BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Evading Detection: A Beginner's Guide to Obfuscation
 \n   When: Saturday\, Aug 13\, 14:00 - 17:59 PDT\n   Where: Harrah's - Lak
 e Tahoe (Workshops) - [1]Map\n   Speakers:Anthony "Cx01N" Rose\,Vincent "V
 innybod" Rose\,Jake "Hubbl3"\n   Krasnov\n\n   SpeakerBio:Anthony "Cx01N" 
 Rose \, Lead Security Researcher\n   Anthony "Cx01N" Rose\, CISSP\, is a S
 ecurity Researcher and Chief\n   Operating Officer at BC Security\, where 
 he specializes in adversary\n   tactic emulation planning\, Red and Blue T
 eam operations\, and embedded\n   systems security. He has presented at nu
 merous security conferences\,\n   including Black Hat\, DEF CON\, and RSA 
 conferences. Anthony is the\n   author of various offensive security tools
 \, including Empire and\n   Starkiller\, which he actively develops and ma
 intains. He is recognized\n   for his work\, revealing widespread vulnerab
 ilities in Bluetooth\n   devices and is the co-author of a cybersecurity b
 log at [2]https://www.bc-security.org/blog/.\n   Twitter: [3]@Cx01N_\n\n  
  SpeakerBio:Vincent "Vinnybod" Rose \, Lead Tool Developer\n   Vincent "Vi
 nnybod" Rose is the lead developer for Empire and\n   Starkiller. He is a 
 software engineer with experience in cloud\n   services\, large-scale web 
 applications\, build pipeline automation\, and\n   big data ETL. Vinnybod 
 has presented at Black Hat and has taught\n   courses at DEF CON on Red Te
 aming and Offensive PowerShell. He\n   currently maintains a cybersecurity
  blog focused on offensive security\n   at [4]https://www.bc-security.org/
 blog/.\n\n   SpeakerBio:Jake "Hubbl3" Krasnov \, Red Team Operations Lead 
 and Chief\n   Executive Officer\n   Jake "Hubbl3" Krasnov is the Red Team 
 Operations Lead and Chief\n   Executive Officer of BC Security. He has spe
 nt the first half of his\n   career as an Astronautical Engineer overseein
 g rocket modifications\n   for the Air Force. He then moved into offensive
  security\, running\n   operational cyber testing for fighter aircraft and
  operating on a red\n   team. Jake has presented at DEF CON\, where he tau
 ght courses on\n   offensive PowerShell and has been recognized by Microso
 ft for his\n   discovery of a vulnerability in AMSI. Jake has authored num
 erous\n   tools\, including Invoke-PrintDemon and Invoke-ZeroLogon\, and i
 s the\n   co-author of a cybersecurity blog at [5]https://www.bc-security.
 org/blog/.\n   Twitter: [6]@_Hubbl3\n\n   Description:\n   Defenders are c
 onstantly adapting their security to counter new\n   threats. Our mission 
 is to identify how they plan on securing their\n   systems and avoid being
  identified as a threat. This is a hands-on\n   class to learn the methodo
 logy behind malware delivery and avoiding\n   detection. This workshop exp
 lores the inner workings of Microsoft's\n   Antimalware Scan Interface (AM
 SI)\, Windows Defender\, and Event Tracing\n   for Windows (ETW). We will 
 learn how to employ obfuscated malware\n   using Visual Basic (VB)\, Power
 Shell\, and C# to avoid Microsoft's\n   defenses. Students will learn to b
 uild AMSI bypass techniques\,\n   obfuscate payloads from dynamic and stat
 ic signature detection\n   methods\, and learn about alternative network e
 vasion methods.\n\n   In this workshop\, we will:\n\n   i.            Unde
 rstand the use and employment of obfuscation in red teaming.\n   ii.      
      Demonstrate the concept of least obfuscation.\n   iii.          Intro
 duce Microsoft's Antimalware Scan Interface (AMSI) and explain its importa
 nce.\n   iv.          Demonstrate obfuscation methodology for .NET payload
 s.   \n\n   Materials\n         Laptop VMWare or Virtual Box Windows Dev m
 achine or other\n         Windows VM Kali Linux VM\n\n   Prereq\n         
 Basic level of PowerShell or C# experience.\n\n   '\n\n   1. https://defco
 n.outel.org/consolidated_page.html#Harrahs\n   2. https://www.bc-security.
 org/blog/.\n   3. https://twitter.com/Cx01N_\n   4. https://www.bc-securit
 y.org/blog/.\n   5. https://www.bc-security.org/blog/.\n   6. https://twit
 ter.com/_Hubbl3\n\n\n
DTEND:20220814T005900Z
DTSTART:20220813T210000Z
LOCATION:WS - Harrah's - Lake Tahoe (Workshops)
SUMMARY:Evading Detection: A Beginner's Guide to Obfuscation
END:VEVENT
END:VCALENDAR
