Curriculum vitae

Adam Taguirov

Founder & Security Researcher

Security researcher and software engineer specialising in reverse engineering, malware analysis, digital forensics and low-level systems. Built malware analysis platforms on Xen and custom-instrumented KVM hypervisors, conducted vulnerability research in the Apple ecosystem, and led malware analysis initiatives for Europol and law-enforcement agencies.

Based
Paris, France
Experience
7+ years
Education
MSc, Information Systems Security
Adam Taguirov

Experience

Founder & Security Researcher

Sigreturn LabsParis, FrancePrivate sector

Mar 2026 – Present

Independent security research and engineering company, specialised in malware analysis, vulnerability research and product development.

  • Founded and operate Sigreturn Labs, setting its technical and commercial direction.
  • Malware analysis and in-depth reverse engineering to extract attack techniques and configurations.
  • Cryptographic and logic vulnerability research.
  • Design, development, testing and maintenance of SaaS products.
  • Automated analysis tooling: triage, unpacking, behavioural analysis.
  • Advisory work on malware analysis, vulnerability research and security architecture.
  • Malware analysis
  • Reverse engineering
  • Vulnerability research
  • Development

Malware Forensic Analysis Specialist

EuropolThe Hague, NetherlandsLaw enforcement

May 2025 – Mar 2026

Specialist engineer in the Cyber Intelligence Team at EC3, the European Cybercrime Centre.

  • Technical lead of EMAS, the Europol Malware Analysis Solution: a large-scale European analysis platform used by law enforcement agencies.
  • Designed and built a malware analysis sandbox on Xen hypervisor introspection and LibVMI.
  • Advanced reverse engineering of malware to analyse attack techniques and extract configurations for international criminal cases.
  • Cryptographic and logic vulnerability research, and decryption tools released through the NoMoreRansom initiative.
  • Automated triage, unpacking and behavioural analysis workflows.
  • Tooling and infrastructure supporting operational investigations.
  • Malware analysis
  • Reverse engineering
  • Cyber intelligence
  • Criminal investigations

Cybercrime Expert Engineer

Police JudiciaireNanterre, FranceLaw enforcement

Apr 2023 – May 2025

Specialised cyber support group, cyber investigations division of the anti-cybercrime office. Digital forensics and malware analysis.

  • In-depth reverse engineering of the ransomware families behind major cybercrime investigations.
  • Research into cryptographic and implementation weaknesses allowing recovery of encrypted victim data.
  • Design and development of the decryption tools used in those investigations.
  • Malware analysis, digital forensics and incident response on more than 30 complex cases.
  • Malware analysis
  • Reverse engineering
  • Digital forensics
  • Criminal investigations

Cybersecurity Researcher

QuarkslabParis, FrancePrivate sector

Apr 2022 – Apr 2023

Mobile team, Research & Development division. Vulnerability research in the Apple ecosystem.

  • Vulnerability research on the macOS kernel, browsers (WebKit, Chromium) and iOS and Android applications.
  • Fuzzing, reverse engineering, exploit development and root-cause analysis.
  • Public talk on JavaScript engine exploitation at Quarks in the Shell.
  • Completed the ESIEA Reverse Engineering BADGE programme.
  • Vulnerability research
  • Reverse engineering
  • Browser exploitation

Cybersecurity Engineer

Orange CyberdefenseNanterre, FrancePrivate sector

Dec 2019 – Apr 2022

P2A team, Product Research & Development division. Malware sandbox development and malware reverse engineering.

  • Designed and built a hypervisor-level malware sandbox, stealthy and resistant to evasion techniques.
  • Windows API hooking, syscall monitoring, process tracking and memory introspection from the hypervisor layer.
  • Built the second-generation analysis platform on a custom-instrumented KVM stack.
  • Modified virtualisation components and wrote the userland tooling for memory acquisition, behavioural analysis and stealth instrumentation of Windows guests.
  • Large-scale malware analysis: detection, deobfuscation, behaviour.
  • Led the research effort and coordinated a small engineering team.
  • Product development
  • Malware analysis
  • Reverse engineering
  • Management

Cybersecurity Engineer

Digital SecurityParis, FrancePrivate sector

Sep 2017 – Mar 2019

Penetration testing team. Reverse engineering and vulnerability research.

  • Offensive tooling and low-level binary protections, including packers, for penetration testing and red team engagements.
  • Internal and external penetration testing engagements.
  • Vulnerability research on embedded and IoT systems on ARM.
  • Hardware reverse engineering and exploitation of components.
  • Reverse engineering
  • Vulnerability research
  • Development

Publications

Time as a Key: Breaking Rhysida Ransomware with the Attacker's Own Ciphertext

PreprintSigreturn LabsAug 2026

Rhysida seeds its PRNG with srand(time(0)) and draws the OAEP seed of its RSA key wrap from that same generator. The blob appended to every encrypted file is therefore reproducible offline, which turns the attacker's own ciphertext into an exact oracle for a guessed key and makes recovery possible without the private key. 15 pages.

  • Cryptanalysis
  • Ransomware
  • Reverse engineering

Talks & training

Trainer

Malware Analysis Training

OFAC International Ransomware Training SessionParis, France

May 2025

Technical ransomware analysis course designed and delivered to police officers from several European countries, under a CEPOL-funded programme. Detection, static and dynamic analysis, identification of encryption mechanisms and remediation strategies.

  • Law enforcement
  • Training
  • Malware analysis

Trainer

Lawful Decryption, Train the Trainer

CEPOL Training on Lawful DecryptionBudapest, Hungary

Apr 2025

Train the Trainer programme run by CEPOL with ECTEG, preparing law enforcement specialists to deliver national training on lawful decryption. Covered the technical side within a legal framework, eDecrypt and Decrypt Advanced, and the pedagogy of handing those skills to investigators.

  • Law enforcement
  • Training
  • Cryptography

Speaker

Cybercrime Conference

Science Festival, National Police MuseumParis, France

Oct 2024

Public talk on cybercrime for the Science Festival at the Paris Police Prefecture Museum. The main forms of digital crime, fraud, identity theft, data breaches, scams and malware distribution, and the methods investigation services use against them.

  • Awareness
  • General public
  • Cybercrime

Trainer

Malware Analysis Training

France-South Africa international cooperationPretoria, South Africa

May 2024

Technical ransomware analysis course designed and delivered to South African police officers under a cooperation agreement between France and South Africa. Detection, static and dynamic analysis, identification of encryption mechanisms and remediation strategies.

  • Law enforcement
  • Training
  • Malware analysis

Speaker

JavaScript Engine Exploitation

Quarks in the ShellParis, France

Apr 2023

Exploitation methodologies for modern JavaScript engines, on V8 and JavaScriptCore. The memory layout of JavaScript objects, the founding primitives addrof and fakeobj, how they become arbitrary read and write, and how they assemble into a chain. Closes on the iOS ecosystem, WebKit's mitigations and the techniques that get past them.

  • Vulnerability research
  • Browser exploitation
  • Conference

Education & certification

BADGE Reverse Engineering

ESIEAParis, France

2022

Certified programme accredited by the Conférence des Grandes Écoles, specialised in reverse engineering and malware analysis.

Diploma REV 2023-26

MSc, Information Systems Security

YNOV Campus & École 42Paris, France

2016 – 2020

Cybersecurity, operating systems, computer architecture, algorithms, systems and network administration.

Diploma 2020-YNOV0599

Professional training

Advanced Decryption

CEPOL, European Union Agency for Law Enforcement Training031/2023

2023

Reverse Engineering 101

Kaspersky

2023

Rust fundamentals

Ambient IT

2021

Skills

Security

  • Reverse engineering
  • Malware analysis
  • Vulnerability research
  • Exploit development
  • Fuzzing
  • Digital forensics
  • Incident response
  • Threat analysis

Systems

  • Linux internals
  • Windows internals
  • macOS and iOS
  • Virtualisation
  • Hypervisors
  • Xen
  • KVM

Programming

  • C
  • C++
  • Python
  • Swift

Tools

  • IDA Pro
  • Ghidra
  • WinDbg
  • LLDB
  • Frida
  • x64dbg
  • YARA
  • Miasm
  • LibVMI

Infrastructure

  • Distributed systems
  • Security automation
  • Malware analysis platforms
  • Blockchain infrastructure

Languages

  • French, native
  • English, fluent (TOEIC 970/990)

Projects & community

Sigreturn Labs

sigreturn.com

Cybersecurity research company, specialised in malware analysis, vulnerability research and SaaS product development. Technical and commercial strategy, automated analysis tooling, and the reverse engineering and product engagements themselves.

  • Entrepreneurship
  • Cybersecurity
  • Research & development

Root-Me

www.root-me.org

Administrator and president of Root-Me, one of the largest cybersecurity training platforms in Europe, with hundreds of thousands of active users. Association management, recruitment and supervision of more than 40 volunteers, and the moderation, QA and testing teams. Eight years in post, now honorary president.

  • Management
  • Cybersecurity
  • E-learning

Polkadot validators & identity registrar

dotid.app

dotID, an independent identity registrar for the Polkadot and Kusama networks, built and operated by Sigreturn Labs. Its registrar seats and username authority were granted by on-chain governance, as registrar #5 on Polkadot and #7 on Kusama. It verifies the fields an account has set on chain, records the judgement on the People Chain, issues .id usernames and publishes a directory of every verified identity. Founded the project and builds the web app and its infrastructure. Before it, validator nodes on Polkadot's nominated proof-of-stake consensus, run for about two years and since stopped.

  • Blockchain
  • Identity
  • Infrastructure

Diplomas & certificates

Scans, shown on screen only.

BADGE Reverse Engineering, ESIEA
BADGE Reverse Engineering, ESIEA
IT and Information Systems Expert, YNOV Campus
IT and Information Systems Expert, YNOV Campus
Digital Technology Architect programme, 42
Digital Technology Architect programme, 42
Advanced Decryption, CEPOL
Advanced Decryption, CEPOL
Decryption Trainer certificate, CEPOL
Decryption Trainer certificate, CEPOL
Letter of appreciation, Europol EC3
Letter of appreciation, Europol EC3
Reverse Engineering 101, Kaspersky
Reverse Engineering 101, Kaspersky
Rust fundamentals, Ambient IT
Rust fundamentals, Ambient IT
TOEIC, 970/990
TOEIC, 970/990