BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: No-Code Malware: Windows 11 At Your Service\n   When
 : Saturday\, Aug 13\, 11:00 - 11:45 PDT\n   Where: Caesars Forum - Academy
  401-410\, 421 (Track 3) - [1]Map\n\n   SpeakerBio:Michael Bargury \, Co-F
 ounder and CTO\, Zenity.io\n   Michael Bargury is the Co-Founder and CTO o
 f Zenity\, where he helps\n   companies secure their low-code/no-code apps
 . In the past\, he headed\n   security product efforts at Azure focused on
  IoT\, APIs and IaC.\n   Michael is passionate about all things related to
  cloud\, SaaS and\n   low-code security\, and spends his time finding ways
  they could go\n   wrong. He also leads the OWASP low-code security projec
 t and writes\n   about it on DarkReading.\n   Twitter: [2]@mbrg0\n\n   Des
 cription:\n   Windows 11 ships with a nifty feature called Power Automate\
 , which\n   lets users automate mundane processes. In a nutshell\, Users c
 an build\n   custom processes and hand them to Microsoft\, which in turn e
 nsures\n   they are distributed to all user machines or Office cloud\, exe
 cuted\n   successfully and reports back to the cloud. You can probably alr
 eady\n   see where this is going.. In this presentation\, we will show how
  Power\n   Automate can be repurposed to power malware operations. We will
 \n   demonstrate the full cycle of distributing payloads\, bypassing\n   p
 erimeter controls\, executing them on victim machines and exfiltrating\n  
  data. All while using nothing but Windows baked-in and signed\n   executa
 bles\, and Office cloud services. We will then take you behind\n   the sce
 nes and explore how this service works\, what attack surface it\n   expose
 s on the machine and in the cloud\, and how it is enabled\n   by-default a
 nd can be used without explicit user consent. We will also\n   point out a
  few promising future research directions for the community\n   to pursue.
  Finally\, we will share an open-source command line tool to\n   easily ac
 complish all of the above\, so you will be able to add it into\n   your Re
 d Team arsenal and try out your own ideas.\n   '\n\n   1. https://defcon.o
 utel.org/consolidated_page.html#CaesarsAcademyBR\n   2. https://twitter.co
 m/mbrg0\n\n\n
DTEND:20220813T184500Z
DTSTART:20220813T180000Z
LOCATION:DC - Caesars Forum - Academy 401-410\, 421 (Track 3)
SUMMARY:No-Code Malware: Windows 11 At Your Service
END:VEVENT
END:VCALENDAR
