Reflective PE Unloading
Offered By: YouTube
Course Description
Overview
Explore reflective PE unloading techniques in this 48-minute conference talk from BSides Cleveland 2018. Delve into the intricacies of reflective DLL injection, understand the importance of reflective unloaders, and learn how they function. Examine image inspection, writable section management, and the reflective transformer process. Gain insights into adapting techniques, handling header fields, entry point resolution, and practical usage notes. Compare methodologies using IDA Pro diffing and PE Bear, and conclude with a closer examination of release notes and implementation details.
Syllabus
Intro
Overview
Reflective DLL Injection
Scenario Time
The Reflective Unloader
Why We Care
How It Works
Inspecting The Image
Dealing with Writable Sections
Reflective Unloader Release Notes the thing that does the things
Reflective Transformer
Adaptation Is Key
Header Fields
The Entry Point
Multiple Entry Points
Entry Point Resolution
Putting It Together
Notes On Usage
IDA Pro Diffing
PE Bear Comparison
Closer Examination
More Release Notes
Thank you for your time!
Related Courses
Computer SecurityStanford University via Coursera Cryptography II
Stanford University via Coursera Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera Building an Information Risk Management Toolkit
University of Washington via Coursera Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network