Black Hat USA 2018 - Windows Offender Reverse Engineering Windows Defenders Antivirus Emulator @HackersOnBoard
Black Hat USA 2018 - Windows Offender Reverse Engineering Windows Defenders Antivirus Emulator  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 5 days ago
Windows Defender's mpengine.dll implements the core of Defender antivirus' functionality in an enormous ~11 MB, 45,000+ function DLL.

In this presentation, we'll look at Defender's emulator for analysis of potentially malicious Windows PE binaries on the endpoint. To the best of my knowledge, there has never been a conference talk or publication on reverse engineering the internals of any antivirus binary emulator before.

I'll cover a range of topics including emulator internals (bytecode to intermediate language lifting and execution; memory management; Windows API emulation; NT kernel emulation; file system and registry emulation; integration with Defender's antivirus features; the virtual environment; etc.), how I built custom tooling to assist in reverse engineering and attacking the emulator; tricks that malicious binaries can use to evade or subvert analysis; and attack surface within the emulator. I'll share code that I used to instrument Defender and IDA scripts that can be helpful in reverse engineering it.
Black Hat USA 2018 - Windows Offender Reverse Engineering Windows Defenders Antivirus EmulatorDEF CON 27 - Joshua Maddux - API-Induced SSRF How Apple Pay Scattered Vulnerabilities Across the WebDEF CON 27 - The Dark Tangent - Closing CeremoniesOver-the-Air: How we Remotely Compromised the Gateway, BCM, and Autopilot ECUs of Tesla CarsBlack Hat USA 2018 - Outsmarting the Smart CityBlack Hat USA 2018 - Meltdown Basics, Details, ConsequencesBlack Hat USA 2018 - An Attacker Looks at Docker Approaching Multi Container ApplicationsBlack Hat USA 2018 - Every ROSE has its Thorn The Dark Art of Remote Online Social EngineeringDEF CON 27 - albinowax - HTTP Desync Attacks Smashing into the Cell Next DoorDEF CON 27 - Jesse Michael - Get Off the Kernel if You Cant DriveDEF CON 27 - Joe Grand Kingpin - Behind the Scenes of the DEFCON 27 BadgeBlack Hat USA 2018 - A Brief History of Mitigation The Path to EL1 in iOS 11
HackersOnBoard |

Black Hat USA 2018 - Windows Offender Reverse Engineering Windows Defender's Antivirus Emulator

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER