Research & Presentations

Keynotes, conference sessions, and research talks. Links go to slide decks hosted on GitHub.

Jan 15, 2025

AI at the Edge: Attacks and Defense

BlueHat India 2025 Day 1 Keynote covering AI security at the edge, including attack vectors and defensive strategies.

View slides bluehat AI security edge computing keynote

Oct 11, 2024

CISA CSAC Technical Advisory Council: Open Source Security Recommendations

Recommendations on improving security in critical open source projects and advancing CISA's secure by design initiative, addressing unique challenges in open source software ecosystems.

View slides CISA open source policy technical advisory secure by design

Oct 03, 2024

A sneak peek into Microsoft's Windows 2030 vision

A sneak peek into what's next for Windows and how AI is shaping the future of the OS.

View slides windows future ai

Jun 15, 2024

Attacking Intelligence: Attacking and Defending AI on The Edge

Keynote on AI security challenges at the edge, covering both offensive and defensive perspectives on edge AI systems.

View slides keynote AI security edge computing adversarial AI

Dec 05, 2023

CISA CSAC Technical Advisory Council: Memory Safety Recommendations

Comprehensive recommendations on advancing memory-safe system languages (MSSL) in federal procurement and cybersecurity practices, including Microsoft's $10M commitment to Rust tooling development.

View slides CISA memory safety policy technical advisory Rust

Nov 16, 2023

ISRG Tectonics Keynote

Keynote for ISRG Tectonics on building trustworthy platforms and the next phase of internet defense.

View slides keynote platform security community

Oct 15, 2023

Stronger Together: Celebrating the Research Community

BlueHat 2023 panel discussion celebrating the security research community and collaborative defense efforts.

View slides bluehat community panel research

Oct 15, 2023

BlueHat 2023 Keynote

BlueHat 2023 keynote address on platform security and the evolving threat landscape.

View slides bluehat keynote platform security

Sep 13, 2023

CISA CSAC Technical Advisory Council Recommendations

Technical Advisory Council recommendations to CISA on threat intelligence, cybersecurity policy, and national security initiatives.

View slides CISA policy threat intelligence technical advisory

Feb 01, 2023

Windows 11 Security by Default

BlueHat IL 2023 session on the secure-by-default work in Windows 11, from hardware baselines to isolation.

View slides bluehat windows 11 secure defaults

Oct 05, 2021

Windows 11 Security — Our Hacker-in-Chief Runs Attacks and Shows Solutions

Demonstration of real attacks against Windows 11 and the built-in security solutions that defend against them.

View slides windows 11 exploitation platform security demonstration

Feb 13, 2020

Keeping Windows Secure

BlueHat IL 2020 talk on keeping Windows secure.

View slides windows bluehat platform security

Jan 01, 2020

Zer0ing Trust: Do Zero Trust Approaches Deliver Real Security?

A candid look at zero trust claims—what delivers, what doesn’t, and how to measure real risk reduction.

View slides zero trust strategy detection

Oct 01, 2019

Advancing Windows Security

Platform Security Summit 2019 talk on Windows' current and future security strategy.

View slides windows platform security

Oct 01, 2019

Factful Security

BlueHat Seattle 2019 session on grounding security strategy in measurable attacker outcomes.

View slides bluehat strategy windows

May 01, 2019

Advancing Windows Security

BlueHat Shanghai keynote on elevating Windows platform defenses and the roadmap for attack surface reduction.

View slides windows bluehat platform security

Feb 01, 2019

Keeping Windows Secure

BlueHat IL 2019 talk covering exploit mitigation progress and the path to safer defaults on Windows.

View slides bluehat exploit mitigation windows

Sep 24, 2018

Real Life Hacks for Windows and Office... and How to Stop Them

Microsoft Ignite session covering real-world attack techniques targeting Windows and Office, and practical defensive measures.

View slides microsoft ignite windows office exploitation

Nov 01, 2017

Securing Windows Defender Application Guard

BlueHat v17 presentation on Windows Defender Application Guard security architecture and implementation.

View slides bluehat windows wdag virtualization security

Mar 16, 2017

Microsoft's strategy and technology improvements toward mitigating arbitrary native code execution

CanSecWest 2017 talk on layered mitigations to reduce native code execution risk, presented by David Weston.

View slides exploit mitigations windows cansecwest

Aug 04, 2016

Windows 10 mitigation improvements

Black Hat USA 2016 session detailing new exploit mitigation features in Windows 10, presented by David Weston.

View slides exploit mitigations windows blackhat

Mar 10, 2011

Targeted taint driven fuzzing using software metrics

CanSecWest 2011 talk on guiding fuzzing with code metrics to prioritize high-risk areas, co-presented with Dustin Duran and David Weston.

View slides fuzzing software security cansecwest

Aug 08, 2008

RE:Trace – Applied Reverse Engineering on OS X

RE:Trace – Applied Reverse Engineering on OS X presentation co-authored with Beauchamp at Defcon 16, including slides and whitepaper.

View slides defcon security

Aug 06, 2008

RE:Trace - Applied Reverse Engineering on OS X

Black Hat USA 2008 session on applied reverse engineering techniques for OS X, co-presented with Tiller Beauchamp.

View slides reverse engineering osx blackhat

Media & Podcasts

WIRED - Jun 26, 2025

So Long, Blue Screen of Death. Amazingly, You'll Be Missed

Listen / Watch

Security Unlocked / BlueHat Podcast - May 28, 2025

Protecting AI at the Edge

Listen / Watch

Security Conversations - Nov 01, 2024

Microsoft's David Weston on the surge in firmware attacks

Listen / Watch

Lessons from the School of Security Hard Knocks - Aug 21, 2024

"Builders and Breakers" interview

Listen / Watch

New York Times - Jul 22, 2024

Congress Calls for Tech Outage Hearing to Grill CrowdStrike C.E.O.

Listen / Watch

TIME - Jul 19, 2024

CrowdStrike's Role In the Microsoft IT Outage, Explained

Listen / Watch

Security Now - Jun 05, 2024

Microsoft's Groundbreaking Update on Recall Security

Listen / Watch

Microsoft Security - May 28, 2024

Defending AI on the Edge with David Weston

Listen / Watch

Microsoft BlueHat Podcast - May 17, 2023

BlueHat Podcast: Security research and Windows OS security

Listen / Watch

pod.co - Jan 18, 2023

David Weston: Builders and Breakers - Lessons from the School of Security Hard Knocks

Listen / Watch

WIRED - Aug 10, 2022

The Microsoft Team Racing to Catch Bugs Before They Happen

Listen / Watch

Business Insider - Apr 07, 2022

How an Xbox anti-cheating chip became Microsoft's new secret weapon to fight increasing cyberattacks on remote workers — and grow its $15 billion security business

Listen / Watch

Hanselminutes #815 - Nov 18, 2021

Understanding Windows 11 security requirements

Listen / Watch

Microsoft Security - Oct 06, 2021

Understanding Windows 11 new security requirements with David Weston

Listen / Watch

Business Insider - Jun 03, 2021

A Microsoft exec explains how its newest acquisition is part of a 'big strategy' in the booming market for securing connected devices that could lead to more M&A

Listen / Watch

WIRED - Nov 17, 2020

Microsoft's Pluton Security Chip Will Be Built Into Future CPUs

Listen / Watch

WIRED - Oct 21, 2019

Microsoft's Secured-Core PCs Protect Against Firmware Attacks

Listen / Watch

NBC's Today Show - Jul 04, 2018

NBC Today show segment

Listen / Watch

Security Conversations - Jun 25, 2018

Security Conversations with David Weston

Listen / Watch

WIRED - Jun 10, 2018

How Microsoft's Windows Red Team Keeps PCs Safe

Listen / Watch

ITV News UK - Nov 25, 2017

ITV News UK segment

Listen / Watch