T vs T or Why my offensive punch beats your forensics stance

No ratings

Presented at t2 2017 by

Last year, right after 2016 edition of t2 infosec, a challenge was placed, and accepted. The presenter was challenged by the infamous t2 founder, Mr. Touminen, to try to defeat his memory forensic skills in an epic duel that will take place, one year later, at this t2 edition. The contenders, that once used to be friends, will have a fierce battle during the presentation in order to finally answer the question: are the presenter offensive skills better than the host forensic ones? One year of preparations, research and development will be unleashed in the arena of the mighty t2 conference, and the attendees will be the ones to decide the outcome of the match! Or to put it in a less dramatic way, in this presentation the speaker will show the results of his research in the field of memory forensics, specifically on how to *defeat* that field of incident investigation. All the previous literature about the duel is, nonetheless, true and the match will take place, followed right after the contest by a extensive technical overview of the methodology, tools, techniques and other resources developed on purpose for that challenge. The efficiency of the research will be proven during the duel but, successful or not, all of it will be explained. Although the code developed for this research will be made available to the attendees *during* the presentation, after it the attendees will have the chance to try them by themselves in a couple of environments that will be made available for them during the conference coffee breaks. What to expect from this presentation? Low level research, Vulnerabilities, Exploits, Tools, GUIs and some fun war stories with the ever present offensive approach of this speaker’s presentations. Round one. Fight! Hugo Teso works as Head of Aviation Cyber Security Services at F-Secure, he hates talking about himself in 3rd person, and he has been working on IT security for the last 17 years. Also being a commercial pilot, he soon focused his attention on aviation security. Together with the development of some open source projects, like Iaitō and Bokken, he has spent a lot of time on aviation security research and has presented some of the results in conferences like RootedCon, HITB, T2, SEC-T and CyCon but never BlackHat or Defcon... and perfectly happy with it :-)