BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Living Off WebView2: Turning Microsoft’s Browser i
 nto a Red\n   Team Asset\n   Tags: Red Team Village | Misc\n   When: Sunda
 y\, Aug 9\, 11:00 - 11:59 PDT\n   Where: LVCCW Level 1 Hall 1 309 (Red Tea
 m Village) Workshop Stage 1 -\n   [1]Map\n\n   Description:\n\n   Modern W
 indows applications are quietly shipping with a built-in\n   Chromium-base
 d browser\, WebView2\, running inside trusted\, signed\n   processes such 
 as Microsoft Teams\, Outlook\, and other enterprise\n   software.\n\n   Th
 is talk shows how that design choice creates a powerful and largely\n   un
 monitored attack surface.\n\n   I demonstrate how this model can be abused
  in offensive operations\,\n   turning WebView2 into a vector for persiste
 nce\, code execution\, and\n   enterprise account impersonation.\n\n   I s
 how how feature flags and environment variables can be leveraged to\n   ma
 nipulate the WebView2 runtime\, enabling techniques such as DLL\n   sidelo
 ading within legitimate applications. This allows arbitrary code\n   execu
 tion inside trusted processes\, supporting stealthy\n   living-off-the-lan
 d persistence.\n\n   Building on this\, I present methods to intercept and
  proxy HTTP/HTTPS\n   traffic generated by WebView2-based applications. Th
 is enables the\n   extraction of session tokens\, cookies\, and other sens
 itive artifacts\,\n   leading to realistic account takeover and impersonat
 ion scenarios\,\n   including access to platforms such as Office 365.\n\n 
   In addition to the offensive techniques\, I provide a detailed analysis\
 n   of the Indicators of Compromise (IOCs) generated throughout these\n   
 attack chains. I highlight detection opportunities\, discuss current\n   v
 isibility gaps in EDR solutions\, and propose practical approaches for\n  
  identifying and responding to this type of activity in real-world\n   env
 ironments.\n\n   SpeakerBio:  Murilo Caixeta\n\n   Murilo Caixeta has been
  working in Offensive Security since 2023\,\n   focusing on web vulnerabil
 ity exploitation and Capture The Flag (CTF)\n   challenge development. In 
 2024\, he joined the market as a pentester\n   and\, in early 2025\, trans
 itioned into Red Team operations\, with an\n   emphasis on malware develop
 ment and phishing techniques.\n\n   '\n\n   1. #LVCCW_Level1_Hall1\n\n\n
DTEND:20260809T185900Z
DTSTART:20260809T180000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Wor
 kshop Stage 1
SUMMARY:Living Off WebView2: Turning Microsoft’s Browser into a Red Team 
 Asset
END:VEVENT
END:VCALENDAR
