Kyle Avery: Evading Memory Scanners — Bypassing YARA and PE-sieve
A DEF CON 30 talk about techniques for evading memory analysis tools used by antivirus products and researchers to detect malware in Windows.
The presentation explains how popular scanners such as PE-sieve, Moneta, MalMemDetect, Volatility malfind, and YARA rules detect indicators of compromise in memory. It demonstrates how malware implants and shellcode can be modified to evade these detection methods. The talk also introduces a new position-independent reflective DLL loader called AceLdr, designed for stealthy loading and successful evasion of memory scanners.
The presentation explains how popular scanners such as PE-sieve, Moneta, MalMemDetect, Volatility malfind, and YARA rules detect indicators of compromise in memory. It demonstrates how malware implants and shellcode can be modified to evade these detection methods. The talk also introduces a new position-independent reflective DLL loader called AceLdr, designed for stealthy loading and successful evasion of memory scanners.