SecretCon 2026
Inside M(AI)ware: Behavior, Analysis, and Detection
Dr. Fatou Sankare
Abstract:
Malware remains one of the most persistent and adaptive threats in cybersecurity, evolving far faster than traditional detection methods can keep pace. Signature-based defenses, while effective against known threats, increasingly struggle against polymorphic, fileless, and AI-assisted malware designed to blend into normal system behavior.
This talk provides a practical, analyst-focused look at how modern malware operates once it lands on a system. Rather than diving into reverse engineering or exploit development, we focus on observable behavior: process creation, persistence mechanisms, and payload execution. Attendees will learn a simple but effective mental model—Process, Persistence, and Payload—for understanding and investigating suspicious activity across endpoints.
Through a safe, live demonstration in a virtualized environment, the audience will see how malware-like behavior is detected and analyzed using common tools such as Process Explorer, hashing utilities, and public threat intelligence sources. The session highlights the strengths and limitations of both signature-based and behavioral detection, and why defenders must increasingly think like analysts rather than rely solely on automated tools.
By the end of this talk, attendees will have a clearer understanding of how malware evades detection, how to observe it in motion, and how to begin developing the mindset and skills required for malware analysis and threat hunting in modern environments.

Dr. Fatou Sankare
Cyber Engineer/Researcher
Dr. Fatou is a cybersecurity researcher and offensive security engineer with over a years of experience dissecting advanced threats at the boundary between real-world operations and experimental research. Her background spans advanced penetration testing, digital forensics, and low-level malware reverse engineering, with a primary research focus on polymorphic and self-evolving malware, adversarial AI, and detection-evasion at scale. Her work examines how modern threats weaponize automation, learning systems, and system internals to persist undetected in hostile environments.
In parallel to her work, Dr. Fatou also teaches undergraduate and graduate-level courses in penetration testing, malware analysis, digital forensics, data science, and applied AI for cybersecurity, designing curricula that emphasize attacker emulation, behavioral analysis, and research-grade experimentation. Her talks deliver a rare fusion of lab-validated research and field-tested tradecraft, offering audiences a clear view into how advanced adversaries think, build, and adapt—and what it actually takes to stop them.