Loading…
This event has ended. Visit the official site or create your own event on Sched.
It is an annual, community-driven information security conference held in Prague. The event provides a platform for cybersecurity professionals, enthusiasts, and researchers to share knowledge, exchange ideas, and discuss the latest trends in the field. It’s a unique opportunity to connect with like-minded individuals, expand professional networks, and stay informed about the ever-evolving cybersecurity landscape.
More info at www.bsidesprg.cz

Tuesday April 21, 2026 13:00 - 17:00 CEST
In this hands-on workshop you will learn how to obfuscate your payloads with a custom VM. This will help to evade signature detections and make reverse engineering more difficult. Participants will walk away with new tooling they can try out in the field right away!

In this workshop we will leverage the RISC-V architecture and the LLVM ecosystem to build a simple obfuscation pipeline. The VM interpreter code is small and once it is loaded, you do not need to allocate additional executable pages to execute arbitrary payloads.

Covered topics:
  • Introduction to VM-based obfuscation 
  • Basics of the RISC-V architecture 
  • Compiling payloads for the RISC-V architecture 
  • Obfuscating the VM interpreter for evasion - VM Hardening to complicate reversing the payloads - Building a basic C2 framework (as time allows)


The bulk of the work will be done in a GitHub Codespace (Linux), which makes it easy for participants to get started. However, the final payloads need to be executed in a Windows VM (which you have to prepare beforehand).


Note: You need basic C programming and Linux command line experience to follow along with the workshop. Reverse engineering experience is definitely a plus!


The start of the workshop is a hands-on version of a blog post I was the main author of: RISC-Y Business: Raging against the reduced machine, specifically tailored for red teamers. The second half will contain currently-unpublished research, discussing obfuscation and evasion techniques which should be interesting to conference participants.


Speakers
avatar for Duncan Ogilvie

Duncan Ogilvie

Reverse Engineer
Reverse engineer, creator of x64dbg and other open source projects. Love binary analysis and Windows internals.
Tuesday April 21, 2026 13:00 - 17:00 CEST
Novotel - WR1 Kateřinská 38, Nové Město, 120 00 Praha-Praha 2, Czechia

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link