DEF CON 31 - Defender Pretender When Windows Defender Updates Become a Security Risk -Bar, Attias

  Рет қаралды 14,221

DEFCONConference

DEFCONConference

Күн бұрын

The signature update process is critical to EDR's effectiveness against emerging threats. The security update process must be highly secured, as demonstrated by the Flame malware attack that leveraged a rogue certificate for lateral movement. Nation-state capabilities are typically required for such an attack, given that signature update files are digitally signed by Microsoft.
We wondered if we could achieve similar capabilities running as an unprivileged user without possessing a rough certificate, instead we aimed to turn the original Windows Defender process to our full control.
In this talk we will deep dive into Windows Defender architecture, the signature database format and the update process, with a focus on the security verification logic. We will explain how an attacker can completely compromise any Windows agent or server, including those used by enterprises, by exploiting a powerful 0day vulnerability that even we didn't expect to discover.
We will demonstrate Defender-Pretender, a tool we developed to achieve neutralization of the EDR. allowing any already known malicious code to run Fully Un-Detected. It can also force Defender to delete admin’s data. OS and driver files, resulting in an unrecoverable OS. We will also explain how an attacker can alter Defender's detection and mitigation logic.

Пікірлер: 12
@SergeTheBlade
@SergeTheBlade Жыл бұрын
One of the coolest talks I saw. Well done.
@stubstunner
@stubstunner 11 ай бұрын
Goteem
@ttrss
@ttrss Жыл бұрын
the dos is like autoimmune disease but for computers
@fabiorj2008
@fabiorj2008 9 ай бұрын
The best talk of Defcon31. No doubt about this.
@sabofx
@sabofx Жыл бұрын
Super cool!
@towelie
@towelie Жыл бұрын
great talk , good level of detail
@KonuralpBalcik
@KonuralpBalcik Жыл бұрын
When I delete all defender folders while offline, it never works, but it seems to work.
@rohitnair5738
@rohitnair5738 Жыл бұрын
great research🙃
@elcasho
@elcasho Жыл бұрын
great research!
@Radi0he4d1
@Radi0he4d1 Жыл бұрын
Very interesting and well presented 👍
@imark7777777
@imark7777777 11 ай бұрын
It's not a security risk it's a feature!
LIFEHACK😳 Rate our backpacks 1-10 😜🔥🎒
00:13
Diana Belitskay
Рет қаралды 3,9 МЛН
Поветкин заставил себя уважать!
01:00
МИНУС БАЛЛ
Рет қаралды 6 МЛН
Новый уровень твоей сосиски
00:33
Кушать Хочу
Рет қаралды 4,8 МЛН
Best Antivirus/EDR vs Unknown Ransomware
11:38
The PC Security Channel
Рет қаралды 103 М.
DEF CON 31 - Defeating VPN Always On - Maxime Clementz
40:07
DEFCONConference
Рет қаралды 13 М.
Virtual Machines vs Containers
8:57
PowerCert Animated Videos
Рет қаралды 904 М.
CrowdStrike IT Outage Explained by a Windows Developer
13:40
Dave's Garage
Рет қаралды 2,1 МЛН
Is your PC hacked? RAM Forensics with Volatility
14:29
The PC Security Channel
Рет қаралды 912 М.
LIFEHACK😳 Rate our backpacks 1-10 😜🔥🎒
00:13
Diana Belitskay
Рет қаралды 3,9 МЛН