email info@BC-Security.org

Top Categories

Spotlight

todayOctober 10, 2024

Offensive Security Tools Cx01N

Not Your Grandfather’s Empire

Not Your Grandfather’s Empire I’ve wanted to put this blog together since returning home from DEFCON. Anytime we ran into someone who recognized our swag, they mentioned how much they loved Empire back in the day and didn’t realize it was being actively maintained. This made me reflect on all [...]


Coming Soon

Windows Payload Development: EDR Evasion and Initial Access Tradecraft

May 16, 2025my_locationHackMiami

Background
share close
Details
Date May 16, 2025 H 09:00
End May 16, 2025 H 18:00
Location HackMiami
Address 18683 Collins Avenue Sunny Isles Beach, FL 33160
Add to Google Calendar

Click here to add this event to your google calendar

About the event

Description:

Windows Payload Development: EDR Evasion and Initial Access Tradecraft is a course designed to provide knowledge and skills to create advanced payloads while navigating and overcoming modern defensive controls. This hands-on class focuses on payload development, analysis, and the initial access tradecraft needed to effectively operate against Windows systems in enterprise networks.

Participants will learn about the full spectrum of payload types and formats, including EXEs, DLLs, shellcode, and .NET assemblies, as well as advanced techniques for designing memory-resident payloads through process injection and memory management. The course also covers strategies for evading Endpoint Detection and Response (EDR) systems and other telemetry solutions, addressing challenges such as API hooking, AMSI bypasses, ETW evasion, and AI/ML-based classifications.

Attendees will delve into implant design with a focus on modularity, reflective loading, encryption, and communication mechanisms, including synchronous and asynchronous methods. Practical exercises explore leveraging LOLBins (living off the land binaries) and third-party binaries, such as PowerShell, JScript, MSBuild, and Python, to bypass application whitelisting and create effective initial access vectors.

The course also introduces participants to the fundamentals of packer design, including compression, encryption, environmental keying, and methods to manipulate entropy and metadata. Students will leave with a strong foundation in building payloads that are both effective and evasive, understanding how to overcome blue team defenses and operate stealthily.

Students Will Be Provided With:

  • Lifetime Access to Course Material, plus 1-month Lab Access
  • Exclusive Course Swag
  • Certificate of Completion

Minimum Course Requirements:

  • Laptop with 8GB of RAM
  • Modern Web Browser (Chrome, Firefox, etc.)

Prerequisites:

  • Basic understanding of Windows fundamentals.
  • Basic programming knowledge.
  • Willingness to learn advanced concepts in a fast-paced environment.

Target Audience:

This course is designed for beginner and intermediate-level red team operators, malware developers, and hackers looking to build a strong foundation in Windows payload development, EDR evasion techniques, and initial access tradecraft.

Rate it