BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Sold Out - Step-by-Step Malware Development: Evading
  EDR from\n   Loaders to the Kernel\n   Tags: DEF CON Workshop | DEF CON W
 orkshops\n   When: Saturday\, Aug 8\, 09:00 - 12:59 PDT\n   Where: LVCCW L
 evel 2 W228 (Workshops) - [1]Map\n\n   Description:\n\n   Endpoint Detecti
 on and Response (EDR) systems are key parts of modern\n   security. This w
 orkshop provides a guide for custom malware\n   development\, C2 customiza
 tion\, defense evasion\, and kernel\n   exploitation. We will use Elastic 
 Defend throughout the session. By\n   analyzing detection logs and rules\,
  we will understand what EDR\n   monitors and why payloads are caught step
  by step.\n\n   After a short overview of Windows defenses and EDR\, we fo
 cus on\n   malware development. Participants will implement typical malwar
 e\n   techniques\, such as APC Injection\, Thread Hijacking\, Fiber and Mo
 dule\n   Stomping in multiple languages. Next\, we learn about call stack\
 n   analysis. Attendees will implement Stack Spoofing and Indirect\n   Sys
 calls to hide execution flows and bypass stack analysis.\n\n   The worksho
 p then moves to C2 customization using the Havoc C&C\n   framework. By com
 bining custom loaders with C2 source code\n   modifications\, participants
  will bypass static signatures\, behavioral\n   rules\, and AI detection t
 o successfully establish a C2 session.\n\n   Finally\, we‚Äôll demonst
 rate the possibilities of Bring Your Own\n   Vulnerable Driver (BYOVD) att
 acks for the post-exploitation phase.\n   When we have access to the kerne
 l space\, we can take more aggressive\n   measures. We‚Äôll use some v
 ulnerable drivers to kill or blind an\n   EDR sensor itself.\n\n   Speaker
 s:Yu Terada\,Kotaro "@Decamark / @BinaryPoodle" Osugi\n\n   SpeakerBio:  Y
 u Terada\n\n   Yu Terada is a security researcher and a red team consultan
 t for\n   Fujitsu. He worked as a SOC Analyst and CSIRT for over five year
 s. In\n   2021\, he joined the company as a Security Researcher. He is pri
 marily\n   involved in developing new attack methods and tools. He also\n 
   participates in internal red team activities and cyber exercises. He\n  
  has spoken at Black Hat USA/Europe\, BSides Las Vegas\, Code Blue\, and\n
    several conferences in Japan. He holds a Master's degree in Computer\n 
   Science\, as well as certifications including OSEP\, OSCP\, CRTL\, CETP\
 ,\n   ODPC\, CISSP\, GIAC\, etc.\n\n   SpeakerBio:  Kotaro "@Decamark / @B
 inaryPoodle" Osugi\n\n   Kotaro Osugi is a security researcher and a red t
 eam consultant who\n   has his profession in reverse-engineering. His rese
 arch area includes\n   malware analysis and binary exploitation. He has gi
 ven a speech at\n   BHEU Arsenal about a tool for kernel exploitation. OSE
 D and OSEE\n   certified.\n\n   Links:\n       Registration (July 14\, 202
 6\, Noon US Pacific) - [2]https://events.humanitix.com/sat_am_ws3_4049\n  
  '\n\n   1. #LVCCW_Level2_North\n   2. https://events.humanitix.com/sat_am
 _ws3_4049\n\n\n
DTEND:20260808T195900Z
DTSTART:20260808T160000Z
LOCATION:DEF CON Workshops - LVCCW Level 2 W228 (Workshops)
SUMMARY:Sold Out - Step-by-Step Malware Development: Evading EDR from Loade
 rs to the Kernel
END:VEVENT
END:VCALENDAR
