Didier Stevens

Didier Stevens (SANS ISC Senior Handler) is a Senior Analyst working at NVISO. Didier has developed and published more than 100 open-source tools mostly for malware analysis, several of them popular in the security community. You can find his open source security tools on his IT security related blog https://blog.DidierStevens.com


Sessions

10-21
13:45
5min
BoD: Bytes Over DNS
Didier Stevens

Some DNS servers, like 1.1.1.1, will accept and forward any byte values inside the DNS packet.
This makes it possible to use DNS as a C2 channel with a higher throughput than hexadecimal encoding.

hack.lu lightning talk
Europe
10-22
19:10
10min
Utilman & CMD
Didier Stevens

Long time ago, in 2004 (that's even before the first Hack.lu conference), Microsoft released a patch for utilman.exe.
Since then, utilman.exe pops up in security incidents.

Call for Failure (CfF 0x1)
Europe
10-23
14:05
5min
Decrypting IIS Backdoor Traffic
Didier Stevens

A method will be presented to decrypt the HTTP(S) C2 channel of an IIS backdoor developed by an APT group reportedly linked to the People’s Republic of China.

hack.lu lightning talk
Europe
10-24
10:15
90min
Practical Maldoc Analysis Workshop
Didier Stevens

Maybe you already attended a maldoc analysis workshop from Didier at the Hack.lu conference. Didier has delivered workshops on PDF, Office and RTF document analysis. These workshops were bottom-up: we first learn about the fundamentals, and gradually we make our way through ever more complex exercises.

This workshop is the other way around: we go top-down (and we cover PDF, Office and RTF in the same workshop). We don’t start with the fundamentals (they will come later during the exercises when necessary), but we start directly with exercise files that we first have to identify, and then decide how to proceed with the analysis.

We immediately start with real maldoc samples, and you learn how to triage the file and start the analysis. You will learn what tools to use depending on the type of maldoc, and what analysis strategy to follow. You will also be guided with custom decision trees designed for this workshop, that you can use later on in your professional practice.

And we will also cover some automation to perform batch analysis.

topic: hack.lu
Schengen 1 & 2