YoVDO

AtomBombing - Injecting Code Using Windows’ Atoms

Offered By: Security BSides San Francisco via YouTube

Tags

Security BSides Courses Cybersecurity Courses

Course Description

Overview

Explore a cutting-edge code injection technique called AtomBombing in this 27-minute conference talk from Security BSides San Francisco. Discover how this method exploits Windows atom tables and Async Procedure Calls (APC) to bypass common security solutions. Learn about the technique's impact on all Windows versions, including Windows 10 and Windows 7, and understand why it cannot be easily patched due to its reliance on core operating system mechanisms rather than flawed code. Gain insights into the challenges of detecting and preventing this infiltration method, which was undetectable by many security solutions at the time of its release in October 2016.

Syllabus

BSidesSF 2017 - AtomBombing: Injecting Code Using Windows’ Atoms (Tal Liberman)


Taught by

Security BSides San Francisco

Related Courses

Early Detection through Deception
YouTube
Hack for Show, Report for Dough - Brian King
YouTube
Blue Teamin on a Budget of Zero - Kyle Bubp
YouTube
Windows Event Logs - Zero to Hero
YouTube
Weaponizing Splunk - Using Blue Team Tools for Evil
YouTube