BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: DFMI: Weaponizing MSI Installers for Fileless Code E
 xecution\n   Tags: Red Team Village | Misc\n   When: Sunday\, Aug 9\, 14:0
 0 - 14:59 PDT\n   Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Works
 hop Stage 1 -\n   [1]Map\n\n   Description:\n\n   DFMI is a cross-platform
 \, open-source offensive toolkit that hijacks &\n   abuses the Windows Ins
 taller's own execution engine to detonate\n   arbitrary payloads during so
 ftware installation\, with zero files\n   written to disk and zero evidenc
 e left behind. And this can be\n   achieved without even corrupting the Au
 thenticode of the binary.\n\n   The attack surface is the CustomAction tab
 le embedded in every MSI\n   database — a small structure that Windows I
 nstaller processes\n   unconditionally at install time. DFMI injects a def
 erred CustomAction\n   (property-based EXE invocation) — firing right be
 fore the\n   modification in system files\; the payload executes before a 
 single\n   legitimate byte touches the filesystem.\n\n   Right now\, DFMI 
 provides 3 different methods for abusing MSI files: -\n   Inject: Simply i
 njects a CustomAction (CA) into an existing MSI\n   package. - Rogue MST: 
 Generates an MSI Transform File (.mst) and\n   injects into legitimate ".m
 si" file without corrupting it's\n   Authenticode. - Stub: Creates a malic
 ious MSI file from scratch.\n\n   What makes DFMI particularly difficult t
 o eradicate is that it\n   exploits no vulnerability\; it's a feature. The
  CustomAction mechanism\n   is a 25-year-old Windows feature\, documented 
 by Microsoft\, used by\n   virtually every enterprise software package and
  trusted implicitly by\n   the OS.\n\n   DFMI simply turns that trust side
 ways — using the Installer engine\n   as its own payload executor.\n\n  
  https://github.com/ccelikanil/DFMI\n\n   SpeakerBio:  Anıl Çelik\n\n   
 Computer Engineer & been working as a Red Teamer for the past ~7\n   years
 . Previously did presentations at DEFCON 33 Demo Labs\, DEFCON 33\n   Red 
 Team Village & Black Hat USA Arsenal 2025. Currently holding 6\n   CVEs\, 
 OSCP & OSWP. Interests: Windows Internals & AD Security\n\n   '\n\n   1. #
 LVCCW_Level1_Hall1\n\n\n
DTEND:20260809T215900Z
DTSTART:20260809T210000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Wor
 kshop Stage 1
SUMMARY:DFMI: Weaponizing MSI Installers for Fileless Code Execution
END:VEVENT
END:VCALENDAR
