BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsidesatl-2023//talk//TYJECP
BEGIN:VTIMEZONE
TZID:EST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T070000Z
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T080000Z
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-bsidesatl-2023-TYJECP@pretalx.com
DTSTART;TZID=EST:20231014T093000
DTEND;TZID=EST:20231014T102000
DESCRIPTION:ELF binary infection has been around for roughly 25 years\, but
  is still an underutilized style of persistence. Instead most persistence 
 mechanism particularly on Linux are focused on modifications of plain-text
  configurations where either a malicious user account is added to the syst
 em or execution of malicious binary or script takes place. The problem wit
 h such mechanism is that they are antiquated and are well known. In the ev
 ent suspicions of system compromise takes place\, most system administrato
 rs and IR personnel will check these configurations for malicious modifica
 tions.  ELF binary infection methods offer a more covert form of carrying 
 out malicious activity because the code can reside in legitimate programs 
 and execute in their context. The lack of knowledge and analysis skills su
 rrounding ELF binaries also serves as a barrier for detection. Both curren
 t automated tools and personnel are far behind in the arena of detection a
 nd analysis in comparison to their counterparts on the Windows platform. U
 sing applications such as d0zer\, we will explore utilizing old and novel 
 techniques to infect targets in order to demonstrate infection capability 
 for offensive purposes. For defense/detection I will demonstrate how basic
  and powerful heuristics can be utilized to help bridge the gap that exist
 s between current Linux antivirus technology and ELF binary infection algo
 rithms.
DTSTAMP:20260713T130517Z
LOCATION:Room 402
SUMMARY:ELF Binary Infection Attacks For Persistence and Heuristic Detectio
 n. - Chad Delecia
URL:https://pretalx.com/bsidesatl-2023/talk/TYJECP/
END:VEVENT
END:VCALENDAR
