Sergei Frankoff -Tracing The Pain Away

Schedule

Thu Aug 08 2024 at 09:00 am to 01:00 pm

Location

SpringHill Suites Las Vegas Convention Center | Las Vegas, NV

Advertisement
Tracing The Pain Away - Practical Binary Tracing Techniques For Defeating Modern Malware Protections
About this Event

Abstract:

Code obfuscation is fast becoming a normal part of modern Windows malware. Pioneered by Emotet and popularized by the Conti ransomware leaks, we now see even simple credential stealers using commercial grade code virtualization! The solution… if you can’t reverse it, just run it!
In this workshop we will cover different tracing techniques that can be used to bypass and extract information from protected code. The workshop is divided into modules covering tracing with x64dbg, dynamic binary instrumentation with PIN, and API tracing with DTrace. A challenge binary is provided with each module for students to practice and the final challenge is a real world malware sample that has been virtualized.
This workshop is aimed at reverse engineers and malware analysts who have experience analyzing malware and are comfortable with debugging in userland. If you don’t have experience with malware but you do have a few hours behind the debugger you should have no problem completing the workshop.
Students must bring a laptop/workstation capable of running a Windows Virtual Machine (VM) and a preinstalled Windows 10 (64bit) 20H1(or later) VM with at least 50G of free space. You will be provided with detailed tools installation and setup instructions prior to the workshop

Bio:
Twitter: @herrcore
Sergei is a co-founder of OpenAnalysis Inc. When he is not reverse engineering malware Sergei is focused on building automation tools for malware analysis, and producing tutorials for the OALABS YouTube channel. With over a decade in the security industry Sergei has extensive experience working at the intersection of incident response and threat intelligence.

Sean Wilson
Sean, a co-founder of OpenAnalysis Inc., splits his time between reverse engineering, tracking malware and building automated malware analysis systems. Sean brings over a decade of experience working in a number of incident response, malware analysis and reverse engineering roles.

Advertisement

Where is it happening?

SpringHill Suites Las Vegas Convention Center, 2989 Paradise Road, Las Vegas, United States

Event Location & Nearby Stays:

Tickets

USD 0.00

DEF CON 32 Workshops

Host or Publisher DEF CON 32 Workshops

It's more fun with friends. Share with friends