YoVDO

Press Play To Restart - Under the Hood of the Windows Restart Manager

Offered By: Recon Conference via YouTube

Tags

REcon Conference Courses Cybersecurity Courses Malware Analysis Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Dive into the inner workings of the Windows Restart Manager in this 36-minute conference talk from Recon 2023. Explore how this often-overlooked Windows component, introduced in Vista to reduce reboots during software updates, can be exploited for malicious purposes. Learn about the Restart Manager's architecture and mechanisms, observe its legitimate use in installers, and examine real-world examples of its misuse. Participate in a live demo showcasing the Restart Manager's functionalities and discover a unique application. Conclude with insights into defensive methods against potential threats. Presented by Mathilde Venault, a CrowdStrike security researcher specializing in Windows operating systems, this talk offers valuable knowledge for those interested in malware analysis, EDR detection, and undocumented Windows mechanisms.

Syllabus

Recon 2023 - Mathilde Venault - Press Play To Restart: Under the Hood of the Windows Restart Manager


Taught by

Recon Conference

Related Courses

Harnessing Intel Processor Trace on Windows for Fuzz
Recon Conference via YouTube
Reverse Engineering Satellite Based IP Content Distribution
Recon Conference via YouTube
Reverse Engineering Windows Defender's JavaScript Engine
Recon Conference via YouTube
DIY ARM Debugger for Wi-Fi Chips
Recon Conference via YouTube
Subverting Your Server Through Its BMC - The HPE iLO4 Case
Recon Conference via YouTube