BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: STrace - A DTrace on windows reimplementation.\n   W
 hen: Sunday\, Aug 14\, 11:00 - 11:45 PDT\n   Where: Caesars Forum - Allian
 ce 301-309\, 321 (Track 4) - [1]Map\n\n   SpeakerBio:Stephen Eckels\n   St
 ephen Eckels\, is a reverse engineer that explores blue team tooling\n   a
 nd regularly sees front line malware. Stephen has published past\n   tools
  such as GoReSym - a golang symbol recovery tool\, and written\n   extensi
 vely about many forms of hooking including hooking the wow64\n   layer. St
 ephen maintains the open source hooking library PolyHook\,\n   some of his
  other work is public on the Mandiant blog!\n   Twitter: [2]@stevemk14ebr\
 n\n   Description:\n   II'll document the kernel tracing APIs in modern ve
 rsions of windows\,\n   implemented to support Microsofts' port of the ‘
 DTrace’ system to\n   windows. This system provides an officially suppor
 ted mechanism to\n   perform system call interception that is patchguard c
 ompatible\, but\n   not secure boot compatible. Alongside the history and 
 details of\n   DTrace this talk will also cover a C++ and Rust based reimp
 lementation\n   of the system that I call STrace. This reimplementation al
 lows users\n   to write custom plugin dlls which are manually mapped to th
 e kernel\n   address space. These plugins can then log all system calls\, 
 or perform\n   any side effects before and after system call execution by 
 invoking\n   the typical kernel driver APIs – if desired.\n   '\n\n   1.
  https://defcon.outel.org/consolidated_page.html#CaesarsAllianceBR\n   2. 
 https://twitter.com/stevemk14ebr\n\n\n
DTEND:20220814T184500Z
DTSTART:20220814T180000Z
LOCATION:DC - Caesars Forum - Alliance 301-309\, 321 (Track 4)
SUMMARY:STrace - A DTrace on windows reimplementation.
END:VEVENT
END:VCALENDAR
