Vaccination - An Anti-Honeypot Approach

No ratings

Presented at hackfest 2017 by

Malware often searches for specific artifacts as part of its “anti-­VManalysissandboxdebugging” evasion mechanisms, we will abuse its cleverness against it. The “anti-­honeypot” approach is a method to repel (instead of luring) attackers, implemented by creating and modifying those artifacts on the potential victim’s machine. Once the created artifacts are found by the malware – it will terminate. The session will include motivations for attackers to use evasion techniques, some in-­the-­wild examples and effective countermeasures against it.