Richard Dosumu

Richard Dosumu is a cybersecurity practitioner, independent researcher, Product Lead and founder of OctaTech, a UK-based digital product company building accessible tools for cybersecurity development, learning, and productivity. He holds an MSc in Cyber Security and Human Factors from Bournemouth University and writes on cybersecurity, AI, digital resilience, and human-centred security. Through CyberYearn and OctaTech’s wider product work, Richard is focused on improving cybersecurity literacy by making security guidance clearer, more practical, and more accessible to learners, early-career professionals, and real-world teams.


Session

08-22
13:30
40min
Ghost in the Kernel: Hunting BYOVD After Microsoft’s 2026 Driver Trust Shift
Richard Dosumu

BYOVD attacks have helped ransomware crews and advanced actors disable security tools, hide activity, and move from admin control towards the kernel. Microsoft’s 2026 Windows Driver Policy is a major hardening step, but it does not make kernel-driver risk disappear. This talk explains what the new policy blocks, what it only audits, and what defenders still need to hunt. Using cases including BlackByte, POORTRY/STONESTOP, and Lazarus/FudModule, we will build a practical approach to driver inventory, Code Integrity events, audit-mode visibility, and reducing kernel attack surface.

Track 1