YoVDO

Living Off the Walled Garden - Abusing the Features of the Early Launch Antimalware Ecosystem

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Cybersecurity Courses Malware Analysis Courses Vulnerability Assessment Courses

Course Description

Overview

Explore a 36-minute Black Hat conference talk that delves into the methodology for assessing Early Launch Antimalware (ELAM) drivers and demonstrates how overly-permissive rules can be exploited by adversaries. Learn about scenarios where intended functionality can be abused without exploiting vulnerabilities, enabling malware to tamper with security products and gain anti-tampering protections. Discover how a single, overly-permissive ELAM driver can hinder detection and remediation efforts. Conclude with a demonstration of achieving user-mode code execution through an abusable, signed executable running with an antimalware-light protection level. Gain insights from presenter Matt Graeber on the potential risks within the early launch antimalware ecosystem.

Syllabus

Living Off the Walled Garden: Abusing the Features of the Early Launch Antimalware Ecosystem


Taught by

Black Hat

Related Courses

Attack on Titan M, Reloaded - Vulnerability Research on a Modern Security Chip
Black Hat via YouTube
Attacks From a New Front Door in 4G & 5G Mobile Networks
Black Hat via YouTube
AAD Joined Machines - The New Lateral Movement
Black Hat via YouTube
Better Privacy Through Offense - How to Build a Privacy Red Team
Black Hat via YouTube
Whip the Whisperer - Simulating Side Channel Leakage
Black Hat via YouTube