BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: LSASS Shtinkering: Abusing Windows Error Reporting t
 o Dump\n   LSASS\n   When: Friday\, Aug 12\, 15:00 - 15:45 PDT\n   Where: 
 Caesars Forum - Academy 401-410\, 421 (Track 3) - [1]Map\n   Speakers:Asaf
  Gilboa\,Ron Ben Yitzhak\n\n   SpeakerBio:Asaf Gilboa \, Security Research
 er\, Deep Instinct\n   Asaf and Ron are Security Researchers at Deep Insti
 nct where they both\n   work on developing new defense capabilities based 
 on research and\n   understanding and novel attack techniques and vectors.
  After serving\n   for several years in the advanced technological cyber u
 nits of the\n   IDF\, Asaf and Ron gained experience in the multiple aspec
 ts of\n   technical cyber-security work including forensics\, incident res
 ponse\,\n   development\, reverse engineering and malware research.\n\n   
 SpeakerBio:Ron Ben Yitzhak\n   Asaf Gilboa and Ron Ben Yitzhak\n\n   Asaf 
 and Ron are Security Researchers at Deep Instinct where they both\n   work
  on developing new defense capabilities based on research and\n   understa
 nding and novel attack techniques and vectors. After serving\n   for sever
 al years in the advanced technological cyber units of the\n   IDF\, Asaf a
 nd Ron gained experience in the multiple aspects of\n   technical cyber-se
 curity work including forensics\, incident response\,\n   development\, re
 verse engineering and malware research.\n\n\n   Description:\n   This pres
 entation will show a new method of dumping LSASS that\n   bypasses current
  EDR defenses without using a vulnerability but by\n   abusing a built-in 
 mechanism in the Windows environment which is the\n   WER (Windows Error R
 eporting) service.\n\n   WER is a built-in system in Windows designed to g
 ather information\n   about software crashes. One of its main features is 
 producing a memory\n   dump of crashing user-mode processes for further an
 alysis.\n\n   We will present in detail and demo a new attack vector for d
 umping\n   LSASS\, which we dubbed LSASS Shtinkering\, by manually reporti
 ng an\n   exception to WER on the LSASS process without crashing it. The\n
    technique can also be used to dump the memory of any other process of\n
    interest on the system.\n\n   This attack can bypass defenses that wron
 gfully assume that a memory\n   dump generated from the WER service is alw
 ays a benign or non-attacker\n   triggered activity.\n\n   The talk will t
 ake the audience through the steps and approach of how\n   we reverse-engi
 neered the WER dumping process\, the challenges we found\n   along the way
 \, as well as how we have managed to solve them.\n\n   '\n\n   1. https://
 defcon.outel.org/consolidated_page.html#CaesarsAcademyBR\n\n\n
DTEND:20220812T224500Z
DTSTART:20220812T220000Z
LOCATION:DC - Caesars Forum - Academy 401-410\, 421 (Track 3)
SUMMARY:LSASS Shtinkering: Abusing Windows Error Reporting to Dump LSASS
END:VEVENT
END:VCALENDAR
