BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Web Shell Hunting\n   When: Saturday\, Aug 13\, 11:0
 0 - 14:59 PDT\n   Where: Virtual - BlueTeam Village - Workshops\n\n   Spea
 kerBio:Joe Schottman\n   Joe Schottman has worn most hats in IT and Securi
 ty\, ranging from\n   application development to DevOps to offensive and d
 efensive security.\n   The nexus of this experience is research into Web S
 hells. He's spoken\n   and given training on topics such as Purple Teams\,
  API security\, Web\n   Shells\, Web Threat Hunting\, and more at AppSec V
 illage at DEF CON\,\n   OWASP Global\, SANS Summits\, various BSides\, Cir
 cle City Con\, and other\n   events.\n\n   Description:\n   This workshop 
 will provide the basics of what web shells are\, how they\n   are typicall
 y used\, defensive strategies to prevent them\, and ways\n   they can be d
 etected in different layers of security. The detection\n   layers that wil
 l be covered are antivirus/endpoint protection\, file\n   integrity monito
 ring\, file system analysis\, log analysis\, network\n   traffic analysis\
 , and endpoint anomaly detection.\n\n   Participants will be provided with
  a virtual machine image that they\n   could both exploit with web shells 
 and perform threat hunting on.\n\n   The breakdown is roughly this:\n   60
 -80 minutes - what web shells are\, what they're used for\, ways they\n   
 can be detected 20 minutes - overview of my perspective on what web\n   th
 reat hunting is and how it varies from conventional threat hunting\n   (TL
 DR - if you're on the internet\, you're always going to be attacked\n   so
  it's not a matter of picking up an unknown threat so much as\n   filterin
 g through evidence to determine if an attack is actually\n   dangerous) 90
 + minutes - hands-on exercises covering various ways to\n   detect web she
 lls such as file integrity monitoring\, deobfuscation\,\n   YARA\, dirty w
 ords\, time stomping\, etc. And then exploiting a\n   vulnerable applicati
 on and uploading a Web Shell and showing how it\n   can be used to plunder
  data.\n\n   Web Shells are malicious web applications used for remote acc
 ess.\n   They've been used in many of the recent prominent\n   breaches/vu
 lnerabilities including Equifax\, SolarWinds\, and ProxyLogon\n   and are 
 used by APTs and other threats. With ProxyLogon\, the FBI was\n   authoriz
 ed to remove them from victim machines.\n\n   This session will help you a
 void telling your employer that the FBI is\n   now doing volunteer admin w
 ork by teaching you about Web Shells\, how\n   to hunt for them\, and doin
 g hands-on hunting in a VM. A little\n   groundwork goes a long way and th
 is class will show what to do.\n\n   '\n\n
DTEND:20220813T215900Z
DTSTART:20220813T180000Z
LOCATION:BTV - Virtual - BlueTeam Village - Workshops
SUMMARY:Web Shell Hunting
END:VEVENT
END:VCALENDAR
