YoVDO

Kernel Mode Threats and Practical Defenses

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Cybersecurity Courses Secure Boot Courses

Course Description

Overview

Explore kernel mode threats and practical defense strategies in this Black Hat conference talk. Delve into the evolution of OS security measures by Microsoft, including PatchGuard, Driver Signature Enforcement, and SecureBoot, and their impact on commodity kernel mode malware. Examine how advanced attackers bypass these protections and continue to leverage kernel mode malware. Learn about first-generation kernel threats, boot kits, and Secure Boot. Investigate Dooku Threats, Double Pulsar, and Hypervisor Code Integrity. Analyze implant design, including the Turla Driver Loader, and explore data-driven attacks, code reuse attacks, and kernel stack hooking. Discover techniques for hunting in the kernel, detecting threats like Double Pulsar, and implementing real-time detection. Evaluate the weaknesses and limitations of Windows platform security, and gain insights into improving your defensive tradecraft against kernel mode threats.

Syllabus

Introduction
Why this talk
First generation kernel threats
Microsofts defenses
Boot Kits
Secure Boot
Dooku Threats
Double Pulsar
Hypervisor Code Integrity
Red vs Blue
Implant Design
Turla Driver Loader
Improving our tradecraft
Datadriven attacks
Code reuse attacks
Kernel stack hooking
Calling a function
Readwrite primitive
Demo
Blacklist of known exploitable drivers
How to hunt in the kernel
Page table remapping
Detecting double pulsar
Realtime detection
Weaknesses
Windows
Microsoft
Weaknesses Limitations
Recap
Windows Platform Security


Taught by

Black Hat

Related Courses

Security Principles
(ISC)² via Coursera
A Strategic Approach to Cybersecurity
University of Maryland, College Park via Coursera
FinTech for Finance and Business Leaders
ACCA via edX
Access Control Concepts
(ISC)² via Coursera
Access Controls
(ISC)² via Coursera