YoVDO

Reflective PE Unloading

Offered By: YouTube

Tags

Conference Talks Courses Software Development Courses Cybersecurity Courses Reverse Engineering Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore reflective PE unloading techniques in this 48-minute conference talk from BSides Cleveland 2018. Delve into the intricacies of reflective DLL injection, understand the importance of reflective unloaders, and learn how they function. Examine image inspection, writable section management, and the reflective transformer process. Gain insights into adapting techniques, handling header fields, entry point resolution, and practical usage notes. Compare methodologies using IDA Pro diffing and PE Bear, and conclude with a closer examination of release notes and implementation details.

Syllabus

Intro
Overview
Reflective DLL Injection
Scenario Time
The Reflective Unloader
Why We Care
How It Works
Inspecting The Image
Dealing with Writable Sections
Reflective Unloader Release Notes the thing that does the things
Reflective Transformer
Adaptation Is Key
Header Fields
The Entry Point
Multiple Entry Points
Entry Point Resolution
Putting It Together
Notes On Usage
IDA Pro Diffing
PE Bear Comparison
Closer Examination
More Release Notes
Thank you for your time!


Related Courses

Software as a Service
University of California, Berkeley via Coursera
Software Testing
University of Utah via Udacity
The Hardware/Software Interface
University of Washington via Coursera
Software Debugging
Saarland University via Udacity
Introduction to Systematic Program Design - Part 1
The University of British Columbia via Coursera