BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//sched.securitybsides.org.uk//bsides-london-2023//speaker
 //7K8KD7
BEGIN:VTIMEZONE
TZID:GMT
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:GMT
TZOFFSETFROM:+0100
TZOFFSETTO:+0000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T020000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:BST
TZOFFSETFROM:+0000
TZOFFSETTO:+0100
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-bsides-london-2023-LCGABU@sched.securitybsides.org.uk
DTSTART;TZID=GMT:20231209T135500
DTEND;TZID=GMT:20231209T144000
DESCRIPTION:Bring Your Own Vulnerable Driver (BYOVD) has become an extremel
 y popular attack technique seen in the wild. Even ransomware groups are us
 ing it to blind Endpoint Detection & Response (EDR)\, dump protected crede
 ntials from memory\, erase their own traces\, and all sorts of other juicy
  things you can do in the Windows kernel. But why bring your own vulnerabl
 e driver when you can use those already installed?\n\nIn this talk we’ll
  share our journey of exploiting a critical zero-day vulnerability that we
  found VPN software\, used by more than 40.000 organisations world-wide. A
 fter a recap on kernel drivers\, we’ll reveal how anyone in the audience
  can find vulnerabilities like these on live systems. Furthermore\, we’l
 l share our abuse path to exploit the vulnerability. We'll reveal several 
 techniques you can use to overcome typical restrictions when exploiting ke
 rnel drivers. We’ll show you how we applied these techniques to build an
  exploit that we use in red teaming engagements. Lastly\, we demo the expl
 oitation of the vulnerability on a target system\, resulting in SYSTEM pri
 vileges.\n\nThe talk is accompanied by the first-hand public release of th
 e exploit\, in the form of a Cobalt Strike (CS) Beacon Object File (BOF). 
 Additionally\, we’ll publish a blog post that includes all technical det
 ails.
DTSTAMP:20260714T123657Z
LOCATION:Track 2
SUMMARY:Elevate & Conquer: A Journey Into Kernel Exploitation - Tijme Gomme
 rs
URL:https://sched.securitybsides.org.uk/bsides-london-2023/talk/LCGABU/
END:VEVENT
END:VCALENDAR
