BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Modern techniques used by Advanced Persistent Threat
  actors\n   for discovering 0-day vulnerabilities\n   When: Sunday\, Aug 1
 4\, 13:00 - 13:15 PDT\n   Where: Flamingo - Sunset-Scenic Ballroom (Advers
 ary Village) - [1]Map\n\n   SpeakerBio:Or Yair\n   Or is a security resear
 cher with over 4 years of experience in cyber\n   security. Currently a re
 searcher in SafeBreach Labs\, he started his\n   professional career in th
 e IDF. Most of his work focused on Platform\n   Research\, including Linux
  kernel components and some Android as well.\n   For over a year\, Or has 
 been drawn to the Windows world and focuses on\n   low level components re
 search.\n\n   Description:\n   Advanced Persistent Threat (APT) actors hav
 e a lot of resources and\n   motivation for reaching their targets. In man
 y cases they pick\n   specific targets very carefully. Unlike regular thre
 at actors\, APTs\n   are covert and difficult to track. They are not likel
 y to try 1-day\n   vulnerabilities to find just any target\; their targets
  are likely to\n   have the latest security updates. Most APTs carry out c
 yber attacks\n   with only unknown vulnerabilities (0-days). They need to 
 find their\n   own new 0-days in order to breach their target environment.
  To succeed\n   in the long run\, they probably need to find many 0-days\,
  so they can\n   minimize the number of times each one is used in the wild
  and the risk\n   of exposing it. The top APTs will aim for kernel vulnera
 bilities where\n   they can alter what users see in user-space\, be persis
 tent\, and\n   generally have much more control over the system.\n\n   The
 y may also aim for hypervisor vulnerabilities to attack cloud\n   services
  based on virtualization. While the search for new\n   vulnerabilities may
  be done manually\, APTs may prefer to use\n   automation for better resul
 ts and longer term usage. One type of\n   automation APTs are likely to us
 e is fuzzing! In this talk\, I will\n   present the main components of fuz
 zing\, different fuzzing strategies\,\n   and provide a quick look at kern
 el / hypervisor fuzzing - the most\n   delicate fuzzing arena of them all.
 \n\n   '\n\n   1. https://defcon.outel.org/consolidated_page.html#Flamingo
 ThirdFloor\n\n\n
DTEND:20220814T201500Z
DTSTART:20220814T200000Z
LOCATION:AVV - Flamingo - Sunset-Scenic Ballroom (Adversary Village)
SUMMARY:Modern techniques used by Advanced Persistent Threat actors for dis
 covering 0-day vulnerabilities
END:VEVENT
END:VCALENDAR
