   Description:\n\n   Clew is an automated fuzzing-candidate extraction 
 pipeline for\n   environment-sensitive malware analysis. Evasive malware r
 outinely\n   queries its execution environment via Windows API calls to hi
 de\n   functionality until specific environmental conditions are met. By\n
    hooking these API calls\, a fuzzer can reveal such execution paths that
 \n   are typically hidden during standard analysis. No seed corpus of\n   
 environmental fuzzing candidates currently exists for this\n   application
 . As a result\, current API-hooking fuzzers rely on\n   hand-written\, sam
 ple-agnostic starting values and blind mutations that\n   cannot scale to 
 the diverse evasion techniques seen in sophisticated\n   samples. Clew add
 resses this by analyzing each PE32 binary and\n   producing a per-sample s
 eed corpus of candidate API return values that\n   downstream environmenta
 l fuzzers use to systematically uncover hidden\n   execution paths.\n\n   
 Speakers:Kyler McElroy\,Anita Ding\,Daniel Koranek\n\n   SpeakerBio:  Kyle
 r McElroy\n\n   McElroy\, a second lieutenant and developmental engineer i
 n the United\n   States Air Force\, is pursuing a master's in computer sci
 ence with an\n   AI focus at the Air Force Institute of Technology. His re
 search\n   focuses on using machine learning and automated analysis to unc
 over\n   hidden behaviors in evasive malware. He is an alumnus of the ACE 
 Cyber\n   Leadership Development program\, where he authored S.A.N.D (Synt
 hetic\n   Adversarial and Natural Data Generation) under the Air Force Res
 earch\n   Laboratory.\n\n   SpeakerBio:  Anita Ding\n\n   Anita Ding is a 
 second lieutenant and cyber operations officer in the\n   United States Ai
 r Force\, is pursuing a master's in cyber operations\n   with an AI focus 
 at the Air Force Institute of Technology. Her\n   research focuses on LLM-
 orchestrated red team automation and graph\n   neural networks for attack-
 path scoring in Active Directory\n   environments. She earned a B.A. in Co
 mputer Science from UC Berkeley\,\n   where she conducted research at the 
 Berkeley AI Research Lab and the\n   Berkeley Risk and Security Lab. She i
 s also an alumna of the ACE Cyber\n   Leadership Development program\, whe
 re she designed a CTF challenge for\n   the British Army's Defence Cyber M
 arvel exercise.\n\n   SpeakerBio:  Daniel Koranek\n\n   Dr. Daniel Koranek
  is an Assistant Professor of Computer Science at\n   the Air Force Instit
 ute of Technology (AFIT) and a two-time graduate\n   of AFIT in cyber oper
 ations (2010\, M.S.) and computer science (2022\,\n   Ph.D.)\, where his r
 esearch interests focus on the intersection of\n   artificial intelligence
 /machine learning and cybersecurity. This\n   includes using AI/ML to enha
 nce cybersecurity and using vulnerability\n   assessment and secure design
  techniques to improve AI deployments. He\n   has spent most of his career
  on reverse engineering and vulnerability\n   assessment of embedded syste
 ms\, and overlapping AI and cybersecurity\n   drove Dr. Koranek's disserta
 tion research on using the reverse\n   engineering tool Binary Ninja to vi
 sualize explanations of malware\n   classifications.\n\n   '\n\n   1. #LVC
 CW_Level1_Hall3\n\n\n
DTEND:20260808T184500Z
DTSTART:20260808T180000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)
SUMMARY:Clew: Untangling Evasive Malware with Per-Sample Fuzzing Seeds
END:VEVENT
END:VCALENDAR
