WS7 - Explore the Windows instrumentation callback
Description
Instructed by: Yoann “Otterhacker” DEQUEKER
Level of Difficulty: Expert
Abstract:
The Nirvana Debug is a type of instrumentation callback existing since Windows 7. This workshop idea is to see how this feature can be weaponized in order to either:
· Hijack execution flow
· Perform process injection
· Perform sleep obfuscation for C2 beacon
During this workshop, you will learn the main principle of Nirvana Debugging, and try to weaponize it. Some debugging, reverse and coding will be needed in order to create a new malware that will evade classic EDR solutions.
Pre-Requisites:
It is strongly recommended that students have at least:
· Basic knowledge about Windows internal (if you know the difference between kernel/userland, NTDLL.DLL/KERNEL32.DLL it should be ok)
· Basic knowledge on reverse engineering (if you've done some crackme or other simple reversing challenge it should be ok)
· Basic knowledge on C (if you know the basic commands and how to compile a program it should be ok)
A WINDOWS 10 computer or VM with a decompiler (IDA Free or Ghidra), something to compile C code for Windows (MSVC/MINGW)
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity


