BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: The Art of Modern Malware Analysis: Initial Infectio
 n Malware\,\n   Infrastructure\, and C2 Frameworks\n   When: Friday\, Aug 
 12\, 09:00 - 12:59 PDT\n   Where: Harrah's - Lake Tahoe (Workshops) - [1]M
 ap\n   Speakers:Aaron Rosenmund\,Josh Stroschein\,Ryan J Chapman\n\n   Spe
 akerBio:Aaron Rosenmund \, Threat Emulation and Detection Operator\n   Aar
 on Rosenmund is an experienced threat emulation and detection\n   operator
 . He is the Director of Security Research and Curriculum at\n   Pluralsigh
 t\, and as the Civilian Red Team Lead for the national DOD\n   exercise Cy
 ber Shield. Part time he serves in the Florida Air National\n   Guard supp
 orting state and federal missions including election support\n   and Opera
 tion Noble Eagle (Homeland Defense). An accomplished speaker\n   and train
 er\, he has over 100 published courses and labs\, provided\n   numerous ta
 lks and workshops\, and continues to support various open\n   source proje
 cts. Www.AaronRosenmund.com @arosenmund “ironcat”\n   Twitter: [2]@aro
 senmund\n\n   SpeakerBio:Josh Stroschein \, Malware Analyst\n   Josh is an
  experienced malware analyst and reverse engineer who has a\n   passion fo
 r sharing his knowledge with others. He is the Director of\n   Training fo
 r OISF\, where he leads all training activities for the\n   foundation and
  is also responsible for academic outreach and\n   developing research ini
 tiatives. Josh is an accomplished trainer\,\n   providing training in the 
 aforementioned subject areas at BlackHat\,\n   DerbyCon\, Toorcon\, Hack-I
 n-The-Box\, Suricon and other public and\n   private venues. Josh is an As
 sistant Professor of Cyber Security at\n   Dakota State University where h
 e teaches malware analysis and reverse\n   engineering\, an author on Plur
 alsight\, and a threat researcher for\n   Bromium.\n\n   SpeakerBio:Ryan J
  Chapman \, IR Practitioner\n   Ryan is an experienced IR practitioner\, m
 alware analyst\, and trainer.\n   He is a Principal IR Consultant for Blac
 kBerry\, the lead organizer of\n   CactusCon\, a SANS author and trainer\,
  and a Pluralsight author. Ryan\n   strives to imbue comedy into his train
 ing and loves being able to\n   teach others while learning from them at t
 he same time. He is a\n   veteran speaker having presented talks and/or wo
 rkshops at conferences\n   including DefCon\, SANS Summits\, BSides events
 \, CactusCon\, and more.\n   "We must not teach people how to press button
 s to get results. We must\n   teach people what happens when these buttons
  are clicked\, such that\n   they fully understand the processes occurring
  in the background\," says\n   Ryan.\n\n   Description:\n   Threat actors 
 go to great lengths to bypass enterprise security to\n   deliver malware\,
  avoid detection after the initial intrusion\, and\n   maintain persistenc
 e to compromise an organization. To achieve this\,\n   threat actors emplo
 y a wide variety of obfuscation and anti-analysis\n   techniques at each p
 hase of an attack. Often\, Malware-as-a-Service\n   (MaaS) is leveraged. I
 n this workshop\, you will get hands-on\n   experience with real-world mal
 ware and learn how to identify key\n   indicators of compromise (IOCs)\, a
 pply analysis to enhance security\n   products to protect users and infras
 tructure\, and gain a deeper\n   understanding of malware behavior through
  reverse engineering.\n\n   Our workshop focuses on MaaS samples and their
  prevalence in attacks.\n   We will break down various MaaS samples and sh
 ow how they function. We\n   will review attacker-controlled infrastructur
 e to show how Command and\n   Control (C2) features are successful within 
 YOUR (hopefully not YOUR!)\n   environment. We will conclude with an analy
 sis of the world’s #1 C2\n   infrastructure: Cobalt Strike (CS). We will
  break down the CS\n   infrastructure\, show how Malleable C2 profiles fun
 ction\, and show you\n   how to extract and analyze profile configurations
  from script- and\n   PE-based payloads alike.\n\n   Students will be prov
 ided with all the lab material used throughout\n   the course in a digital
  format. This includes all lab material\, lab\n   guides\, and virtual mac
 hines used for training. The material provided\n   will help to ensure tha
 t students have the ability to continue\n   learning well after the course
  ends and maximize the knowledge gained\n   from this course. Whatever isn
 ’t covered during the class\, or\n   whatever the student wants to focus
  on later\, will be available.\n\n   Materials\n         Linux/Windows/Mac
  desktop environment A laptop with the ability\n         to run virtualiza
 tion software such as VMWare or VirtualBox\n         Access to the system 
 BIOS to enable virtualization\, if disabled\n         via the chipset Abil
 ity to temporarily disable anti-virus or\n         white-list folders/file
 s associated with lab material A laptop\n         that the attendee is com
 fortable handling live malware on Enough\n         disk space to store at 
 least two 40 GB VMs\, although more VMs\n         may be used 16GB of RAM 
 preferred to run all VMs simultaneously\n\n   Prereq\n         The primary
  requirement for this course is a desire to learn and\n         the determ
 ination to tackle challenging problems. In addition\,\n         having som
 e familiarization with the following topics will help\n         students m
 aximize their time in this course: - A general\n         background in Dig
 ital Forensics & Incident Response (DFIR) -\n         Familiarity with blu
 e team-oriented tools - An understanding of\n         general networking c
 oncepts\n\n   '\n\n   1. https://defcon.outel.org/consolidated_page.html#H
 arrahs\n   2. https://twitter.com/arosenmund\n\n\n
DTEND:20220812T195900Z
DTSTART:20220812T160000Z
LOCATION:WS - Harrah's - Lake Tahoe (Workshops)
SUMMARY:The Art of Modern Malware Analysis: Initial Infection Malware\, Inf
 rastructure\, and C2 Frameworks
END:VEVENT
END:VCALENDAR
