BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Weaponizing eBPF and XDP with Covert Triggered Rever
 se Shells\n   Tags: DEF CON Demo Labs | Intermediate | Defense/Blue Team |
  Malware |\n   Offense/Red Team | Purple Team | DEF CON Demo Labs\n   When
 : Saturday\, Aug 8\, 16:00 - 16:45 PDT\n   Where: LVCCW Level 1 Hall 3 901
  (Demo Labs Track 5) - [1]Map\n\n   Description:\n   eBPF and XDP now unde
 rpin critical Linux infrastructure yet their\n   kernel-level access creat
 es a blind spot: adversaries can weaponize\n   these primitives for stealt
 h persistence that evades standard forensic\n   tools. Current defenses ar
 e not equipped for this emerging threat.\n\n   We built Phantasma\, an ope
 n-source eBPF implant\, to expose this gap.\n   It combines three kernel-l
 evel techniques: (1) XDP covert triggering\n   that intercepts packets at 
 the NIC driver before they reach the\n   networking stack\, firewalls\, or
  packet capture systems (2) getdents64\n   syscall interception to hide pr
 ocesses from /proc\, defeating ps\, top\,\n   and all enumeration tools\; 
 and (3) bpf() syscall interception to cloak\n   loaded eBPF objects from b
 pftool and forensic inspection.\n\n   We live-demonstrate the full attack 
 chain deployment\, self-cloaking\,\n   magic packet activation\, and encry
 pted reverse shell showing the\n   implant defeating packet capture\, proc
 ess listing\, and BPF\n   introspection simultaneously.\n\n   We then pres
 ent the defenses this threat demands: kernel audit rules\n   for bpf() sys
 calls\, /sys/fs/bpf inspection\, XDP attachment monitoring\,\n   and behav
 ioral indicators. Attendees leave with detection rules\,\n   hardening ste
 ps\, and a clear understanding of why eBPF must be treated\n   as an attac
 k surface\, not just a defense tool.\n\n   SpeakerBio:  Yll "0xBabar0ka" B
 erisha\n\n   I am an offensive security researcher with 2 years of experie
 nce in\n   penetration testing\, red teaming\, and custom tooling. I am th
 e creator\n   of Phantasma\, an open-source eBPF/XDP implant framework for
  stealth\n   persistence research.\n\n   Professionally\, I have worked at
  Sentry\, conducting web\, mobile\, and\n   internal/external network pene
 tration tests. At Finbbug\, I contributed\n   to a US Embassy-supported pr
 oject assessing the cybersecurity posture\n   of NGOs and media organizati
 ons in Kosovo\, identifying issues such as\n   XSS\, directory listing\, a
 nd IDOR vulnerabilities. At Starlabs\, I built\n   dark web monitoring too
 ls using HaveIBeenPwned and LeakX APIs for\n   automated credential leak d
 etection.\n\n   I hold BSCP (Burp Suite Certified)\, CRT-ID (Certified Red
  Team Infra\n   Dev)\, MCRTA (Multi Cloud Red Teamer)\, CISCO ETHICAL HACK
 ER\, and\n   HACKWISER CAPT certifications. I placed 1st at the Iowa State
  Cyber\n   Defense Competition and represented Kosovo at the 2024 ENISA Eu
 ropean\n   Cybersecurity Challenge in Turin.\n\n   I have presented at Cyb
 erZero on prompt injection attacks and\n   deepfake-based social engineeri
 ng at the TechRisck conference\, and\n   co-organized national and interna
 tional CTFs designing real-world\n   attack chain challenges.\n\n   I am a
 lso a member of DefCon Group Prishtina (DC38338)\, where I\n   contribute 
 to co-organizing meetups and community events.\n\n   Links:\n       GitHub
  - [2]https://gitlab.com/0xBabar0ka/Phantasma\n   '\n\n   1. #LVCCW_Level1
 _Hall3\n   2. https://gitlab.com/0xBabar0ka/Phantasma\n\n\n
DTEND:20260808T234500Z
DTSTART:20260808T230000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)
SUMMARY:Weaponizing eBPF and XDP with Covert Triggered Reverse Shells
END:VEVENT
END:VCALENDAR
