Session
Behind CVE-2020-26053: Policy Delay's Role in RCE and Ransomware
This session delves into CVE-2020-26053, employing efficient detection tests within an endpoint solution. The presentation combines defensive security analysis with an offensive mindset, exploring various techniques. Initial objectives include simulating targeted attacks, utilizing invasive methods like Dll Injection with Metasploit's msfvenom. PowerView, a PowerShell tool, enhances network situational awareness in Windows domains. The presentation covers Shell Injection, DLL injection using Remote DLL Injector, downloading Ransomware via PowerShell, and stress testing with daily malware. This exploration provides practical insights how you can use offensive techniques to bypass security sensores, offering a holistic understanding of endpoint security challenges and countermeasures.
Filipi Pires
Head of Technical Advocacy
Dallas, Texas, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top