YoVDO

Testing Endpoint Protection - How Anyone Can Bypass Next Gen AV

Offered By: YouTube

Tags

Conference Talks Courses Cybersecurity Courses Penetration Testing Courses Malware Analysis Courses Digital Art Courses Endpoint Protection Courses Antivirus Software Courses Atomic Red Team Courses

Course Description

Overview

Explore endpoint protection testing and next-generation antivirus bypass techniques in this 42-minute conference talk from Derbycon 2019. Delve into Kevin Gennuso's methodology, covering topics such as Atomic Red Team, malware, and MS Venom. Learn about vendor claims, configuration changes, false positives, and test environments. Discover insights on containment, automation, and standard user scenarios. Gain understanding of success and failure metrics, NDA considerations, and vendor reactions to testing. Uncover the intricacies of evaluating endpoint security solutions and their effectiveness against modern threats.

Syllabus

Intro
Who am I
How we got here
Methodology
Atomic Red Team
Malware
MS Venom
Not PowerShell NPS
Results
Conclusions
Vendor Claims
Clear Winner
Configuration Changes
False Positives
Did we have anything additional
Can the end point solution catch it
Can we bypass it
Can we cripple it
Test environment
Automation
Standard User
Containment
Success Failure
Does NDA Expire
Vendors Watching
Did the vendors threaten legal action
Did they know I was going to talk about Next Gen AV


Related Courses

Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera
Palo Alto Networks Cybersecurity Essentials II
Palo Alto Networks via Coursera
Introducción al Análisis del Malware en Windows
National Technological University – Buenos Aires Regional Faculty via Miríadax
Android Malware Analysis - From Zero to Hero
Udemy
How to Create and Embed Malware (2-in-1 Course)
Udemy