Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Improving the Stealthiness of Memory Injection Techniques Using Python Ctypes

x33fcon via YouTube

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Learn advanced memory injection techniques and their stealthy implementations in a conference talk that explores innovative approaches using Python ctypes for in-memory loading of DLLs, EXEs, and BOFs. Discover the advantages of ctypes implementation while diving into Module-Shifting, a novel enhancement to Module-Overloading injection. Explore memory injection fundamentals, purposes, and main categories including code injection, PE injection, and process manipulation techniques. Examine common memory injection components, payload constraints, and testing methodologies with memory scanners. Master the PythonMemoryModule implementation, understanding its benefits and limitations, before advancing to Module Overloading and Module Stomping concepts. Gain insights into Module Shifting's key features, including byte restoration and detection opportunities, while developing a comprehensive understanding of modern memory injection methodologies and their security implications.

Syllabus

Intro
Agenda
Memory Injection Definition
Memory Injection - Purposes
Memory Injection - Main categories
Code injection - Common techniques
PE injection - Common techniques
Process Manipulation - Common technique
Memory Injection - Moving Parts
Setting the constraints - Injection
Setting the constraints - Payload
Testing with Memory scanners
Starting Point - Python Memory Module
PythonMemoryModule - Pros and cons
Next step - Module Overloading
Module Overloading - loCs
Next step - Module Stomping
Module Stomping locs
Module Shifting - Key Points
Module Shifting - Restore modified bytes
Detection Opportunities
Main Takeaways

Taught by

x33fcon

Reviews

Start your review of Improving the Stealthiness of Memory Injection Techniques Using Python Ctypes

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.