BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: beacon injected with HOOKCHAIN 2026\n   Tags: Red Te
 am Village | Misc\n   When: Sunday\, Aug 9\, 14:00 - 14:59 PDT\n   Where: 
 LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 -\n   [1]Map\n\
 n   Description:\n\n   In penetration testing\, we constantly find ourselv
 es facing EDRs/AVs\,\n   etc. But as in all cases\, we aim to develop our 
 own tooling or\n   techniques that we believe may not yet be properly mapp
 ed or detected.\n   On this occasion\, we share part of our perspective wh
 en dealing with\n   EDRs using Machine Learning technology configured in â
 €œFULLâ€ mode.\n   We were able to leverage this technique combined with 
 an encrypted\n   payload to evade this configuration\; additionally\, when
  the payload\n   was downloaded or shared as a â€œ.zip\,â€ the agent did 
 not inspect\n   it. Now\, letâ€™s dive a bit into the technical aspects\, 
 but especially\n   into how it was exploited. HookChain is an advanced tec
 hnique for\n   evading EDR solutions. It is primarily used by threat actor
 s (APTs)\,\n   but it can also be applied ethically in Red Team exercises.
  Its main\n   principle is to intercept the hooks that EDRs install in the
  operating\n   system kernel. What is a hook? Hooks are a mechanism used b
 y EDRs to\n   monitor calls to Windows API functions\, mainly from ntdll.d
 ll. In this\n   way\, they can intercept and analyze suspicious behavior i
 n real time.\n   The HookChain technique aims to bypass this monitoring la
 yer.\n\n   Encrypting our payload with XOR HookChain typically combines ho
 ok\n   evasion with payload encryption\; in this case\, we will use XOR to
 \n   avoid static signature-based detection. The shellcode is encrypted in
 \n   memory and only decrypted right before execution.\n\n   We can use a 
 string (in this case\, â€œCHANGEMYKEYâ€) as the key for\n   our XOR encry
 ption\, along with shellcode generated using msfvenom\,\n   although we ca
 n also leverage other C2 frameworks\, as we will see\n   later.\n\n   Spea
 kerBio:  Arnold Jared Morales Yepez\, Senior Team Lead\, Grupo\n   Salinas
 \n\n   Self-taught in computer security since age 12\; holds a degree in\n
    Computer Forensics and Cybersecurity and is pursuing a Master's in AI\n
    and Cybersecurity.\n\n   --\n\n   Desde los 12 aÃ±os\, me he dedicado a
  la informÃ¡tica con un enfoque\n   especial en la seguridad. Actualmente\
 , a mis 22 aÃ±os\, sigo explorando\n   este mundo con la misma pasiÃ³n\, i
 mpulsado por la constante evoluciÃ³n\n   de la tecnologÃa y su interminabl
 e curva de aprendizaje.\n\n   Cuento con una carrera en CÃ³mputo Forense y
  Ciberseguridad\,\n   actualmente curso una maestrÃa en Inteligencia Artif
 icial y\n   Ciberseguridad.\n\n   Certificaciones: CWEE | CAPE |CPTS | EWP
 TX | CRTO | eMAPT | OSCP |\n   OSCP+ |CEH V13 | EJPT| HTB prolabs Hades - 
 Cybernetics - Zephyr -\n   APTlabs | MDK\n\n   '\n\n   1. #LVCCW_Level1_Ha
 ll1\n\n\n
DTEND:20260809T215900Z
DTSTART:20260809T210000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Tac
 tic Table 3
SUMMARY:beacon injected with HOOKCHAIN 2026
END:VEVENT
END:VCALENDAR
