DiscoverDEF CON 23 [Audio] Speeches from the Hacker ConventionSean Pierce - Abusing native Shims for Post Exploitation
Sean Pierce - Abusing native Shims for Post Exploitation

Sean Pierce - Abusing native Shims for Post Exploitation

Update: 2015-10-30
Share

Description

Abusing native Shims for Post Exploitation

Sean Pierce Technical Intelligence Analyst for iSIGHT Partners

Shims offer a powerful rootkit-like framework that is natively implemented in most all modern Windows Operating Systems. This talk will focus on the wide array of post-exploitation options that a novice attacker could utilize to subvert the integrity of virtually any Windows application. I will demonstrate how Shim Database Files (sdb files / shims) are simple to create, easy to install, flexible, and stealthy. I will also show that there are other far more advanced applications such as in-memory patching, malware obfuscation, evasion, and system integrity subversion. For defenders, I am releasing 6 open source tools to prevent, detect, and block malicious shims.



Sean Pierce is a Technical Intelligence Analyst for iSIGHT Partners. Sean currently specializes in reverse engineering malware & threat emulation and in the past has worked on incident response, botnet tracking, security research, automation, and quality control. Prior working at iSIGHT Partners, he was an academic researcher and part time lecturer at the University of Texas at Arlington where he earned a Bachelors of Computer Engineering with a minor in Math. Sean also does freelance consulting, penetration testing, forensics, and computer security education. He is an Eagle Scout and enjoys learning how things work.



Twitter: @secure_sean

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Sean Pierce - Abusing native Shims for Post Exploitation

Sean Pierce - Abusing native Shims for Post Exploitation

DEF CON Announcements