BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2026//talk//3D9FXD
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251022T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:GoaTracer: A Hybrid Dynamic Analysis Platform - Pierre MARTY\, Fab
 rice Sabatier\, ROYER
DTSTART;TZID=Europe/Luxembourg:20261022T080000
DTEND;TZID=Europe/Luxembourg:20261022T083000
DTSTAMP:20261009T054100Z
UID:pretalx-hack-lu-2026-3D9FXD@pretalx.com
DESCRIPTION:Modern malware increasingly relies on packing\, process inject
 ion\, self-modifying code\, and anti-analysis techniques that challenge tr
 aditional dynamic analysis platforms. Existing approaches often force anal
 ysts to choose between fine-grained execution visibility and stealth\, whi
 le many advanced solutions remain proprietary\, difficult to reproduce\, o
 r poorly suited for extracting reusable low-level execution traces for res
 earch and reverse purposes.\n\nIn this paper\, we present GoaTracer\, an o
 pen-source dynamic binary analysis platform for Windows that combines in-g
 uest binary instrumentation with hypervisor-level virtual machine introspe
 ction. This hybrid architecture provides instruction-level visibility whil
 e limiting the observable footprint exposed to the analyzed program\, impr
 oving resistance against common anti-analysis and anti-debugging mechanism
 s.\n\nBeyond execution tracing\, GoaTracer is designed as a low-level anal
 ysis foundation from which higher-level semantic information can be recons
 tructed automatically. The platform introduces a wave-based execution mode
 l that isolates dynamically generated execution stages and enables the rec
 onstruction of unpacked binaries\, shellcodes\, control-flow graphs\, call
  graphs\, and behavioral artifacts associated with malware activity. GoaTr
 acer also captures system interactions with parameters and maps observed b
 ehaviors to MITRE ATT&CK and Malware Behavior Catalog (MBC) techniques.\n
 \nWe describe the architecture and implementation of GoaTracer and demonst
 rate its practical capabilities through the analysis of the ClaimLoader ma
 lware\, showing how the platform reconstructs multi-stage execution flows
 \, extracts intermediate payloads\, and reveals behaviors that remain diff
 icult to observe with conventional dynamic analysis systems.
LOCATION:Europe
URL:https://pretalx.com/hack-lu-2026/talk/3D9FXD/
END:VEVENT
END:VCALENDAR
