DEF CON 32 - Defeating EDR Evading Malware with Memory Forensics - Case, Sellers, Richard, et al.

Endpoint detection and response (EDR) software has gained significant market share due to its ability to examine system state for signs of malware and attacker activity well beyond what traditional anti-virus software is capable of detecting. This deep inspection capability of EDRs has led to an arms race with malware developers who want to evade EDRs while still achieving desired goals, such as code injection, lateral movement, and credential theft. This monitoring and evasion occurs in the lowest levels of hardware and software, including call stack frames, exception handlers, system calls, and manipulation of native instructions. Given this reality, EDRs are limited in how much lower they can operate to maintain an advantage. The success of EDR bypasses has led to their use in many high-profile attacks and by prolific ransomware groups. In this talk, we discuss our research effort that led to the development of new memory forensics techniques for the detection of the bypasses that malware uses to evade EDRs. This includes bypass techniques, such as direct and indirect system calls, module overwriting, malicious exceptions handlers, and abuse of debug registers. Our developed capabilities were created as new plugins to the Volatility memory analysis framework, version 3, and will be released after the talk.

Develop Your Own RAT: EDR + AV Defense by Dobin Rutishauser
▶︎

Develop Your Own RAT: EDR + AV Defense by Dobin Rutishauser

EDR Evasion Techniques EXPOSED : Using Windows to Break Windows - Payatu Webinar
▶︎

EDR Evasion Techniques EXPOSED : Using Windows to Break Windows - Payatu Webinar

DEF CON 32 - Breaking Secure Web Gateways  for Fun and Profit -Vivek Ramachandran, Jeswin Mathai
▶︎

DEF CON 32 - Breaking Secure Web Gateways for Fun and Profit -Vivek Ramachandran, Jeswin Mathai

DEF CON 32 - Inside the FBI’s Secret Encrypted Phone Company ‘Anom’ - Joseph Cox
▶︎

DEF CON 32 - Inside the FBI’s Secret Encrypted Phone Company ‘Anom’ - Joseph Cox

RL for Agents Workshop - Deep Dive on Training Agents with RL and Open Source
▶︎

RL for Agents Workshop - Deep Dive on Training Agents with RL and Open Source

Tales of AV/EDR Bypass - Double Feature w/ Greg Hatcher & John Stigerwalt
▶︎

Tales of AV/EDR Bypass - Double Feature w/ Greg Hatcher & John Stigerwalt

KubeFleet APAC Community Call - May 2026
▶︎

KubeFleet APAC Community Call - May 2026

Compromising LLMs: The Advent of AI Malware
▶︎

Compromising LLMs: The Advent of AI Malware

DEF CON 32 - Winning the Game of Active Directory - Brandon Colley
▶︎

DEF CON 32 - Winning the Game of Active Directory - Brandon Colley

Casey Muratori – The Big OOPs: Anatomy of a Thirty-five-year Mistake – BSC 2025
▶︎

Casey Muratori – The Big OOPs: Anatomy of a Thirty-five-year Mistake – BSC 2025

Investigating Malware Using Memory Forensics - A Practical Approach
▶︎

Investigating Malware Using Memory Forensics - A Practical Approach

Black Hat USA 2025 | Advanced Active Directory to Entra ID Lateral Movement Techniques
▶︎

Black Hat USA 2025 | Advanced Active Directory to Entra ID Lateral Movement Techniques

CrikeyCon 2019 - Christopher Vella - Reversing & bypassing EDRs
▶︎

CrikeyCon 2019 - Christopher Vella - Reversing & bypassing EDRs

The Biggest Hack in US History: SolarWinds Hack
▶︎

The Biggest Hack in US History: SolarWinds Hack

#HITB2022SIN EDR Evasion Primer For Red Teamers - Jorge Gimenez & Karsten Nohl
▶︎

#HITB2022SIN EDR Evasion Primer For Red Teamers - Jorge Gimenez & Karsten Nohl

DEF CON 33 - Kill List: Hacking an Assassination Site on the Dark Web - Carl Miller, Chris Monteiro
▶︎

DEF CON 33 - Kill List: Hacking an Assassination Site on the Dark Web - Carl Miller, Chris Monteiro

DEF CON 32 - Your AI Assistant has a Big Mouth:  A New Side Channel Attack - Yisroel Mirsky
▶︎

DEF CON 32 - Your AI Assistant has a Big Mouth: A New Side Channel Attack - Yisroel Mirsky

BlueHat Oct 23. S16: All Killer, No Filler: Exploring the Current State of EDR Killers
▶︎

BlueHat Oct 23. S16: All Killer, No Filler: Exploring the Current State of EDR Killers

System Design Course – APIs, Databases, Caching, CDNs, Load Balancing & Production Infra
▶︎

System Design Course – APIs, Databases, Caching, CDNs, Load Balancing & Production Infra

How Hackers Use netsh.exe For Persistence & Code Execution (Sliver C2)
▶︎

How Hackers Use netsh.exe For Persistence & Code Execution (Sliver C2)