BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Master of Puppets: How to tamper the EDR?\n   When: 
 Friday\, Aug 12\, 14:00 - 14:30 PDT\n   Where: Flamingo - Sunset-Scenic Ba
 llroom (Adversary Village) - [1]Map\n\n   SpeakerBio:Daniel Feichter\n   D
 aniel Feichter has his original background in industrial engineering\,\n  
  he started 3.5 years ago more or less as an offensive security rookie\n  
  in an employed relationship. For different reasons he decided to start\n 
   his own company in 2022 (Infosec Tirol)\, with which he focuses even\n  
  more on offensive security like APT testing\, adversary simulation and\n 
   red teaming. Daniel invests a lot of his time in learning and\n   resear
 ching in the area of endpoint security. Based on the Windows\n   Internals
  he tries day by day to better understand AV/EPP/EDR products\n   on Windo
 ws and is always looking for new ways to bypass and evade\n   them.\n   Tw
 itter: [2]@virtualallocex\n\n   Description:\n   More and more companies r
 ealize\, trying to prevent malicious\n   activities alone is not enough\, 
 therefore more and more companies are\n   using EDR products in their envi
 ronment. From red team perspective\n   this gets more and more a challenge
 \, because even if the red team has\n   achieved a local privilege escalat
 ion\, most well known EDR products\n   are still be very annoying. In the 
 last few months we saw a lot about\n   bypassing EDRs\, but what about pos
 sible ways to disable the main\n   functionalities from an EDR by targeted
 \, controlled tampering from\n   specific key components from them? What E
 DR components can be a key\n   element in Windows user space and kernel sp
 ace to disable the EDR main\n   functionalities\, but without relying on a
 n uninstall password\,\n   uninstalling the product or using the Windows s
 ecurity center. And how\n   can we as red teamer not just get rid of preve
 ntion by the antivirus\n   module from an EPP/EDR\, instead we also want t
 o get rid of detections\n   (active alerts in the web console) by the EDR 
 module\, get rid of the\n   telemetry footprint based on the EDR sensor\, 
 host isolation\, real time\n   response remote shells and EDR sensor recov
 ery feature.\n   '\n\n   1. https://defcon.outel.org/consolidated_page.htm
 l#FlamingoThirdFloor\n   2. https://twitter.com/virtualallocex\n\n\n
DTEND:20220812T213000Z
DTSTART:20220812T210000Z
LOCATION:AVV - Flamingo - Sunset-Scenic Ballroom (Adversary Village)
SUMMARY:Master of Puppets: How to tamper the EDR?
END:VEVENT
END:VCALENDAR
