DEF CON 31 - Defender Pretender When Windows Defender Updates Become a Security Risk -Bar, Attias

  Рет қаралды 13,678

DEFCONConference

DEFCONConference

8 ай бұрын

The signature update process is critical to EDR's effectiveness against emerging threats. The security update process must be highly secured, as demonstrated by the Flame malware attack that leveraged a rogue certificate for lateral movement. Nation-state capabilities are typically required for such an attack, given that signature update files are digitally signed by Microsoft.
We wondered if we could achieve similar capabilities running as an unprivileged user without possessing a rough certificate, instead we aimed to turn the original Windows Defender process to our full control.
In this talk we will deep dive into Windows Defender architecture, the signature database format and the update process, with a focus on the security verification logic. We will explain how an attacker can completely compromise any Windows agent or server, including those used by enterprises, by exploiting a powerful 0day vulnerability that even we didn't expect to discover.
We will demonstrate Defender-Pretender, a tool we developed to achieve neutralization of the EDR. allowing any already known malicious code to run Fully Un-Detected. It can also force Defender to delete admin’s data. OS and driver files, resulting in an unrecoverable OS. We will also explain how an attacker can alter Defender's detection and mitigation logic.

Пікірлер: 11
@ttrss
@ttrss 8 ай бұрын
the dos is like autoimmune disease but for computers
@SergeTheBlade
@SergeTheBlade 8 ай бұрын
One of the coolest talks I saw. Well done.
@stubstunner
@stubstunner 7 ай бұрын
Goteem
@fabiorj2008
@fabiorj2008 5 ай бұрын
The best talk of Defcon31. No doubt about this.
@sabofx
@sabofx 8 ай бұрын
Super cool!
@Radi0he4d1
@Radi0he4d1 8 ай бұрын
Very interesting and well presented 👍
@elcasho
@elcasho 8 ай бұрын
great research!
@towelie
@towelie 8 ай бұрын
great talk , good level of detail
@KonuralpBalcik
@KonuralpBalcik 8 ай бұрын
When I delete all defender folders while offline, it never works, but it seems to work.
@rohitnair5738
@rohitnair5738 7 ай бұрын
great research🙃
@imark7777777
@imark7777777 7 ай бұрын
It's not a security risk it's a feature!
The "New" File System in Windows: ReFS
11:37
ThioJoe
Рет қаралды 889 М.
I PEELED OFF THE CARDBOARD WATERMELON!#asmr
00:56
HAYATAKU はやたく
Рет қаралды 38 МЛН
FOOTBALL WITH PLAY BUTTONS ▶️ #roadto100m
00:29
Celine Dept
Рет қаралды 72 МЛН
Когда на улице Маябрь 😈 #марьяна #шортс
00:17
Cloud Computing Explained
8:37
PowerCert Animated Videos
Рет қаралды 830 М.
How to make, dimple lock picks at home.
7:43
Rook Knight
Рет қаралды 8 М.
Windows Defender vs Top 100 Malware Sites
10:15
The PC Security Channel
Рет қаралды 585 М.
I finally own the Dyson Zones.
13:55
DankPods
Рет қаралды 446 М.
The Eve Of The War
5:05
Jeff Wayne - Topic
Рет қаралды 402 М.
Skiing drills, fun, learning moments with kids
9:36
Deb Armstrong
Рет қаралды 100 М.
Virtual Machines vs Containers
8:57
PowerCert Animated Videos
Рет қаралды 807 М.
How to know if your PC is hacked? Suspicious Network Activity 101
10:19
The PC Security Channel
Рет қаралды 1,1 МЛН
Why it Was Almost Impossible to Put a Computer in Space
17:20
Linus Tech Tips
Рет қаралды 546 М.
Полный обзор iPad Pro M4 - хвалю!
26:27
Rozetked
Рет қаралды 243 М.
ПК с Авито за 3000р
0:58
ЖЕЛЕЗНЫЙ КОРОЛЬ
Рет қаралды 1,3 МЛН
Что еще за Smartisan?
0:49
Не шарю!
Рет қаралды 306 М.
ПРОБЛЕМА МЕХАНИЧЕСКИХ КЛАВИАТУР!🤬
0:59
Корнеич
Рет қаралды 3,1 МЛН