BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2023//speaker//LAFQQS
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20221019T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20221030T030000
RDATE:20231029T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20230326T030000
RDATE:20240331T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:The rise of malicious MSIX file - Shogo Hayashi\, Rintaro Koike
DTSTART;TZID=Europe/Luxembourg:20231019T143000
DTEND;TZID=Europe/Luxembourg:20231019T150000
DTSTAMP:20260816T141617Z
UID:pretalx-hack-lu-2023-WULFLD@pretalx.com
DESCRIPTION:Since February 2023\, we have observed an attack campaign usin
 g MSIX files. MSIX file is the successor format to MSI file\, but many peo
 ple are unaware of its existence and\, needless to say\, do not know of an
 y abuse cases.\n\nThis session will first introduce basic information on M
 SIX file\, such as the file format\, basic behavior\, and the creation met
 hod\, followed by attack cases of MSIX file abuse. Specifically\, we will 
 detail attacks conducted by a financially motivated threat group called St
 eelClover. In particular\, we will delve into the Package Support Framewor
 k (PSF). Our session will contribute to your better understanding of the a
 ttack flow and the behavior through specific attack cases abusing MSIX fil
 es.\n\nFinally\, we will discuss detection and defense techniques\, includ
 ing the detection logics available for EDR solutions\, against attacks tha
 t exploit MSIX files. This session will enable SOC analysts\, IR team memb
 ers\, CSIRT personnel\, and others to gain a deep understanding of the spe
 cific attack cases and behavior abusing MSIX files and to take concrete co
 untermeasures.
LOCATION:Salle Europe
URL:https://pretalx.com/hack-lu-2023/talk/WULFLD/
END:VEVENT
END:VCALENDAR
