BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: StackMoonwalk: A Novel approach to stack spoofing on
  Windows\n   x64\n   When: Sunday\, Aug 13\, 10:00 - 10:45 PDT\n   Where: 
 Caesars Forum - Forum - 105\,135\,136 - Track 1 - [1]Map\n   Speakers:Ales
 sandro "klezVirus" Magnosi\,Arash "waldo-irc"\n   Parsa\,Athanasios "trick
 ster0" Tserpelis\n\n   SpeakerBio:Alessandro "klezVirus" Magnosi \, Princi
 pal Security\n   Consultant at BSI\n   Alessandro Magnosi is a Principal c
 yber security consultant with more\n   than 10 years of experience in the 
 IT field. Currently\, he's part of\n   the Security Testing Team at BSI\, 
 which is the UK national standards\n   body\, and a Global certification\,
  training and cybersecurity firm. On\n   top of his normal work\, Alessand
 ro works as an independent researcher\n   for Synack RT\, and an OSS devel
 oper for Porchetta Industries\, where he\n   maintains offensive tools.\n 
   Twitter: [2]@@klezVirus\n\n   SpeakerBio:Arash "waldo-irc" Parsa \, Cybe
 rsecurity Professional\n   Arash Parsa is a highly skilled and passionate 
 cybersecurity\n   professional with extensive experience in threat hunting
 \, red teaming\,\n   and research. As a dedicated member of the InfoSec co
 mmunity\, Arash\n   has become a trusted name in advancing the field and h
 elping to\n   protect digital assets from ever-evolving threats. Above all
 \, Arash\n   takes great pride in being an active community member and men
 tor to\n   aspiring cybersecurity professionals. By sharing their knowledg
 e and\n   experience\, he is helping to shape the next generation of InfoS
 ec\n   experts and ensure the continued growth and success of the industry
 .\n   Twitter: [3]@@waldoirc\n\n   SpeakerBio:Athanasios "trickster0" Tser
 pelis \, Red Teamer and Malware\n   Developer\n   Thanos is a senior secur
 ity consultant in Nettitude\, focused mainly in\n   Red Teaming and specia
 lizes in Offensive tool development such as\n   elaborate malwares\, EDR e
 vasion techniques and tooling that makes a\n   red teamer's life easier. A
 dditionally\, he is really into low level\n   stuff\, such as exploit deve
 lopment in Windows OS.\n   Twitter: [4]@trickster012\n\n   Description:\n 
   The rapid advancement of cyber defense products has led to an increase\n
    in sophisticated memory evasion techniques employed by Red Teaming and\
 n   Malware Development communities. These techniques aim to bypass the\n 
   detection of malicious code by concealing its presence in a target\n   p
 rocess's memory. Among these methods\, "Thread Stack Spoofing" is a\n   te
 chnique that hides malicious calls in the stack by replacing\n   arbitrary
  stack frames with fake ones.\n\n   In this talk\, we present two novel ap
 proaches\, "Full Moon" and "Half\n   Moon\," for tampering with call stack
 s in a manner that is both opaque\n   and difficult to detect. These techn
 iques manipulate the call stack to\n   produce unwinding or logically vali
 d stacks\, thwarting conventional\n   detection methods.\n\n   We also int
 roduce a detection algorithm\, Eclipse\, designed to identify\n   instance
 s of these tampering techniques. This algorithm extends the\n   functional
 ity of RtlVirtualUnwind to perform strict checks on specific\n   instructi
 ons and call sequences\, enabling the detection of tampered\n   call stack
 s. We evaluate the efficacy of Eclipse against both Full\n   Moon and Half
  Moon techniques and discuss its performance and\n   limitations.\n\n   Ad
 ditionally\, we explore the possibility of combining these techniques\n   
 to create an even more robust method for call stack tampering that is\n   
 resistant to detection. Our study contributes to the growing body of\n   k
 nowledge in the field of call stack tampering and detection and\n   provid
 es valuable insights for researchers and security professionals\n   aiming
  to mitigate such threats.\n\n   REFERENCES\n\n   namazso. 2019. x64 retur
 n address spoofing (source + explanation).\n   UnKnoWnCheaTs - Multiplayer
  Game Hacking and Cheats. Retrieved April\n   4\, 2023 from [5]https://www
 .unknowncheats.me/forum/anti-cheat-bypass/268039-x64-return-address-spoofi
 ng-source-explanation.html\n   Mariusz Banach. 2023. Thread Stack Spoofing
  / Call Stack Spoofing PoC.\n   Retrieved April 3\, 2023 from [6]https://g
 ithub.com/mgeeky/ThreadStackSpoofer\n   William Burgess. Behind the Mask: 
 Spoofing Call Stacks Dynamically\n   with Timers | Cobalt Strike Blog. For
 tra. Retrieved April 3\, 2023 from\n   [7]https://www.cobaltstrike.com/blo
 g/behind-the-mask-spoofing-call-stacks-dynamically-with-timers/\n   Willia
 m Burgess. Spoofing Call Stacks To Confuse EDRs. Retrieved April\n   4\, 2
 023 from [8]https://labs.withsecure.com/publications/spoofing-call-stacks-
 to-confuse-edrs\n   Microsoft Corp. 2021. x64 prolog and epilog. Retrieved
  April 3\, 2023\n   from [9]https://learn.microsoft.com/en-us/cpp/build/pr
 olog-and-epilog\n   Microsoft Corp. 2022. x64 exception handling. Retrieve
 d April 3\, 2023\n   from [10]https://learn.microsoft.com/en-us/cpp/build/
 exception-handling-x64\n   CodeMachine. 2021. x64 Deep Dive. Retrieved Apr
 il 3\, 2023 from [11]https://www.codemachine.com/article_x64deepdive.html\
 n\n   '\n\n   1. #CaesarsForumBR\n   2. https://twitter.com/@klezVirus\n  
  3. https://twitter.com/@waldoirc\n   4. https://twitter.com/trickster012\
 n   5. https://www.unknowncheats.me/forum/anti-cheat-bypass/268039-x64-ret
 urn-address-spoofing-source-explanation.html\n   6. https://github.com/mge
 eky/ThreadStackSpoofer\n   7. https://www.cobaltstrike.com/blog/behind-the
 -mask-spoofing-call-stacks-dynamically-with-timers/\n   8. https://labs.wi
 thsecure.com/publications/spoofing-call-stacks-to-confuse-edrs\n   9. http
 s://learn.microsoft.com/en-us/cpp/build/prolog-and-epilog\n   10. https://
 learn.microsoft.com/en-us/cpp/build/exception-handling-x64\n   11. https:/
 /www.codemachine.com/article_x64deepdive.html\n\n\n
DTEND:20230813T174500Z
DTSTART:20230813T170000Z
LOCATION:DC - Caesars Forum - Forum - 105\,135\,136 - Track 1
SUMMARY:StackMoonwalk: A Novel approach to stack spoofing on Windows x64
END:VEVENT
END:VCALENDAR
