YoVDO

Bringing the Power of Symbolic Execution to the Fight Against Malicious Excel 4 Macros

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Cybersecurity Courses Symbolic Execution Courses

Course Description

Overview

Explore a 35-minute Black Hat conference presentation on Symbexcel, a new tool implementing Symbolic Execution for Excel 4.0 macros. Dive into the world of cybersecurity as experts Giovanni Vigna, Nicola Ruaro, Fabio Pagani, and Stefano Ortolani discuss how this innovative approach combats malicious macros. Learn about the challenges in detecting these attack vectors, the limitations of current security measures, and how Symbexcel's plugins support the analysis of highly obfuscated and evasive samples. Gain insights into Excel 4 macro functionality, evasion techniques, and the principles of Symbolic Execution. Discover the tool's architecture, including its loader, simulation manager, and step function. Understand the importance of deobfuscating malicious samples and evaluate the effectiveness of this cutting-edge cybersecurity solution.

Syllabus

Introduction
Excel 4 Macros
How they work
Mouse and Audio
Evasion
Char Function
Register Function
Symbolic Execution Example
Introduction to Symbolic Execution
Concrete Analysis
Concrete Analysis Problem
Architecture
Loader
Simulation Manager
Environment and constraints
Step function
Examples
Malicious Excel sample analysis
Why deobfuscate a sample
Evaluation
Conclusion


Taught by

Black Hat

Related Courses

Attack on Titan M, Reloaded - Vulnerability Research on a Modern Security Chip
Black Hat via YouTube
Attacks From a New Front Door in 4G & 5G Mobile Networks
Black Hat via YouTube
AAD Joined Machines - The New Lateral Movement
Black Hat via YouTube
Better Privacy Through Offense - How to Build a Privacy Red Team
Black Hat via YouTube
Whip the Whisperer - Simulating Side Channel Leakage
Black Hat via YouTube