BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsides-bristol-2026//talk//UG3UNB
BEGIN:VTIMEZONE
TZID:Europe/London
BEGIN:DAYLIGHT
DTSTART:20250822T000000
TZNAME:BST
TZOFFSETFROM:+0100
TZOFFSETTO:+0100
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T020000
RDATE:20261025T020000
TZNAME:GMT
TZOFFSETFROM:+0100
TZOFFSETTO:+0000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T020000
RDATE:20270328T020000
TZNAME:BST
TZOFFSETFROM:+0000
TZOFFSETTO:+0100
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Ghost in the Kernel: Hunting BYOVD After Microsoft’s 2026 Driver
  Trust Shift - Richard Dosumu
DTSTART;TZID=Europe/London:20260822T133000
DTEND;TZID=Europe/London:20260822T141000
DTSTAMP:20260812T231611Z
UID:pretalx-bsides-bristol-2026-UG3UNB@pretalx.com
DESCRIPTION:BYOVD attacks have helped ransomware crews and advanced actors
  disable security tools\, hide activity\, and move from admin control towa
 rds the kernel. Microsoft’s 2026 Windows Driver Policy is a major harden
 ing step\, but it does not make kernel-driver risk disappear. This talk ex
 plains what the new policy blocks\, what it only audits\, and what defende
 rs still need to hunt. Using cases including BlackByte\, POORTRY/STONESTOP
 \, and Lazarus/FudModule\, we will build a practical approach to driver in
 ventory\, Code Integrity events\, audit-mode visibility\, and reducing ker
 nel attack surface.
LOCATION:Track 1
URL:https://pretalx.com/bsides-bristol-2026/talk/UG3UNB/
END:VEVENT
END:VCALENDAR
