WS1 - Malware Development 101 - From Zero to Hero: Adapt your payload to your environment
Description
Instructed by: Yoann “OtterHacker” DEQUEKER
Level of Difficulty: Advanced
Abstract:
This workshop will give an initiation to offensive malware development in C/C++ and how it is possible to adapt the approach depending on the security solution that must be tackled down. Different methods such as ModuleStomping, DLL Injection, Threadless Injection and Hardware Breakpoint for dehooking will be seen.
The idea is to start with a basic malware performing process injection and apply additional techniques to start evading EDR. At each step, some analysis on the malware will be performed to understand the differences at the system level and the IOC detected by the EDR.
At the end of this workshop, you will have all the knowledge needed to develop your own malware and adapt it to the targeted environment to escape from the basic pattern and spawn your beacons as if EDR didn't exist.
Pre-Requisites:
Some basic C/C++ knowledge and an entry level skills on Windows OS
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity


