BlueHat v18 || Return of the kernel rootkit malware (on windows 10)
Matt Oh, Microsoft We are seeing new technique used everyday by malware. But, it is very hard to find any impressive techniques used in the wild. Recently there was huge buzz about Detrahere malware which used internally known issues with certificate signing in Windows 10 kernel driver. Even though the certificate check bypass technique itself is very interesting, also I found that the tactics used by the malware is more impressive. Even though the malware is mainly focused on Ad-hijacking functionality through Netfilter driver installation, but it also has rootkit ability through file system driver hooking. This feels like old days coming back with various new arsenals. The rootkit detects kernel debugging settings and will destroy the system when it finds one. The unpacking process can be very challenging job, too as it uses kernel driver image hollowing technique (something similar to process hollowing) to deobfuscate itself and run unpacked code. Our patchguard doesn't seem like triggering on this action, because all the sections are pre-allocated with execute permission already. Through this talk, I want to present various techniques used by this malware focusing on the kernel level obfuscation and anti-analysis tactics. This will give us new insights on how new Windows rootkit malware might look like in the future and how detecting them from security systems and detonation systems can be a challenge. https://www.slideshare.net/MSbluehat/...

ATT&CK® Deep Dive: How to Detect Rootkits

Malware Buried Deep Down the SPI Flash: Sednit's First UEFI Rootkit Found in the Wild

Kernel Mode Threats and Practical Defenses

Something is jamming GPS over Europe. Here's what we found

Breaking the x86 Instruction Set

Abusing Windows Management Instrumentation (WMI)

Demystifying Modern Windows Rootkits

Practical Malware Analysis Essentials for Incident Responders

How Hackers Exploit Vulnerable Drivers

Windows Internals

ROP is DEAD! Kernel Driver Binary Exploitation

Windows Internals Crash Course

The UEFI Firmware Rootkits: Myths and Reality

DEF CON 33 - Kill List: Hacking an Assassination Site on the Dark Web - Carl Miller, Chris Monteiro

CNIT 126 10: Kernel Debugging with WinDbg

How to Disappear Online and Become Untraceable

Linux And Windows Kernel Comparison

Windows 10 Kernel Mitigations and Exploitation w/ Jaime Geiger & Stephen Sims - SANS HackFest Summit

BlueHat Seattle 2019 || Guarding Against Physical Attacks: The Xbox One Story

