Windows Offender: Reverse Engineering Windows Defender's Antivirus Emulator
Black Hat
0:00 / 0:00
Windows Offender: Reverse Engineering Windows Defender's Antivirus Emulator
10 679 просмотров · 6 лет назад
Black Hat
277 тыс. подписчиков
10 679 просмотров · 6 лет назад
In this presentation, we'll look at Defender's emulator for analysis of potentially malicious Windows PE binaries on the endpoint. To the best of my knowledge, there has never been a conference talk or publication on reverse engineering the internals of any antivirus binary emulator before.
By Alexei Bulazel
Full abstract and materials: https://www.blackhat.com/us-18/briefi...