YoVDO

MoRE Shadow Walker - The Progression of TLB-Splitting on x86

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Cybersecurity Courses x86 Architecture Courses

Course Description

Overview

Explore the evolution of translation lookaside buffer (TLB) splitting for code hiding on x86 architecture in this 44-minute Black Hat conference talk. Gain insights into how Intel's Core i-series processors changed TLB architecture, rendering previous techniques obsolete. Learn about new research methods for TLB-splitting on modern hardware and their applications in both defensive and offensive cybersecurity. Discover how the EPT Shadow Walker rootkit leverages TLB-splitting to present different memory versions to defensive tools and the CPU, effectively concealing malicious code from anti-virus systems. Witness a demonstration of memory manipulation and hiding techniques, and examine the research results presented by Jacob Torrey.

Syllabus

MoRE Shadow Walker: The Progression of TLB-Splitting on x86


Taught by

Black Hat

Related Courses

Information Security- II
Indian Institute of Technology Madras via Swayam
Assembly Language Adventures (1): Counting with two digits
Udemy
Assembly
Cybrary
Advanced Malware Analysis: Redux
Cybrary
Reverse Engineering for Beginners
begin.re via Independent