Uploaded August 2025 | Updated September 2026, 13 hours ago
Omri Misgav (Independent, IL)
Omri is an independent security researcher with over a decade of experience in the field. Previously, he headed a security research group in Fortinet's FortiGuard Labs, focused on OS internals, malware and vulnerabilities. Omri joined Fortinet following enSilo's acquisition, where he was the security research team leader and spearheaded the development of new offensive and defensive techniques. Before that, He led the R&D of unique network and endpoint security products for large-scale enterprise environments and was part of an incident response team, conducting investigations and hunting for nation-state threat actors. Omri is a past speaker in various conferences such as DEF CON, AVAR, BSideLV, BSidesTLV and others.
--
Following the largest global IT outage in history on last July, which disrupted numerous services and industries, many took to the public stage to advocate against allowing endpoint security vendors to design and deploy agents that are kernel-based, even prompting regulators to weigh in.User mode-based engines are already integral piece of many endpoint-oriented security solutions from different malware analysis tools to various commercial products like AVs, EDRs, sandboxes and more. This kicked off research to map the entire threat landscape to assess the impact of the proposed design shift. Analyzing and reverse-engineering over 40 different malware families and open-source projects yielded an in-depth understanding and insights into attackers' tradecraft.This talk will explore all the unique tactics and techniques which malware authors and red teamers have developed to beat user mode-based protection engines, showcasing their very fundamental design flaw: the reliance on the same execution environment that is intended to be protected. The talk will also highlight drawbacks of the various methods and provide a detection scheme focusing on runtime and forensics indicators to give a leg up to CISRTs, malware researchers and detection engineers facing this issue.
Omri Misgav (Independent, IL)
Omri is an independent security researcher with over a decade of experience in the field. Previously, he headed a security research group in Fortinet's FortiGuard Labs, focused on OS internals, malware and vulnerabilities. Omri joined Fortinet following enSilo's acquisition, where he was the security research team leader and spearheaded the development of new offensive and defensive techniques. Before that, He led the R&D of unique network and endpoint security products for large-scale enterprise environments and was part of an incident response team, conducting investigations and hunting for nation-state threat actors. Omri is a past speaker in various conferences such as DEF CON, AVAR, BSideLV, BSidesTLV and others.
--
Following the largest global IT outage in history on last July, which disrupted numerous services and industries, many took to the public stage to advocate against allowing endpoint security vendors to design and deploy agents that are kernel-based, even prompting regulators to weigh in.User mode-based engines are already integral piece of many endpoint-oriented security solutions from different malware analysis tools to various commercial products like AVs, EDRs, sandboxes and more. This kicked off research to map the entire threat landscape to assess the impact of the proposed design shift. Analyzing and reverse-engineering over 40 different malware families and open-source projects yielded an in-depth understanding and insights into attackers' tradecraft.This talk will explore all the unique tactics and techniques which malware authors and red teamers have developed to beat user mode-based protection engines, showcasing their very fundamental design flaw: the reliance on the same execution environment that is intended to be protected. The talk will also highlight drawbacks of the various methods and provide a detection scheme focusing on runtime and forensics indicators to give a leg up to CISRTs, malware researchers and detection engineers facing this issue.










