BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Weaponizing Windows Syscalls as Modern\, 32-bit Shel
 lcode\n   When: Friday\, Aug 12\, 13:30 - 13:50 PDT\n   Where: Caesars For
 um - Academy 401-410\, 421 (Track 3) - [1]Map\n   Speakers:Tarek Abdelmota
 leb\,Dr. Bramwell Brizendine\n\n   SpeakerBio:Tarek Abdelmotaleb \, Securi
 ty Researcher\, VERONA Labs\n   Tarek Abdelmotaleb is a security researche
 r at VERONA Labs\, and he is\n   a graduate student at Dakota State Univer
 sity\, who will soon graduate\n   with a MS in Computer Science. Tarek spe
 cializes in malware\n   development\, software exploitation\, reverse engi
 neering\, and malware\n   analysis. Tarek recently published an IEEE paper
  that provides a new\n   way for finding the base address of kernel32\, ma
 king it possible to do\n   shellcode without needing to make use of walkin
 g the Process\n   Environment Block (PEB).\n\n   SpeakerBio:Dr. Bramwell B
 rizendine\n   Dr. Bramwell Brizendine completed his Ph.D. in Cyber Operati
 ons\n   recently\, where he did his dissertation on Jump-Oriented Programm
 ing\,\n   a hitherto\, seldom-studied and poorly understood subset of code
 -reused\n   attacks. Bramwell developed a fully featured tool that helps\n
    facilitate JOP exploit development\, the JOP ROCKET. Bramwell is the\n 
   Director of the Vulnerability and Exploitation Research for Offensive\n 
   and Novel Attacks (VERONA Lab)\, specializing in vulnerability\n   resea
 rch\, software exploitation\, software security assessments\, and\n   the 
 development of new\, cutting-edge tools and techniques with respect\n   to
  software exploitation and malware analysis. Bramwell also teaches\n   und
 ergraduate\, graduate\, and doctoral level courses in software\n   exploit
 ation\, reverse engineering\, malware analysis\, and offensive\n   securit
 y. Bramwell teaches the development of modern Windows shellcode\n   from s
 cratch in various courses. Bramwell is a PI on an NSA grant to\n   develop
  a shellcode analysis framework. Bramwell has been a speaker at\n   many t
 op security conferences\, such as DEF CON\, Black Hat Asia\, Hack\n   in t
 he Box Amsterdam\, Hack\, and more.\n\n   Description:\n   While much know
 ledge exists on using syscalls for red team efforts\,\n   information on w
 riting original shellcode with syscalls so in modern\n   x86 is sparse and
  lacking. Our reverse engineering efforts\, however\,\n   have revealed th
 e necessary steps to take to successfully perform\n   syscalls in shellcod
 e\, both for Windows 7 and 10\, as there are some\n   significant differen
 ces.\n\n   In this talk\, we will embark upon a journey that will show the
  process\n   of reverse engineering how Windows syscalls work in both Wind
 ows 7 and\n   10\, while focusing predominately on the latter. With this n
 ecessary\n   foundation\, we will explore the process of effectively utili
 zing\n   syscalls inside shellcode. We will explore the special steps that
  must\n   be taken to set up syscalls – steps that may not be required t
 o do\n   equivalent actions with WinAPI functions.\n\n   This talk will fe
 ature various demonstrations of syscalls in x86\n   shellcode.\n\n   '\n\n
    1. https://defcon.outel.org/consolidated_page.html#CaesarsAcademyBR\n\n
 \n
DTEND:20220812T205000Z
DTSTART:20220812T203000Z
LOCATION:DC - Caesars Forum - Academy 401-410\, 421 (Track 3)
SUMMARY:Weaponizing Windows Syscalls as Modern\, 32-bit Shellcode
END:VEVENT
END:VCALENDAR
