Visit Trellix at Black Hat at Booth 1932 to learn how to strengthen your security posture and reduce time to detect and respond to ransomware threats.
Our experts will share how you can add the missing page in your ransomware playbook with the most comprehensive, integrated, and open XDR platform and best-of-breed security controls.
Join us for an exclusive interview with John Fokker, our esteemed Head of Threat Intelligence and Principal Engineer. Gain unique insights into the current threat landscape, emerging trends, and proactive strategies to safeguard your organization against evolving cyber threats:
By Jesse Netz Field CTO, Principal Engineer
Ransomware is a race against time. The median dwell time between the first evidence of malicious activity and the deployment of ransomware is nine days. Reducing mean time to detect (MTTD), respond (MTTR), and investigate (MTTI) can mean the difference between preventing ransomware extortion and suffering significant reputational and business loss.
Discover the power of SHAREM, an advanced Windows shellcode analysis framework integrated with the Ghidra plugin. Our experts will showcase how this tool enhances your ability to analyze and combat sophisticated Windows-based attacks.
Trellix, Information Security Specialist
Co-Presenter
Co-Presenter
In this session, we delve into the world of information stealers, examining their methods, motivations, and the impact of their activities on victims. We explore the Genesis market takedown as a case study, shedding light on the inner workings of a major underground cybercrime marketplace that facilitated the sale of stolen credentials.
By the end of this session, participants will gain a comprehensive understanding of information stealers, the Genesis market takedown, and practical steps to enhance their organization's defenses against these sophisticated attack vectors.
DotNet based malware originally started out as a novelty, but has shown it is here to stay. With DotNet malware being used by APT actors and script kiddies, and anything in-between, it is safe to say that one will encounter it sooner rather than later. This four-hour workshop primarily focuses on the analyst mindset and fundamental knowledge, including topics such as loaders, unpacking, obfuscation, DotNet internals, and (un)managed hooks.
Shellcode is omnipresent, seen or unseen. Yet tooling to analyze shellcode is lacking. We present the cutting-edge SHAREM framework to analyze enigmatic shellcode.
SHAREM can emulate shellcode, identifying 20,000 WinAPI functions and 99% of Windows syscalls. In some shellcode, some APIs may never be reached, due to the wrong environment, but SHAREM has a new solution: Complete code coverage preserves the CPU register context and memory at each change in control flow. Once the shellcode ends, it restarts, restoring memory and context, ensuring all functionality is reached and identifying all APIs.
Trellix, Malware Analyst
Assistant Professor at University of Alabama in Huntsville
Cybersecurity Engineer
Our current administration lists "Defend Critical Infrastructure" as the DEF CON Forums item in the 2023 National Cybersecurity Strategy. At the intersection of governmental and corporate concerns is data center security, a trend that is bound to continue as more and more operations move to the cloud. This talk details our findings in the domain of power management, the first category in a broader effort to investigate the security of critical data center components.
Trellix, Sr. Security Researcher
Trellix, Security Researcher
DotNet based malware originally started out as a novelty, but has shown it is here to stay. With DotNet malware being used by APT actors and script kiddies, and anything in-between, it is safe to say that one will encounter it sooner rather than later. This four-hour workshop primarily focuses on the analyst mindset and fundamental knowledge, including topics such as loaders, unpacking, obfuscation, DotNet internals, and (un)managed hooks.
Shellcode is omnipresent, seen or unseen. Yet tooling to analyze shellcode is lacking. We present the cutting-edge SHAREM framework to analyze enigmatic shellcode.
SHAREM can emulate shellcode, identifying 20,000 WinAPI functions and 99% of Windows syscalls. In some shellcode, some APIs may never be reached, due to the wrong environment, but SHAREM has a new solution: Complete code coverage preserves the CPU register context and memory at each change in control flow. Once the shellcode ends, it restarts, restoring memory and context, ensuring all functionality is reached and identifying all APIs.
Trellix, Malware Analyst
Assistant Professor at University of Alabama in Huntsville
Cybersecurity Engineer
Our current administration lists "Defend Critical Infrastructure" as the DEF CON Forums item in the 2023 National Cybersecurity Strategy. At the intersection of governmental and corporate concerns is data center security, a trend that is bound to continue as more and more operations move to the cloud. This talk details our findings in the domain of power management, the first category in a broader effort to investigate the security of critical data center components.
Trellix, Sr. Security Researcher
Trellix, Security Researcher
| Demo Stations | Abstract |
|---|---|
| Trellix Endpoint Security | Keeps organizations safer and more resilient with comprehensive visibility, and control to secure endpoints before, during, and after attacks.
|
| Trellix XDR | Quickly reveal the alerts and threats that matter, cross correlate across vectors and easily determine the critical steps to stop the attack.
|
| Trellix Data Security | Discovers, classifies, and protects data at rest, in use, and in motion across the organization while also providing context to Trellix XDR, to help SOC analysts quickly identify high-priority threats to the organization.
|
| Trellix Collaboration Security | As organizations strive to innovate and grow, they create highly complex interconnected networks of external partners, suppliers, vendors, contractors, and customers introducing a largely unprotected attack vector. Trellix Collaboration Security ensures people can work together securely across the extended enterprise emerging threats.
|
August 23, 2023 |
AMER - 10am PT / 1pm ET | Register Now
August 24, 2023 |
EMEA - 9am BST / 10am CEST | Register Now
August 24, 2023 |
APAC - 12pm SGT / 2pm AEST | Register Now
Be concise and specific:
Wrong: I want to learn how to migrate to Trellix Endpoint Security
Right: Trellix Endpoint Security migration
Use quotation marks to find a specific phrase:
“migrate to Trellix Endpoint Security”
Use sets of quotation marks to search for multiple queries:
“endpoint security” “Windows”
Punctuation and special characters are ignored:
Avoid these characters: `, ~, :, @, #, $, %, ^, &, =, +, <, >, (, )
The search engine is not case sensitive:
Endpoint security, endpoint security, and ENDPOINT SECURITY will all yield the same results.