David Shandalov
David Shandalov is a Staff Security Researcher at Palo Alto Networks, where he focuses on post-exploitation techniques, tracking the evolving malware threat landscape and Identity Security.
Previously, David worked as a Mobile Malware Researcher at Check Point and as a Security Researcher at Deep Instinct, gaining hands-on experience across multiple security doctrines and attack surfaces and presenting his findings at DEF CON. Outside of cybersecurity, he enjoys flying as a licensed private pilot.
Session
Security solutions have long since established absolute control over disk I/O and user-land memory. Every step you take, you generate telemetry. To survive, attackers need to operate where EDRs and other solutions cannot see. However, most attack surfaces include touching the disk or RAM, triggering monitored disk writes or creating suspicious memory allocations.
This talk introduces a novel attack surface that bypasses this barrier by weaponizing the Windows Cloud Filter and its API (CFAPI). Although CFAPI was originally designed for cloud storage providers, we abuse it to bridge the gap from untouchable memory space of the GPU directly to the attacking Cloud Provider.
We will demonstrate how our 0-byte file placeholders can achieve PE while not triggering a single event on a fully patched Windows 11 machine. Compute Shaders will decrypt the payload entirely on the GPU, completely bypassing traditional monitoring.
Attendees will learn how to conduct low-level attack surface research, observing all the steps we went through. The obstacles of our research journey will be noted so the audience will learn from our mistakes. The undocumented structures and flows of the attack surface will be shown and dissected. Attendees will walk away from this talk with enough knowledge and ideas to continue where this research left off.