BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Less SmartScreen More Caffeine – ClickOnce (Ab)Use
  for\n   Trusted Code Execution\n   When: Sunday\, Aug 14\, 13:00 - 13:45 
 PDT\n   Where: Caesars Forum - Forum 104-105\, 135-136 (Track 1) - [1]Map\
 n   Speakers:Nick Powers\,Steven Flores\n\n   SpeakerBio:Nick Powers \, Co
 nsultant at SpecterOps\n   Nick Powers is an operator and red teamer at Sp
 ecterOps. He has\n   experience with providing\, as well as leading\, pent
 est and red team\n   service offerings for a large number of fortune 500 c
 ompanies. Prior\n   to offensive security\, Nick gained security and consu
 lting experience\n   while offering compliance-based gap assessments and v
 ulnerability\n   audits. With a career focused on offensive security\, his
  interests and\n   prior research focuses have included initial access tec
 hniques\,\n   evasive Windows code execution\, and the application of alte
 rnate C2\n   and data exfiltration channels.\n   Twitter: [2]@zyn3rgy\n\n 
   SpeakerBio:Steven Flores \, Senior Consultant at SpecterOps\n   Steven F
 lores is an experienced red team operator and former Marine.\n   Over the 
 years Steven has performed engagements against organizations\n   of varyin
 g sizes in industries that include financial\, healthcare\,\n   legal\, an
 d government. Steven enjoys learning new tradecraft and\n   developing too
 ls used during red team engagements. Steven has\n   developed several comm
 only used red team tools such as SharpRDP\,\n   SharpMove\, and SharpStay.
 \n   Twitter: [3]@0xthirteen\n\n   Description:\n   Initial access payload
 s have historically had limited methods that\n   work seamlessly in phishi
 ng campaigns and can maintain a level of\n   evasion. This payload categor
 y has been dominated by Microsoft Office\n   types\, but as recent news ha
 s shown\, the lifespan of even this\n   technique is shortening. A vehicle
  for payload delivery that has been\n   greatly overlooked for initial acc
 ess is ClickOnce. ClickOnce is very\n   versatile and has a lot of opportu
 nities for maintaining a level of\n   evasion and obfuscation. In this tal
 k we’ll cover methods of\n   bypassing Windows controls such as SmartScr
 een\, application\n   whitelisting\, and trusted code abuses with ClickOnc
 e applications.\n   Additionally\, we’ll discuss methods of turning regu
 lar signed or\n   high reputation .NET assemblies into weaponized ClickOnc
 e deployments.\n   This will result in circumvention of common security co
 ntrols and\n   extend the value of ClickOnce in the offensive use case. Fi
 nally\,\n   we’ll discuss delivery mechanisms to increase the overall le
 gitimacy\n   of ClickOnce application deployment in phishing campaigns. Th
 is talk\n   can bring to attention the power of ClickOnce applications and
  code\n   execution techniques that are not commonly used.\n   '\n\n   1. 
 https://defcon.outel.org/consolidated_page.html#CaesarsForumBR\n   2. http
 s://twitter.com/zyn3rgy\n   3. https://twitter.com/0xthirteen\n\n\n
DTEND:20220814T204500Z
DTSTART:20220814T200000Z
LOCATION:DC - Caesars Forum - Forum 104-105\, 135-136 (Track 1)
SUMMARY:Less SmartScreen More Caffeine – ClickOnce (Ab)Use for Trusted Co
 de Execution
END:VEVENT
END:VCALENDAR
