Igor Korkin, Ph.D. - OS Security Research

Igor Korkin, PhD

Lead Security Researcher & Developer | Black Hat Speaker | Author of Monograph

Igor Korkin

Research Areas

Windows kernel security Intel VT-x / EPT Hypervisor-based protection Memory forensics Rootkit detection ETW, WMI, ALPC

AboutОбо мне

Korkin Igor Yurievich, PhD in Cybersecurity (05.13.19), is an alumnus of Department No. 42, National Research Nuclear University MEPhI, Moscow, Russia; Lead Researcher in international cybersecurity projects at Huawei Technologies (China) and Binarly (USA), with expertise in operating system security, hypervisors (Intel VT-x/EPT), and advanced cyber threat mitigation.

With a publication record of over 50 scholarly works, I have authored research papers, hold a patent, and have presented research at major cybersecurity conferences in the USA, Europe, Asia, and Russia. I also serve as an invited academic supervisor at MEPhI, mentoring undergraduate research in information security.

Publications, talks, patents, and materials are listed on the achievements page.

Education

  • Ph.D. Cybersecurity and Computer Science, Moscow Engineering Physics Institute / NRNU MEPhI, Department of Cryptology and Cybersecurity. Dissertation: Detection Hidden Virtualization-Based Malware.
  • M.S. Cybersecurity and Computer Science, Moscow Engineering Physics Institute / NRNU MEPhI. Thesis: Detection Hidden Malware in Windows Kernel.

Коркин Игорь Юрьевич, кандидат технических наук (05.13.19), выпускник кафедры № 42 Национального исследовательского ядерного университета «МИФИ»; ведущий исследователь международных проектов по кибербезопасности в компаниях Huawei Technologies (Китай) и Binarly (США); системный программист в области информационной безопасности операционных систем, гипервизорных технологий (VT-x/EPT) и противодействия перспективным киберугрозам.

Автор более 50 научных работ, включая статьи, патент и доклады на международных конференциях по кибербезопасности в США, Европе, Азии и России; научный руководитель дипломных и научно-исследовательских работ студентов МИФИ по направлению «Информационная безопасность».

Полный список публикаций, докладов, патентов и материалов собран на странице Achievements.

Education

  • Ph.D. Cybersecurity and Computer Science, Moscow Engineering Physics Institute / NRNU MEPhI, Department of Cryptology and Cybersecurity. Dissertation: Detection Hidden Virtualization-Based Malware.
  • M.S. Cybersecurity and Computer Science, Moscow Engineering Physics Institute / NRNU MEPhI. Thesis: Detection Hidden Malware in Windows Kernel.

News

Recent Talks

ALPChecker: Detecting Spoofing and Blinding Attacks

HITBSecConf Phuket, 2023

session / slides / blog

Blasting Event-Driven Cornucopia: WMI-based User-Space Attacks Blind SIEMs and EDRs

Black Hat USA, 2022

Black Hat / event / archive

Blasting Event Driven Cornucopia: WMI Edition

LABScon, 2022

replay

Blinding Endpoint Security Solutions: WMI attack vectors

Ekoparty, 2022

video

Veni, No Vidi, No Vici: Attacks on ETW Blind EDR Sensors

Black Hat Europe, 2021

event / archive

Kernel Hijacking is Not an Option: MemoryRanger Comes to the Rescue Again

HITB Lockdown 002, 2020

session

Protected Process Light is not Protected: MemoryRanger Fills the Gap Again

IEEE S&P Workshops / Texas Cyber Summit, 2021

doi / materials

Divide et Impera: MemoryRanger Runs Drivers in Isolated Kernel Spaces

Black Hat Europe, 2018

blackhat / materials / code

Recorded Talks on YouTube

Blinding Endpoint Security Solutions: WMI attack vectors on YouTube

Blinding Endpoint Security Solutions: WMI attack vectors

Ekoparty, 2022

Blasting Event-Driven Cornucopia: WMI-based User-Space Attacks Blind SIEMs and EDRs on YouTube

Blasting Event-Driven Cornucopia: WMI-based User-Space Attacks Blind SIEMs and EDRs

Black Hat USA, 2022

Microsoft Defender Will Be Defended on YouTube

Microsoft Defender Will Be Defended - MemoryRanger Prevents Blinding Windows AV

ROOTCON 16, 2022

Veni, No Vidi, No Vici: Attacks on ETW Blind EDR Sensors on YouTube

Veni, No Vidi, No Vici: Attacks on ETW Blind EDR Sensors

Black Hat Europe, 2021

Protected Process Light will be Protected on YouTube

Protected Process Light Will Be Protected

Texas Cyber Summit, 2021

Your Linux Passwords Are in Danger: MimiDove Meets the Challenge on YouTube

Your Linux Passwords Are in Danger: MimiDove Meets the Challenge

Texas Cyber Summit, 2021 (short talk)

Divide et Impera: MemoryRanger Runs Drivers in Isolated Kernel Spaces on YouTube

Divide et Impera: MemoryRanger Runs Drivers in Isolated Kernel Spaces

Black Hat Europe, 2018

International Project Collaboration

Conference Record

Year Conferences and venues
2025 MEPhI CIB / КИБ Moscow (Russia).
2023 HITBSecConf Phuket (Thailand).
2022 Black Hat USA (USA), LABScon (USA), Ekoparty (Argentina), ADFSL (USA), ROOTCON (Philippines).
2021 Black Hat Europe (UK), IEEE S&P Workshops / SADFE (USA), Texas Cyber Summit (USA).
2020 HITB Lockdown 002 (Singapore / online), Journal of Digital Forensics, Security and Law (USA).
2018-2019 Black Hat Europe (UK), ADFSL (USA), Journal of Digital Forensics, Security and Law (USA).
2016-2017 REcon Montreal (Canada), ADFSL (USA).
2014-2015 ADFSL (USA), Journal of Digital Forensics, Security and Law (USA).
2012 Methods and Technical Means of Information Security / MTSOBI, Saint Petersburg (Russia).
2011 Infoforum (Russia), Youth and Science / MEPhI (Russia), MTSOBI, Saint Petersburg (Russia), Telecommunications and New Information Technologies in Education / MEPhI (Russia), RusCrypto (Russia), ISP RAS seminar (Russia), Bauman MSTU seminar (Russia).
2010 Infoforum (Russia), MTSOBI, Saint Petersburg (Russia), Youth and Science / MEPhI (Russia).
2009 Infoforum / Problems of Information Security in Higher Education (Russia).

Academic Advising and Journal Review

Academic supervision

Invited academic supervisor at MEPhI since 2013, advising undergraduate and graduate research in information security. More than 30 graduates have defended diplomas and joined security teams in Russian and International companies.

  • State Examination Board, Moscow Engineering Physics Institute.
  • MEPhI student research topics include ETW-based malware detection, Windows memory forensics, rootkit detection, RASP for LSASS, ALPChecker, Defender security analysis, and sandboxing attacks.

Journal Peer Review

  • Review activity for Journal in Computer Virology. ISSN: 1772-9890.
  • Review activity for Journal of Computer Virology and Hacking Techniques. ISSN: 2263-8733.
  • Review activity for Journal of Information Security and Applications. ISSN: 2214-2126.

More material