Тёмный

11. Moritz Laurin Thomas: Hiding Payloads in Plain .text 

x33fcon
Подписаться 3,3 тыс.
Просмотров 1,2 тыс.
50% 1

This is not "yet another payload obfuscation" talk but the story of how we found an intriguing way to hide stageless payloads and eventually evaded some sophisticated EDRs we faced. We'll cover some topics like x86-64 ASM (superficially), PECOFF, binary Shannon entropy and bin-rev. Also, live-demos!
Sometimes we just can't afford the luxury of staging our C2 payloads but need to bring them along as part of the initial payload we deliver. This can become quite the challenge as modern AVs and EDRs feature some pretty sophisticated static and dynamic analysis strategies. One strategy, detection of high file entropy, proved to be an unexpected but annoying challenge we needed to overcome during an assessment. The specific EDR we faced just wouldn't let our binaries pass - so we went to find a solution.
In this talk, they'll tell the story of our journey to solving this problem;
-explaining what the Shannon entropy is, how it's used by EDRs and how we can counter it,
-dissecting the PECOFF format to try and find some cozy places for our shellcode to hide,
-looking into the contents of .text sections (x86-64 ASM) and how we can try and hide our secrets there,
-writing a tool that transforms our payload into something that looks benign and features a low entropy,
-dissecting the generated & seemingly benign binary in Ghidra and
-drawing conclusions about our approach.
They'll also open-source the abovementioned tool so you can look into it yourself! Also, there will be live-demos!

Опубликовано:

 

7 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 2   
@user-bc4gp4nr5v
@user-bc4gp4nr5v Месяц назад
fire talk
@soumyanilbiswas_reveng007
@soumyanilbiswas_reveng007 18 дней назад
time 7:30 : Shellcode Entropy value
Далее
"The New COBOL" - Benno Rice (PyCon AU 2019)
25:54
Просмотров 79 тыс.
Swift creator Chris Lattner on Mojo & Roc
1:49:26
Просмотров 6 тыс.
The "Modern Day Slaves" Of The AI Tech World
52:42
Просмотров 534 тыс.
Meet The New Mark Zuckerberg | The Circuit
24:02
Просмотров 1,8 млн
Where People Go When They Want to Hack You
34:40
Просмотров 1,7 млн
Why Hacking is the Future of War
31:45
Просмотров 2,7 млн