BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: The Purple Malware Development Approach\n   When: Th
 ursday\, Aug 11\, 09:00 - 12:59 PDT\n   Where: Harrah's - Elko (Workshops)
  - [1]Map\n   Speakers:Mauricio Velazco\,Olaf Hartong\n\n   SpeakerBio:Mau
 ricio Velazco \, Principal Threat Research Engineer\n   Mauricio Velazco (
 @mvelazco) is a Principal Threat Research Engineer\n   at Splunk. Prior to
  Splunk\, he led the Threat Management team at a\n   Fortune 500 organizat
 ion. Mauricio has presented and hosted workshops\n   at conferences like D
 efcon\, BlackHat\, Derbycon\, BSides and SANS. His\n   main areas of focus
  include detection engineering\, threat hunting and\n   adversary simulati
 on.\n   Twitter: [2]@mvelazco\n\n   SpeakerBio:Olaf Hartong \, Defensive S
 pecialist\n   Olaf Hartong is a Defensive Specialist and security research
 er at\n   FalconForce. He specializes in understanding the attacker tradec
 raft\n   and thereby improving detection. He has a varied background in bl
 ue\n   and purple team operations\, network engineering\, and security\n  
  transformation projects. Olaf has presented at many industry\n   conferen
 ces including WWHF\, Black Hat\, DEF CON\, DerbyCon\, Splunk\n   .conf\, F
 IRST\, MITRE ATT&CKcon\, and various other conferences. Olaf is\n   the au
 thor of various tools including ThreatHunting for Splunk\,\n   ATTACKdatam
 ap and Sysmon-modular.\n\n   Description:\n   This workshop merges offensi
 ve and defensive lab exercises to provide\n   attendees hands-on experienc
 e on custom malware development as well as\n   live malware analysis and r
 esponse. The workshop has a total of 5\n   hands-on exercises and each con
 tains a Red and a Blue section. In the\n   Red section attendees write cus
 tom payloads using C# and C++ with\n   different techniques to obtain a re
 verse shell on a Windows victim\n   endpoint. In the Blue section attendee
 s investigate the infection by\n   reviewing events and logs using open so
 urce static and dynamic malware\n   analysis tools like CFFExplorer\, Pe-S
 tudio\, dnSpy\, Process Explorer\,\n   Process Monitor\, Sysmon\, Frida\, 
 Velociraptor\, etc..\n\n   Materials\n         Laptop with virtualization 
 software. A Windows virtual machine A\n         Kali Linux Virtual Machine
 .\n\n   Prereq\n         Beginner to intermediate programming/scripting sk
 ills. Prior\n         experience with C# helps but not required. Beginner 
 static and\n         dynamic malware analysis skills.\n\n   '\n\n   1. htt
 ps://defcon.outel.org/consolidated_page.html#Harrahs\n   2. https://twitte
 r.com/mvelazco\n\n\n
DTEND:20220811T195900Z
DTSTART:20220811T160000Z
LOCATION:WS - Harrah's - Elko (Workshops)
SUMMARY:The Purple Malware Development Approach
END:VEVENT
END:VCALENDAR
