Session
Autonomous Malware Logic: Practical Design and Analysis of Stealth Execution Techniques
Modern malware relies on autonomous execution to evade dynamic analysis. Building on a BSides Prague session, this workshop demonstrates how threat actors gate execution flow using environmental signals.
WHAT IT COVERS:
Focusing on Windows, we analyze how implants use Win32 APIs (network state, DNS, uptime) and state machines to build conditional execution paths. Practical insights align closely with OSED, OSEP, and OSCP methodologies.
CORE OUTCOMES:
1. Trace Logic: Reverse-engineer Win32 API sequences to uncover malware profiling.
2. Identify Blind Spots: Discover why standard sandboxes observe zero behavior.
3. Enhance Strategies: Improve automated detection and advanced threat testing.
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top