Reflective PE Unloading
Offered By: YouTube
Course Description
Overview
Explore reflective PE unloading techniques in this 48-minute conference talk from BSides Cleveland 2018. Delve into the intricacies of reflective DLL injection, understand the importance of reflective unloaders, and learn how they function. Examine image inspection, writable section management, and the reflective transformer process. Gain insights into adapting techniques, handling header fields, entry point resolution, and practical usage notes. Compare methodologies using IDA Pro diffing and PE Bear, and conclude with a closer examination of release notes and implementation details.
Syllabus
Intro
Overview
Reflective DLL Injection
Scenario Time
The Reflective Unloader
Why We Care
How It Works
Inspecting The Image
Dealing with Writable Sections
Reflective Unloader Release Notes the thing that does the things
Reflective Transformer
Adaptation Is Key
Header Fields
The Entry Point
Multiple Entry Points
Entry Point Resolution
Putting It Together
Notes On Usage
IDA Pro Diffing
PE Bear Comparison
Closer Examination
More Release Notes
Thank you for your time!
Related Courses
Software as a ServiceUniversity of California, Berkeley via Coursera Software Testing
University of Utah via Udacity The Hardware/Software Interface
University of Washington via Coursera Software Debugging
Saarland University via Udacity Introduction to Systematic Program Design - Part 1
The University of British Columbia via Coursera