WS3 - Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel
Description
Instructed by: Yu Terada
Level of Difficulty: Intermediate, Advanced
Abstract:
Endpoint Detection and Response (EDR) systems are key parts of modern security. This workshop provides a guide for custom malware development, C2 customization, defense evasion, and kernel exploitation. We will use Elastic Defend throughout the session. By analyzing detection logs and rules, we will understand what EDR monitors and why payloads are caught step by step.
After a short overview of Windows defenses and EDR, we focus on malware development. Participants will implement typical malware techniques, such as APC Injection, Thread Hijacking, Fiber and Module Stomping in multiple languages. Next, we learn about call stack analysis. Attendees will implement Stack Spoofing and Indirect Syscalls to hide execution flows and bypass stack analysis.
The workshop then moves to C2 customization using the Havoc C&C framework. By combining custom loaders with C2 source code modifications, participants will bypass static signatures, behavioral rules, and AI detection to successfully establish a C2 session.
Finally, we’ll demonstrate the possibilities of Bring Your Own Vulnerable Driver (BYOVD) attacks for the post-exploitation phase. When we have access to the kernel space, we can take more aggressive measures. We’ll use some vulnerable drivers to kill or blind an EDR sensor itself.
Pre-Requisites:
Basic knowledge of C&C and malware
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity


