YoVDO

Counterfeiting the Pipes with FakeNet 2.0

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Malware Analysis Courses Dynamic Analysis Courses Windows Internals Courses

Course Description

Overview

Explore advanced techniques for dynamic malware analysis in this Black Hat conference talk. Learn to use FakeNet 2.0, a free Windows network simulation tool, to trick malware into believing it's connected to the Internet. Master mimicking common protocols like HTTP, SSL, and DNS, and discover how to quickly reconfigure FakeNet for successful malware deception. Gain insights into Windows Internals, process tracking for identifying malicious network activity, and automatic PCAP logging. Participate in hands-on challenges analyzing real-world malware samples to extract network-based signatures, progressing from basic to advanced levels. Understand how to extend FakeNet's capabilities by writing Python extensions for custom malware protocols. Bring your Windows malware analysis Virtual Machine or use a provided one to fully engage in this practical, skill-building session.

Syllabus

Introduction
Practical Matter Analysis
Outline
Background Malware
Protocols
Infrastructure
Beaconing
Why Fake the Network
Existing Tools
Fake DNS
Fake DNS GUI
Netcat
Inetsim
FakeNet
Goals
Usage
Downloading Files
Downloading Programs
Layered Service Providers
How Does It Work
Listeners
WSP dll
Packet Capture
Output Options
Python
Fame
New Features
Process Logging
Bug Breakpoint
Demo EXE
Stop DNS Service
Post Response
IP Address
Additional Changes
Whats Next
Lunch


Taught by

Black Hat

Related Courses

The RedTeam Blueprint - A Unique Guide To Ethical Hacking
Udemy
Indicators of Compromise - From Malware Analysis to Eradication
44CON Information Security Conference via YouTube
Counterfeiting the Pipes with FakeNet 2.0 - Part 2
Black Hat via YouTube
Advanced Process Injection Techniques
NorthSec via YouTube
Hypervisors in Your Toolbox - Monitoring and Controlling System Events with HyperPlatform
nullcon via YouTube