BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: MSIX'd Up: Weaponizing the Modern Windows App Packag
 ing\n   Ecosystem\n   Tags: DEF CON Official Talk | Demo ðŸ’» | Tool ðŸ›  
 | Exploit ðŸª²\n   When: Sunday\, Aug 9\, 12:00 - 12:59 PDT\n   Where: LVC
 CW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - [1]Map\n\n   Descriptio
 n:\n\n   What happens when the ecosystem Microsoft built for isolation and
 \n   integrity of modern Windows applications becomes a foundation for\n  
  novel attacker tradecraft?\n\n   For over 13 years\, an ecosystem that no
 w includes MSIX\, UWP\,\n   AppContainers\, package identity\, and the Win
 dows Runtime has shipped\n   by default on modern Windows. Yet offensive r
 esearch into this\n   ecosystem remains scarce\, and visibility into its a
 buse lags further\n   behind. In this talk\, we demonstrate novel techniqu
 es spanning all\n   major parts of an attack path.\n\n   For initial acces
 s\, we abuse URL protocol handlers and packaging file\n   formats to subve
 rt endpoint detections. For post-exploitation\, we\n   overcome AppContain
 er process isolation to operate beneath EDR\n   visibility thresholds. For
  lateral movement\, we expose previously\n   unabused WMI providers and DC
 OM objects within package installation\n   services. For privilege escalat
 ion\, we chain a logic flaw in package\n   capabilities to achieve SYSTEM 
 from a standard user context. Every\n   technique requires no third-party 
 software\, works on fully patched\n   systems\, and abuses default-enabled
  features. Tools for red teams will\n   be released alongside detection gu
 idance for defenders.\n\n   The modern app packaging ecosystem was designe
 d for isolation and\n   integrity. We used its design to our advantage and
  turned it into an\n   attack platform.\n\n   https://projectzero.google/2
 021/08/understanding-network-access-windows-app.html\n\n   https://www.pen
 testpartners.com/security-blog/ms-enterprise-app-management-service-rce-cv
 e-2022-35841/\n\n   https://conference.hitb.org/hitbsecconf2018pek/materia
 ls/D1T2%20-%20The%20Inner%20Workings%20of%20the%20Windows%20Runtime%20-%20
 James%20Forshaw.pdf\n   https://activecyber.us/activelabs/windows-appx-dep
 loyment-service-local-privilege-escalation-cve-2020-1488\n\n   SpeakerBio:
   Nick "zyn3rgy" Powers\, SpecterOps\n\n   An offensive security professio
 nal with experience in leading and\n   offering red team assessments and p
 enetration testing across several\n   attack surfaces to a diverse set of 
 industries. Professional interests\n   include furthering knowledge of Win
 dows internals\, static and dynamic\n   Endpoint Detection & Response (EDR
 ) evasion\, as well as initial access\n   attack surface research. Passion
 ate about contributing back to the\n   security community by speaking at c
 onferences such as Defcon\, Wild\n   West Hackinâ€™ Fest\, and Troopers al
 ong with instructing course\n   content at conferences such as BlackHat US
 A.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260809T195900Z
DTSTART:20260809T190000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-
 2
SUMMARY:MSIX'd Up: Weaponizing the Modern Windows App Packaging Ecosystem
END:VEVENT
END:VCALENDAR
