
Joseph Edwards

2026
One of the most difficult challenges of supply-chain malware is the sample variety and the need for cross-platform execution to extract indicators. Also, the more components are involved in an attack, the more likely an analyst is to return to the analysis and dig deeper. The gift of Time-Travel Debugging is the ability to create an exhaustive recording of process execution deterministically, so that the human or AI analyst can query the recording like a database, write custom hooks, and perform taint analysis on transformed data. What if we could get record-and-replay capability for the whole system and all its interactions?
In this workshop, we will demo and share an open-source malleable sandbox based on a reboot of a QEMU-based introspection project that supports the three major operating system families and any sample they execute (with room for more). The first half of the workshop will be demos, but the second half will be a stress test driven by the attendees (you!). Bring malware, and we'll see how deep our dynamic introspection can go.
About Joseph Edwards
Joseph analyzes threats to the software supply chain on the Threat Research team at Socket. A career malware analyst and forensic investigator, he learned reverse engineering in support of incident response at IBM X-Force and researched malware at ReversingLabs. He spent several years working in DFIR at SentinelOne with a focus on modernizing forensic analysis and teaching malware triage. Joseph is currently researching using QEMU and hypervisor-based frameworks for forensics research, multi-platform malware detonation, and teaching.
