No video

"GetInjectedThreadEx - improved heuristics for suspicious thread creations", John Uhlmann, BSidesCbr

  Рет қаралды 174

BSides Canberra

BSides Canberra

Күн бұрын

Since its debut in 2017, Get-InjectedThread.ps1 has been a blue team staple for identifying suspicious threads via their start addresses. However, red teams have subsequently identified low-cost evasion techniques to counteract this - obfuscating their shellcode threads with start addresses within legitimate modules.
This talk will outline the memory artifacts that each evasion leaves behind and the development of an updated script which may be used to detect them.
John Uhlmann
John (he/him) is a Security Research Engineer at Elastic, where he focuses on scalable Windows in-memory malware detection. Prior to this he did similar work at the Australian Cyber Security Centre.

Пікірлер
SPONGEBOB POWER-UPS IN BRAWL STARS!!!
08:35
Brawl Stars
Рет қаралды 22 МЛН
طردت النملة من المنزل😡 ماذا فعل؟🥲
00:25
Cool Tool SHORTS Arabic
Рет қаралды 24 МЛН
Oh No! My Doll Fell In The Dirt🤧💩
00:17
ToolTastic
Рет қаралды 11 МЛН
The Joker kisses Harley Quinn underwater!#Harley Quinn #joker
00:49
Harley Quinn with the Joker
Рет қаралды 21 МЛН
"Locks on the wire" by Eldar Marcussen, BSides Canberra 2023
32:19
BSides Canberra
Рет қаралды 124
"APT Attack Techniques in Azure Cloud" by Lina Lau, BSides Canberra 2023
23:15
"Cold Case - Catch a Killer in 16 Bytes" - Iggy
27:24
BSides Canberra
Рет қаралды 897
Keynote - Director-General of Security Mike Burgess
36:18
BSides Canberra
Рет қаралды 1,8 М.
SPONGEBOB POWER-UPS IN BRAWL STARS!!!
08:35
Brawl Stars
Рет қаралды 22 МЛН