Videos / Defcon / Kyle Avery: Evading Memory Scanners — Bypassing YARA and PE-sieve

Kyle Avery: Evading Memory Scanners — Bypassing YARA and PE-sieve

Duration: 43min 33sec Type: Presentation (lecture) Playlist: 130 of 146 in Defcon
A DEF CON 30 talk about techniques for evading memory analysis tools used by antivirus products and researchers to detect malware in Windows.

The presentation explains how popular scanners such as PE-sieve, Moneta, MalMemDetect, Volatility malfind, and YARA rules detect indicators of compromise in memory. It demonstrates how malware implants and shellcode can be modified to evade these detection methods. The talk also introduces a new position-independent reflective DLL loader called AceLdr, designed for stealthy loading and successful evasion of memory scanners.