Evading in Plain Sight: How Adversaries Beat User-Mode Protection Engines @FIRSTdotorg
Evading in Plain Sight: How Adversaries Beat User-Mode Protection Engines  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 13 hours ago
Omri Misgav (Independent, IL)

Omri is an independent security researcher with over a decade of experience in the field. Previously, he headed a security research group in Fortinet's FortiGuard Labs, focused on OS internals, malware and vulnerabilities. Omri joined Fortinet following enSilo's acquisition, where he was the security research team leader and spearheaded the development of new offensive and defensive techniques. Before that, He led the R&D of unique network and endpoint security products for large-scale enterprise environments and was part of an incident response team, conducting investigations and hunting for nation-state threat actors. Omri is a past speaker in various conferences such as DEF CON, AVAR, BSideLV, BSidesTLV and others.
--
Following the largest global IT outage in history on last July, which disrupted numerous services and industries, many took to the public stage to advocate against allowing endpoint security vendors to design and deploy agents that are kernel-based, even prompting regulators to weigh in.User mode-based engines are already integral piece of many endpoint-oriented security solutions from different malware analysis tools to various commercial products like AVs, EDRs, sandboxes and more. This kicked off research to map the entire threat landscape to assess the impact of the proposed design shift. Analyzing and reverse-engineering over 40 different malware families and open-source projects yielded an in-depth understanding and insights into attackers' tradecraft.This talk will explore all the unique tactics and techniques which malware authors and red teamers have developed to beat user mode-based protection engines, showcasing their very fundamental design flaw: the reliance on the same execution environment that is intended to be protected. The talk will also highlight drawbacks of the various methods and provide a detection scheme focusing on runtime and forensics indicators to give a leg up to CISRTs, malware researchers and detection engineers facing this issue.
Evading in Plain Sight: How Adversaries Beat User-Mode Protection EnginesVulnrichment PlaygroundBenchmarking Your Constituency: A Practical Framework for CERTs with Results from Academic SectorBillions of Indicators, Zero Action: How We Fixed ThatCritical SaaS, Critical Blind Spots: A Detection Engineers Field Guide to SaaS AttacksThe Hidden Cost of CVEs: Can CSAF and VEX Change the Equation?The SOC Of The Future… The Future Is NowOne SOC, The Whole SOC, and Nothing But The SOC, So Help MeEiffel: A Tool to Oversee Incident Response From the HeightsProtecting Customers Through Smarter OSS ManagementOperationalizing AIBOMs: Extending Vulnerability Management to AI Models and DatasetsMalice in the Modules - How NPM Became a Supply-Chain Battleground?
FIRST |

Evading in Plain Sight: How Adversaries Beat User-Mode Protection Engines

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER