BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Bring-Your-Own-EDR - Breaking Windows Process Protec
 tion to\n   build EDR-Protected Malware\n   Tags: DEF CON Official Talk | 
 Demo ðŸ’» | Tool ðŸ›  | Exploit ðŸª²\n   When: Friday\, Aug 7\, 13:00 - 13
 :59 PDT\n   Where: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - [1
 ]Map\n\n   Description:\n\n   The core assumption of modern endpoint defen
 se is broken. While\n   Endpoint Detection and Response (EDR) solutions ar
 e built to restrict\n   administrators through Protected Process Light (PP
 L) and\n   anti-tampering\, this research reveals an industry-wide design 
 flaw:\n   the "Bring-Your-Own-EDR" (BYOEDR) technique. We demonstrate a\n 
   post-exploitation scenario where a local administrator weaponizes the\n 
   EDR's own trusted installer to bypass its formidable defenses\,\n   esta
 blishing a self-protected malware. This shows a structural\n   weakness in
  how security products handle installation and trust. We\n   will show a c
 omplete exploit chain that any attacker can leverage to\n   achieve arbitr
 ary unsigned code execution within PPL boundaries.\n\n   Ultimately\, the 
 strongest defender becomes the attackerâ€™s most\n   powerful tool.\n\n   
 https://blog.slowerzs.net/posts/pplsystem/\n   https://github.com/hasherez
 ade/pe_to_shellcode/\n   https://github.com/googleprojectzero/symboliclink
 -testing-tools\n\n   SpeakerBio:  Shahak Morag\, Akamai\n\n   Shahak Morag
  is currently serving as the Senior Security Researcher at\n   Akamai\, wi
 th more than seven years of experience in security research.\n   His backg
 round includes extensive expertise in Linux kernel\, embedded\n   systems\
 , and Windows internals.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260807T205900Z
DTSTART:20260807T200000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3
SUMMARY:Bring-Your-Own-EDR - Breaking Windows Process Protection to build E
 DR-Protected Malware
END:VEVENT
END:VCALENDAR
