Revisiting Ring3 API Hooks: Tricks to Defeat Analysis Tools - Rafael Salema Marquez - Ekoparty - 2021

Revisiting Ring3 API Hooks: Tricks to Defeat Analysis Tools - Rafael Salema Marquez - Ekoparty - 2021

Ekoparty Security Conference via YouTube Direct link

Introduction

1 of 26

1 of 26

Introduction

Class Central Classrooms beta

YouTube playlists curated by Class Central.

Classroom Contents

Revisiting Ring3 API Hooks: Tricks to Defeat Analysis Tools - Rafael Salema Marquez - Ekoparty - 2021

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Introduction
  2. 2 Agenda
  3. 3 Rafaels background
  4. 4 What is important
  5. 5 Dark side
  6. 6 Credentials
  7. 7 Expose new techniques
  8. 8 Basic knowledge
  9. 9 What is API hooks
  10. 10 Avoid distractions
  11. 11 Inline hooks
  12. 12 IAT hooks
  13. 13 Regular flow
  14. 14 How it works
  15. 15 Detection strategies
  16. 16 Egg hook
  17. 17 Egg hook explanation
  18. 18 Create process suspended
  19. 19 allocate memory
  20. 20 the fun part
  21. 21 proof of concept
  22. 22 virtual machine
  23. 23 fast look
  24. 24 results
  25. 25 actual results
  26. 26 outro

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.