Reach the Nirvana
DEF CON Workshops
Event description
Reach the Nirvana
Level of Instruction: Advanced
Instructed by: Yoann "OtterHacker" DEQUEKER
Abstract:
The Nirvana Debug is a Windows internal features existing since Windows 7. This workshop idea is to see how this feature can be weaponized in order to either:
- Hijack execution flow
- Perform process injection
- Perform sleep obfuscation for C2 beacon
During this workshop, you will learn the main principle of Nirvana Debugging, and try to weaponize it. Some debugging, reverse and coding will be needed in order to create a new malware that will evade classic EDR solutions.
WHILE THIS IS AN INTRODUCTION TO NIRVANA HOOKING, THIS WORKSHOP IS STILL A HIGHLY TECHNICAL WORKSHOP
Powered by
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity