In NTDLL I Trust - Process Reimaging and Endpoint Security Solution Bypass - E. Carroll - Hack in Paris - 2019
Hack in Paris via YouTube
Overview
Syllabus
Introduction
Relevance
attribution
about me
Agenda
What is Process Reimaging
AV Scanners
Process Reimaging
Mitre Attack Framework
Game of Thrones
Process Doppelganger
AP
Process Re Imaging
Weaponized Process Re Imaging
Summary
Image File Pointer Field
Summary Table
Attack vectors
Get process image
Run process
Rename process
Demo
Recap
Pros and Cons
Impact
Endpoint Security Solution
Protection Recommendations
Microsoft Update
Conclusion
Taught by
Hack in Paris