Overview
Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore reflective PE unloading techniques in this 48-minute conference talk from BSides Cleveland 2018. Delve into the intricacies of reflective DLL injection, understand the importance of reflective unloaders, and learn how they function. Examine image inspection, writable section management, and the reflective transformer process. Gain insights into adapting techniques, handling header fields, entry point resolution, and practical usage notes. Compare methodologies using IDA Pro diffing and PE Bear, and conclude with a closer examination of release notes and implementation details.
Syllabus
Intro
Overview
Reflective DLL Injection
Scenario Time
The Reflective Unloader
Why We Care
How It Works
Inspecting The Image
Dealing with Writable Sections
Reflective Unloader Release Notes the thing that does the things
Reflective Transformer
Adaptation Is Key
Header Fields
The Entry Point
Multiple Entry Points
Entry Point Resolution
Putting It Together
Notes On Usage
IDA Pro Diffing
PE Bear Comparison
Closer Examination
More Release Notes
Thank you for your time!