
John Althouse

2026
One of the most difficult challenges of supply-chain malware is the sample variety and the need for cross-platform execution to extract indicators. Also, the more components are involved in an attack, the more likely an analyst is to return to the analysis and dig deeper. The gift of Time-Travel Debugging is the ability to create an exhaustive recording of process execution deterministically, so that the human or AI analyst can query the recording like a database, write custom hooks, and perform taint analysis on transformed data. What if we could get record-and-replay capability for the whole system and all its interactions?
In this workshop, we will demo and share an open-source malleable sandbox based on a reboot of a QEMU-based introspection project that supports the three major operating system families and any sample they execute (with room for more). The first half of the workshop will be demos, but the second half will be a stress test driven by the attendees (you!). Bring malware, and we'll see how deep our dynamic introspection can go.
About John Althouse
John Althouse and team are the inventors behind network fingerprinting methods JA3, JARM, and JA4+. These methods are built into nearly every tool that handles network traffic and utilized by threat hunters around the world.
John is the founder of FoxIO, a company dedicated to continued research and development of network fingerprinting and cyber security solutions for impossible problems.
