WS1 - Intro to Writing Windows Malware with Rust!
Description
Instructed by: “iDigitalFlame”
Level of Difficulty: Beginner, Intermediate, Advanced
Abstract:
In the Information Security news space, we often hear about the cool malware and tools nation states and APTs develop. While there are many tools out there that "do the thing", have you ever wonder how it "does the thing"? Instead of just using tools and scripts that sound cool, why not make them?
Using the Rust programming language, you'll be taken step-by-step into building your own Windows malware! We'll break down the process and work our way into more complex tasks. From a simple, no-imports binary we'll slowly work into loading and executing Windows API functions without ever calling "LoadLibrary" or "GetProcAddress" while not touching a single Rust "std::*" function or importing any extra crates!
You'll be introduced into Windows concepts like the Process Environment Block (PEB), the Thread Environment Block (TEB) and how we can use them to our advantage! At the end of this workshop, you'll be able to build binaries without any imports while doing fun tricks like shellcode injection!
Some of the topics we'll touch on are:
· Assembly!
· Rust Allocators
· Windows Structs
· API Function Calls
· Binary File Inspection
Pre-Requisites:
· Participants should have at least a basic understanding of how to program in Rust.
· Some Experience in using unsafe Rust is recommended.
· Basic Windows API knowledge is recommended, but not required.
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity


