More dates

Payment plans

How does it work?

  • Reserve your order today and pay over time in regular, automatic payments.
  • You’ll receive your tickets and items once the final payment is complete.
  • No credit checks or third-party accounts - just simple, secure, automatic payments using your saved card.

WS3 - Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel

Share
DEF CON Workshops
Add to calendar
 

Description

Instructed by:  Yu Terada

Level of Difficulty: Intermediate, Advanced

Abstract:

Endpoint Detection and Response (EDR) systems are key parts of modern security. This workshop provides a guide for custom malware development, C2 customization, defense evasion, and kernel exploitation. We will use Elastic Defend throughout the session. By analyzing detection logs and rules, we will understand what EDR monitors and why payloads are caught step by step.

After a short overview of Windows defenses and EDR, we focus on malware development. Participants will implement typical malware techniques, such as APC Injection, Thread Hijacking, Fiber and Module Stomping in multiple languages. Next, we learn about call stack analysis. Attendees will implement Stack Spoofing and Indirect Syscalls to hide execution flows and bypass stack analysis.

The workshop then moves to C2 customization using the Havoc C&C framework. By combining custom loaders with C2 source code modifications, participants will bypass static signatures, behavioral rules, and AI detection to successfully establish a C2 session.

Finally, we’ll demonstrate the possibilities of Bring Your Own Vulnerable Driver (BYOVD) attacks for the post-exploitation phase. When we have access to the kernel space, we can take more aggressive measures. We’ll use some vulnerable drivers to kill or blind an EDR sensor itself.

Pre-Requisites:

Basic knowledge of C&C and malware

Powered by

Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity

Register

This event has passed

Register

This event has passed
DEF CON Workshops