Behind the Binary by Google Cloud Security
Josh Stroschein
0
Behind the Binary is a podcast about reverse engineering and the people, technology, and tools behind it. Host Josh Stroschein, a reverse engineer on Google's FLARE team, interviews guests about their paths into the field, the challenges they face, and the impact of their work. The show explores the human side of reverse engineering, including motivations and unique perspectives. It is aimed at malware analysts, software developers, security researchers, and anyone curious about how technology is taken apart and secured.
Епизоде
-
EP29 Binary Similarity in the LLM Era with Jonas Wagner and Endre Bangerter of ThreatRay 16.09.2026 57мин"Throwing more LLM prompts at a packed binary won’t make your analysis faster. But combining code similarity with AI will." In Episode 29 of Behind the Binary, Jonas Wagner and Endre Bangerter of ThreatRay join the podcast to lay out the real-world state of binary similarity in the LLM era. They demystify the current AI hype cycle, explaining why large language models are structurally unsuited for raw, unguided binary analysis, and how traditional binary similarity techniques are finding a ma... -
EP28 macOS Security Internals: Kernel Exploitation, PAC Defenses, and the Rise of macOS Infostealers with Olivia Gallucci 26.08.2026 51минIn this episode, we're joined by security researcher Olivia Gallucci to explore macOS low-level security, kernel exploitation, and macOS threat trends. We break down how macOS internals differ from Linux—focusing on IOKit, C++ dynamic class resolution, and Vtable hijacking in kernel drivers. Olivia explains the mechanics behind use-after-free (UAF) vulnerabilities, heap shaping, and legacy kernel exploits, as well as modern Apple hardware and OS defenses like Pointer Authentication Codes (PAC... -
EP27 The Challenges of Reversing Modern Languages: From C++ to Go and Rust with Jae Young Kim 15.07.2026 56минWhen malware analysis first emerged, reverse engineers typically operated in a straightforward C landscape — standard Win32 APIs, no massive runtimes, and clear code paths. Today, the landscape has fundamentally shifted. The natural progression to C++ introduced object-oriented hurdles like virtual function tables and standard template library bloat, laying the groundwork for the complexities we see in today's modern ecosystem. In this episode of Behind the Binary, we sit down with Jae Young ... -
EP26 When AI Features Create Zero-Click Exploits: The Pixel 9 Chain with Seth Jenkins 03.06.2026 58минMobile security boundaries rely on isolating remote, untrusted inputs from highly privileged system components. However, when new automated features are introduced, the available attack surface can shift—sometimes exposing unexpected code paths to remote attackers. In the latest episode of Behind the Binary, we sit down with Seth Jenkins from Google Project Zero to dissect a full two-bug, zero-click exploitation chain targeting the Pixel 9. By chaining a user-space decoder flaw with a kernel ... -
EP25 The Future of Debugging: A Paradigm Shift with Xusheng Li 06.05.2026 57мин"TTD is a paradigm shift in the way you interact with the target... Potentially, five years from now, when we talk about debugging, we will just by default go to TTD." In this episode, we are joined by Xusheng Li, a debugger architect and reverse engineering expert, to explore the evolution of Time Travel Debugging (TTD). While traditional debugging has remained largely stagnant for decades, TTD introduces a novel new way to debug by recording and replaying execution traces with total precisi... -
EP24 The Glupteba Takedown: What Happens When Botnet Operators Show Up in Court with Pierre-Marc Bureau 01.04.2026 54мин"I thought that we would never hear about these people after they were named. But what was a surprise is that they actually hired a lawyer in New York... and they were like, 'Yeah, we're going to be taking part in this trial." In this episode, we are joined by Pierre-Marc Bureau from Google’s Threat Intelligence Group (GTIG) to unpack the unprecedented takedown of the Glupteba botnet. Active since 2011, Glupteba infected roughly 1 million Windows devices before Google launched a coordinated t... -
EP23 Immutable C2: How EtherHiding and Frontend Attacks are Weaponizing the Blockchain 04.03.2026 41минIn this episode, we are joined by Robert Wallace, Joseph Dobson, and Blas Kajusner to dissect the new "Hybrid Heist." The panel argues that the era of isolated crypto-theft is over; sophisticated actors are now targeting the Web2 layer—the frontends, the developer workstations, and the cloud infrastructure—to bypass the immutability of the chain itself. We also break down "Ether Hiding," a technique where attackers store malware payloads directly on the blockchain to create an unstoppable Com... -
EP22 Jailbreaking, Prompt Injection, and the "Agentic" Flaw in MCP with Kevin Harris 04.02.2026 57мин"Skilled adversaries have a 100% success rate against all of the defenses that we know about." In this episode, Kevin Harris defends that claim. We move past the standard "AI Safety" talking points to distinguish between the two attack vectors confusing the industry: Prompt Injection (an application-layer failure) vs. Jailbreaking ("gaslighting" the model via context shifting). Kevin argues that we haven't actually invented AI yet—we've just built a mirror that reflects our own intelligence (... -
EP21 From HITB Origins to Agentic AI: Web3, Music & The Future of Hacking with Dhillon Kannabhiran 14.01.2026 1ч 2минIn this episode, Dhillon Kannabhiran shares the gritty origin story of Hack in the Box (HITB), detailing how he dug a $20k financial hole to launch the first event in Malaysia before building it into a global brand. The conversation moves beyond conferences to explore the cutting edge of technology and creativity. Dhillon explains why "agentic" systems (like Xbow) signal the end of hand-built exploits and discusses the unique challenges of securing Web3 smart contracts. We also dive into the ... -
EP20 Windows Under the Hood: Kernel Design, EDRs, and the Shift to VBS with Pavel Yosifovich 10.12.2025 1ч 10минIn this episode, we get a unique look at the history of Windows through the eyes of one of its leading experts, Pavel Yosifovich. We delve into his fascinating origin story, including the "fluke" that led him to become the author of the legendary Windows Internals series, and why he describes himself as a developer who "hates security." The conversation explores the most significant foundational changes in Windows kernel design, specifically the architectural shift toward Virtualization-Based... -
EP19 The Art of Deconstructing Problems: Tools, Tactics, and the ScatterBrain Obfuscator with Nino Isakovic 19.11.2025 1ч 53минIn this episode, we’re joined by Nino Isakovic, a long-time low-level security expert, for a thought-provoking conversation that spans the foundational and the cutting-edge. Nino discusses the art of deconstructing problems—sharing insights on how to learn effectively, the building blocks of a robust RE toolkit, and the critical shift required in our analytical approach. We then transition into the front lines of threat intelligence, where Nino discusses the specific challenges of analyzing s... -
EP18 10,000 DLLs and Too Much Math - Wrapping Up FLARE-On 12 with the FLARE Team 05.11.2025 47минIn this episode, we sit down with Nick Harbour, Blas Kojusner, Moritz Raabe, and Sam Kim — members of the FLARE Team and some of this year’s challenge authors — for a deep dive into the design and execution of FLARE-On 12. The team discusses the complexity and intent behind this year's challenges, including how Sam created his grueling final challenge, "10,000," which featured 10,000 individual DLLs to force competitors toward automation. Sam reveals that solving the final puzzle required dee... -
EP17 What Lurks Beneath: Building a Robust Network at Black Hat with Mark Overholser 22.10.2025 1ч 9минIn this episode, we're asking the question: "What Lurks Beneath?" We're joined by Mark Overholser, a Technical Marketing Engineer at Corelight who's part of the team running the Black Hat Network Operations Center (NOC). We discuss the incident during Black Hat 2025 that introduced us and revealed the team's proactive approach to protecting every guest from the unseen threats hiding in the shadows. Mark gives us an insider’s look at the philosophy and challenges behind building a robust netwo... -
EP16 The Machine Learning Revolution in Reverse Engineering with Hahna Kane Latonick 01.10.2025 1ч 25минIn this episode of Behind the Binary, we're joined by renowned security researcher Hahna Kane Latonick for a deep dive into the powerful world where reverse engineering meets data science. Hahna shares her expertise on how techniques like supervised and unsupervised learning can be used to classify and predict security threats, and she explains how deep learning and neural networks are being applied to identifying code sharing and solving other classification problems. We also discuss how Gen... -
EP15 Getting Ready for FLARE-On 12 - An Inside Look at the Reverse Engineering Gauntlet 17.09.2025 39минIn this episode, we're "Getting Ready for FLARE-On 12" with an inside look at the world-renowned reverse engineering competition. We’re joined by long-time FLARE-On host and challenge author Nick Harbour and regular challenge author Blas Kojusner for an in-depth conversation. We'll take a brief tour of FLARE-On history and discuss how it has grown into a must-do event for malware analysts and reverse engineers. We’ll also break down how the competition works, from the evolution of the unique ... -
EP14 Web3's Dark Side: Unmasking the New Age of Financial Crime 03.09.2025 1ч 12минWeb3 promised a new era of decentralized finance, but it has also created a new frontier for crime, with thefts and hacks far surpassing those in the traditional financial sector. In this episode, we sit down with experts Blas Kojusner, Robert Wallace, and Joseph Dobson to explore the Wild West of Web3 and decentralized finance (DeFi). But what is Web3? Our episode begins by taking a look at Web3 technologies like DeFi, blockchain, and smart contracts and explain how their very design makes t... -
EP13 Beyond the Bug: Scaling Bug Bounty Programs & Launching a Cyber Startup with Dr. Jared DeMott 13.08.2025 37минIn this episode of Behind the Binary, we sit down with Dr. Jared DeMott to pull back the curtain on the world of cybersecurity. Formerly with the Microsoft Security Response Center (MSRC), Jared shares invaluable wisdom on managing bug bounty programs at scale and what truly makes a good bug report. We then pivot to explore his fascinating career journey, from his start with the NSA to leading teams at Microsoft. If that wasn’t enough, we’ll also dive into the unique challenges of a cyber sta... -
EP12 Unpacking Malware & Minds: A Reverse Engineer's Journey with Danny Quist 16.07.2025 59минJoin us as we explore the world of reverse engineering with pioneer and CTO, Danny Quist. We'll examine the evolving landscape of binary analysis tools, the constant battle with malware obfuscation, and what it was like building one of the very first malware repositories for research. Plus, Danny shares unique insights on neuro-diversity and cognitive load – crucial topics that impact us all. That's just a glimpse of what's ahead. Danny Quist isn't just a leading mind in reverse engineering; ... -
EP11 Tracing Lazarus: Greg Sinclair on Attributing North Korean Cyber Threats Through Binary Similarity 25.06.2025 1ч 2минEver wonder who names the world's most notorious APTs? In this episode, we sit down with Greg Sinclair, a reverse engineer from the FLARE team at Google. Greg not only hunts down sophisticated malware but also shares the behind the scenes story of how he discovered and named the North Korean APT, the Lazarus Group. He also discusses his innovative methods for identifying malware families through binary similarities. Get ready for an inside look at the challenges, triumphs, and the sheer passi... -
EP10 Tim Blazytko - Protecting Intellectual Property: Obfuscation & Anti-Reverse Engineering in Software 04.06.2025 1ч 8минWhat goes into creating effective software protections? This episode features a conversation with Tim Blazytko, Chief Scientist and Head of Engineering at Emproof, about the essential strategies for protecting software intellectual property. We cover the core concepts of code obfuscation and anti-reverse engineering and discuss practical, modern approaches to implementing these defenses effectively, while also shedding light on the significant challenges and trade-offs involved. Listeners wil...
Популаран у
Овај подкаст се појављује и у подкаст листама ових земаља.