More dates

Payment plans

How does it work?

  • Reserve your order today and pay over time in regular, automatic payments.
  • You’ll receive your tickets and items once the final payment is complete.
  • No credit checks or third-party accounts - just simple, secure, automatic payments using your saved card.

WS7 - Explore the Windows instrumentation callback

Share
DEF CON Workshops
Add to calendar
 

Description

Instructed by:  Yoann “Otterhacker” DEQUEKER 

Level of Difficulty: Expert

Abstract:

The Nirvana Debug is a type of instrumentation callback existing since Windows 7. This workshop idea is to see how this feature can be weaponized in order to either:

·      Hijack execution flow

·      Perform process injection

·      Perform sleep obfuscation for C2 beacon

During this workshop, you will learn the main principle of Nirvana Debugging, and try to weaponize it. Some debugging, reverse and coding will be needed in order to create a new malware that will evade classic EDR solutions.

Pre-Requisites:

It is strongly recommended that students have at least:

·      Basic knowledge about Windows internal (if you know the difference between kernel/userland, NTDLL.DLL/KERNEL32.DLL it should be ok)

·      Basic knowledge on reverse engineering (if you've done some crackme or other simple reversing challenge it should be ok)

·      Basic knowledge on C (if you know the basic commands and how to compile a program it should be ok)

A WINDOWS 10 computer or VM with a decompiler (IDA Free or Ghidra), something to compile C code for Windows (MSVC/MINGW)

Powered by

Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity

Register

This event has passed

Register

This event has passed
DEF CON Workshops