Xabier Pedrero is a Team Leader and research-focused engineering manager with 8+ years driving threat research and machine learning work at Cisco Talos in Spain. He blends deep academic training—a PhD in Computer Science—with hands-on experience in malware detection, memory forensics, and virtual machine instrumentation. Xabier has contributed to high-profile open-source projects like Volatility 3 and Cisco Talos' pyrebox, adding low-level capabilities such as ELF parsing, kernel symbol retrieval, and guest-agent memory/file operations. His background spans research internships and production research engineering, giving him a rare mix of reproducible academic rigor and practical security tooling delivery. Colleagues rely on him to translate complex reverse-engineering problems into robust backend implementations and to mentor teams bridging ML and malware analysis.
8 years of coding experience
8 years of employment as a software developer
Doctor of Philosophy (PhD), Computer Science, Doctor of Philosophy (PhD), Computer Science at Universidad de Deusto
Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU
Role in this project:
Backend Developer
Contributions:224 commits, 26 PRs, 124 pushes in 2 years 5 months
Contributions summary:Xabier primarily contributed to the project by adding and enhancing functionality related to reverse engineering and virtual machine instrumentation. The commits demonstrate the implementation of new features, including support for reading and writing IO ports and a guest agent with various capabilities such as memory manipulation, file operations, and breakpoint handling. Furthermore, the user made significant changes to enhance the existing code and incorporate upgrades to QEMU.
Contributions:12 commits, 5 PRs, 9 comments in 9 months
Contributions summary:Xabier primarily contributed to the core functionality of the Volatility 3 framework, specifically focusing on memory analysis and digital forensics. Their work involved fixing computations, refactoring existing code related to PEB, EPROCESS, and module handling. They also implemented new features, such as adding ELF parsing and symbol retrieval for Linux kernel modules, thereby expanding the framework's capabilities.
memoryrampythonincident-responseforensics
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.