Hunting for Memory-Resident Malware

DerbyCon 7.0 - Legacy

Presented by: Joe Desimone
Date: Saturday September 23, 2017
Time: 13:00 - 13:25
Location: Stable Talks

Once a staple of nation state level adversaries, memory-resident malware techniques have become ubiquitous even for lowly criminal activity. With their ability to evade endpoint protection products, it is critical for defenders to understand and defend against these techniques. In this talk, I will describe both common and advanced stealth malware techniques which evade today’s hunt tools and methodologies. Attendees will learn about adversary stealth and understand ways to detect some of these methods. New code for rapidly hunting for these techniques across your enterprise will be released.

Joe Desimone

Joe Desimone is a Senior Malware Researcher at Endgame. He has over 5 years of experience in the information security industry, primarily tracking and countering APTs, reverse engineering malware, and developing novel techniques and tools to empower hunt teams. Joe holds a BS and MS in Computer Security from RIT. @dez_


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats