FoxIO

John Althouse

John Althouse

2026

Under The Wire - Detecting Targeted Attacks against US Government Networks with JA4 and X509 Chain Validation

One of the most difficult challenges of supply-chain malware is the sample variety and the need for cross-platform execution to extract indicators. Also, the more components are involved in an attack, the more likely an analyst is to return to the analysis and dig deeper. The gift of Time-Travel Debugging is the ability to create an exhaustive recording of process execution deterministically, so that the human or AI analyst can query the recording like a database, write custom hooks, and perform taint analysis on transformed data. What if we could get record-and-replay capability for the whole system and all its interactions?  

In this workshop, we will demo and share an open-source malleable sandbox based on a reboot of a QEMU-based introspection project that supports the three major operating system families and any sample they execute (with room for more). The first half of the workshop will be demos, but the second half will be a stress test driven by the attendees (you!). Bring malware, and we'll see how deep our dynamic introspection can go.


About John Althouse

John Althouse and team are the inventors behind network fingerprinting methods JA3, JARM, and JA4+. These methods are built into nearly every tool that handles network traffic and utilized by threat hunters around the world. 

John is the founder of FoxIO, a company dedicated to continued research and development of network fingerprinting and cyber security solutions for impossible problems.