Overview
Syllabus
Intro
POWER OF THE ACADEMY
INITIAL INFECTION: BEAR TACTIC - MALICIOUS LNK
LNK FILE COMPONENTS
LNK FILE CONSTRUCTION
INITIAL INFECTION: PANDA TACTIC - MACRO DOCUMENT
PRIVILEGE ESCALATION: BEAR TACTIC - UACME #23
HIGH LEVEL EXPLANATION: USMDISM METHOD
PRIVILEGE ESCALATION: PANDA TACTIC - KERNEL O-DAY
CREDENTIAL THEFT: BEAR & PANDA - IT'S A TIE!
PERSISTENCE: BEAR TACTIC - WMI EVENT SUBSCRIPTION
WMI EVENT SUBSCRIPTION BREAKDOWN
PERSISTENCE: PANDA TACTIC - SERVICEDLL
REGISTERING THE SERVICE
COUNTERMEASURES
EXFILTRATION: PANDA TACTIC - DISGUISED RAR
Taught by
RSA Conference