BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Infostealer: Replicating Commodity Threat Actor Cred
 ential\n   Theft TTPs and Validating Detection Gaps\n   Tags: Adversary Vi
 llage | Creator Workshop\n   When: Saturday\, Aug 8\, 13:00 - 14:55 PDT\n 
   Where: LVCCW Level 1 Hall 2 602 (Adversary Village) Workshop Stage -\n  
  [1]Map\n\n   Description:\n\n   Commodity infostealers account for a sign
 ificant share of initial\n   access in enterprise breaches. Their TTPs are
  documented\, their\n   tooling is public\, and most detection stacks stil
 l miss them. This\n   workshop emulates the full infostealer playbook agai
 nst a live target\n   and measures exactly where the gaps are.\n\n   Atten
 dees execute an eight-stage adversary emulation scenario\n   replicating d
 ocumented commodity threat actor TTPs: HTA phishing\n   delivery\, in-memo
 ry C2 via Meterpreter\, browser credential theft from\n   Chrome and Edge 
 using DPAPI and the SQLite Login Data file\, in-memory\n   keylogging via 
 process migration to explorer.exe\, UAC bypass using the\n   fodhelper reg
 istry hijack documented across multiple threat actor\n   profiles\, and LS
 ASS credential dumping via Kiwi/Mimikatz recovering\n   NTLM hashes\, SAM 
 contents\, and the DPAPI_SYSTEM master key. Every\n   technique is drawn f
 rom documented threat actor behavior and mapped to\n   MITRE ATT&CK before
  execution begins.\n\n   The second half of the workshop shifts to validat
 ion. Attendees enable\n   Sysmon64 telemetry and replay the emulation\, st
 age by stage\,\n   identifying which techniques generated detectable event
 s and which did\n   not. Each gap maps to a concrete control recommendatio
 n. The\n   keylogging stage writes nothing to disk. The Meterpreter sessio
 n\n   exists only in memory. The DPAPI_SYSTEM extraction is not anomalous 
 to\n   most SIEMs by default. Attendees document all three as validated\n 
   findings\, not assumptions.\n\n   Key Takeaways\n\n     1. \n\n       Ad
 versary emulation with real TTPs produces validated detection\n       gaps
 \, not theoretical ones. Running the actual technique against\n       your
  stack tells you whether the control works. Running it in this\n       wor
 kshop tells you before an attacker does.\n\n     2. \n\n       In-memory e
 xecution breaks file-based detection entirely.\n       Meterpreter leaves 
 no binary on disk. The only detection path is\n       behavioral: process 
 injection signals\, memory scanning\, or network\n       correlation betwe
 en a user-context process and an external C2\n       session.\n\n     3. \
 n\n       DPAPI_SYSTEM recovery after LSASS access retroactively compromis
 es\n       all protected data on the machine. Most SIEMs do not alert on t
 his\n       extraction by default. Attendees leave with the specific Event
  IDs\n       and Sysmon rule configuration that catch it.\n\n   SpeakerBio
 :  Filipi Pires\, Head of Technical Advocacy at SCYTHE\n\n   I’ve been w
 orking as Head of Technical Advocacy at SCYTHE\, Founder &\n   Investor at
  CROSS-INTEL\, Advisor & Investor at Sherlockeye\, BSides\n   Porto Organi
 zer\, Red Team Village Director (DEF CON)\, Senior Advisor\n   Raices Cybe
 r Academy\, Founder of Red Team Community (Brazil and\n   LATAM)\, AWS Com
 munity Builder\, Snyk Ambassador\, Application Security\n   Specialist and
  Hacking is NOT a crime Advocate. International Speaker\n   at Security an
 d New technologies events in many countries such as US\n   (Black Hat & De
 fcon)\, Canada\, France\, Spain\, Germany\, Poland\, Black\n   Hat MEA - M
 iddle-East - and others\, I’ve served as University\n   Professor in Mas
 ter Degree in Portugal\, Graduation and MBA courses at\n   Brazilian colle
 ges\, in addition\, I'm Creator and Instructor of the\n   Course - Malware
  Attack Types with Kill Chain Methodology\n   (PentestMagazine)\, PowerShe
 ll and Windows for Red\n   Teamers(PentestMagazine) and Malware Analysis -
  Fundamentals\n   (HackerSec).\n\n   Black Hat US 2025 -\n   https://black
 hat.com/us-25/arsenal/schedule/presenters.html#filipi-pires-46329\n   Blac
 k Hat US 2024 -\n   https://blackhat.com/us-24/arsenal/schedule/presenters
 .html#filipi-pires-46329\n   Black Hat MEA 2025 - https://blackhatmea.com/
 speaker/filipi-pires-0\n   Black Hat MEA 2024 - https://blackhatmea.com/sp
 eaker/filipi-pires DEF\n   CON 33 / 32 - https://sessionize.com/filipi-pir
 es/ DEF CON - Adversary\n   Village -\n   https://adversaryvillage.org/adv
 ersary-events/DEFCON-33/Filipi-Pires/\n\n   Links:\n       adversaryvillag
 e.org/adversary-events/DEFCON-34/Filipi-Pires/ -\n   [2]https://adversaryv
 illage.org/adversary-events/DEFCON-34/Filipi-Pires/\n   '\n\n   1. #LVCCW_
 Level1_Hall2\n   2. https://adversaryvillage.org/adversary-events/DEFCON-3
 4/Filipi-Pires/\n\n\n
DTEND:20260808T215500Z
DTSTART:20260808T200000Z
LOCATION:Adversary Village - LVCCW Level 1 Hall 2 602 (Adversary Village) W
 orkshop Stage
SUMMARY:Infostealer: Replicating Commodity Threat Actor Credential Theft TT
 Ps and Validating Detection Gaps
END:VEVENT
END:VCALENDAR
