Nullcon Goa

Demystifying Driver Research A Systematic Approach For Vulnerability Hunting

25:24 · 28 Feb 2026 – 01 Mar 2026 · YouTube

About this talk

This talk introduces a structured five-step methodology for hunting driver vulnerabilities, a critical area in offensive security. Led by Priyanshu Sharma from MIT Pune, the session emphasizes moving beyond random fuzzing by combining mass collection, API filtering, device verification, static analysis, and guided fuzzing into a repeatable pipeline. The speaker demonstrates how to effectively narrow down thousands of drivers to a shortlist of high-value targets using import table analysis and device verification. Additionally, the session explores navigating dispatch tables and IRP major functions in Ghidra to identify dangerous IOCTL handlers, highlighting the real-world application of this methodology, which led to the discovery of multiple zero-days, including CVE-2025-60419.

From event

Nullcon Goa

28 Feb 2026 – 01 Mar 2026

All event videos
Back to Watch