
DEF CON 33 - Automated Unpacking & Deobfuscation of Nested VM-Based Protectors - Agostino Panico
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 38:43
VM Dragon Slayer presents a framework to combat virtualization-based software protection that dominates modern malware, reducing analysis time from months to minutes 0:55-1:12.
Key Takeaways:
• 70% of advanced threats use VM protection, with traditional tools having less than 15% success rate 5:30-6:29
• VM Dragon Slayer uses hybrid analysis: dynamic taint tracking + symbolic execution + machine learning 13:15-13:54
• Analysis demonstrates 70-84% success rate across 300 samples, reducing analysis time from months to hours 29:25-30:07
• Case studies show cost reduction from $40,000 to $250 per sample in analyst time 30:09-30:24
• The framework will be open-sourced to accelerate defensive capabilities 37:56-38:16
The framework demonstrates that with the right tools and community collaboration, defenders can gain an advantage in the ongoing battle against sophisticated malware protection techniques.
Sources:
- 0:55-1:12 Introduction to VM Dragon Slayer and its purpose
- 5:30-6:29 Statistics on VM protection prevalence and tool failures
- 13:15-13:54 Explanation of the hybrid analysis approach
- 29:25-30:07 Success rates and time reduction statistics
- 30:09-30:24 Cost savings analysis
- 37:56-38:16 Open source announcement and conclusion
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Good afternoon, Defcon. I'm Augustino aka Vanish and I'm here to talk about slaying dragons. Not the mythical one. So, we are not talking about the orbit uh but we are talking about the one that guard modern software through sophisticated virtualization based off ofcation techniques. This is the agenda for the next 45 minutes. We are going to start with a brief introduction. We are going to see the VM protection evolution. I'm presenting the VM dragons layer architecture and we do a deep dive. We do some live demos because it's cool. We do some we analyze some performance and validation and we analyze the limitation the future work and the community that that I hope to build around the project after this talk. Let's set up the expectation why VM protection is winning the armories. This is …