Welcome to the VB2021 conference!

Workshop: Analysing Android malware

Led by Vitor Ventura (Cisco Talos); hosted by Cisco Talos
In brief:
This workshop - hosted by Cisco Talos - is designed to provide the participants with different approaches to malware analysis, so that they can perform their own analysis without the use of automated tools.
Duration: approx. 3 hours.
When:
Thursday 7 Oct 17:30 UTC
How to join:
This workshop is now over.
Android malware has become prevalent across the landscape. In this workshop Vitor Ventura will provide hands-on reverse engineering techniques for Android malware

This workshop is designed to provide the participants with different approaches to malware analysis, so that they can perform their own analysis without the use of automated tools. When everything else fails, we need to know what's under the hood.

On the analysis side the workshop covers:

  • Basic Android topics

  • Triage and feature identification

  • Malware unpacking

  • Emulation and root check bypass

  • String deobfuscation


During the workshop attendees will work with Gustuff, DoNot, Loda4Android and other malware. By the end, attendees should be able to apply the same techniques, or adapted versions of them, to new malware samples and even to different approaches
Vitor Ventura
Cisco Talos

Vitor Ventura is a Cisco Talos security researcher. As a researcher, he has investigated and published various articles on emerging threats. Most days Vitor hunts for threats, investigating them, reversing code, but also looking for the geopolitical and/or economic context. Vitor has spoken at conferences such as NorthSec, Recon Brussels, DEFCON Crypto Village and BSides Lisbon among others. Previously, he was IBM X-Force IRIS European manager and did penetration testing at IBM X-Force Red. Vitor holds multiple security-related certifications including GREM (GIAC Reverse Engineer Malware) and CISM (Certified Information Security Manager).

Workshop: IoT hacking 101

Led by Zoltán Balázs (CUJO AI); hosted by IoT Village
In brief:
Interested in the world of IoT security and enjoy challenges? Join this workshop by IoT Village during VB2021 to receive a quick and fun introduction to techniques used in IoT security analysis.

Duration: Work at your own pace, or join Zoltán for the instructor-led version (approx. 1 hour)
When:
Labs are open Thursday 7 & Friday 8 Oct, between 16:00-20:30 UTC. The instructor-led workshop will start on Thursday 7 Oct at 18:55 UTC.
How to join:
This workshop is now over.
IoT Village's IoT hacking lab is series of fun, interactive lab exercises to introduce you to IoT security, from router firmware analysis to finding hidden backdoors or exploits in IoT devices. These self-paced labs are provided by IoT Village during the live hours of conference. If you want more interactivity and maybe a few hints for the bonus challenges of the lab, join the instructor-led workshop from Zoltán Balázs of CUJO AI who will live stream a lab walkthrough and answer your questions on the labs or IoT security in general.

Duration: Work at your own pace, or join Zoltán for the instructor-led version (approx. 1 hour) at 18:55 UTC on Thursday 7 October.
IoT Village

IoT Village advocates for advancing security in the Internet of Things (IoT) industry through bringing researchers and industry together. IoT Village hosts talks by expert security researchers, interactive hacking labs, live bug hunting in the latest IoT tech, and competitive IoT hacking contests. Over the years IoT Village has served as a platform to showcase and uncover hundreds of new vulnerabilities, giving attendees the opportunity to learn about the most innovative techniques to both hack and secure IoT. IoT Village is organized by security consulting and research firm, Independent Security Evaluators (ISE), and the non-profit organization, Village Idiot Labs (VIL)

Zoltán Balázs
CUJO AI

Zoltán is Head of Vulnerability Research Lab at CUJO AI, a company focusing on smart home security. Before joining CUJO AI he worked as CTO for an AV testing company, as an IT security expert in the financial industry for five years, and as a senior IT security consultant at one of the Big Four companies for two years. His primary areas of expertise are penetration testing, malware analysis, computer forensics and security monitoring. He released the Zombie Browser Tool that has POC malicious browser extensions for Firefox, Chrome and Safari. He is also the developer of the Hardware Firewall Bypass Kernel Driver (HWFWBypass), the Encrypted Browser Exploit Delivery tool (#IRONSQUIRREL) and the Sandbox tester tool to test malware analysis sandboxes. He found and disclosed a vulnerability in IP cameras, and this vulnerability was exploited by the Persirai botnet, running on ˜600 000 cameras. He has been invited to give presentations at information security conferences worldwide including DEF CON, SyScan360, SAS2018, Virusbulletin, Disobey, Deepsec, Hacker Halted USA, Botconf, AusCERT, Nullcon, Hackcon, Shakacon, OHM, Nopcon, Hacktivity, and Ethical Hacking.

Workshop: Modern threat hunting

Led by Vicente Diaz (VirusTotal); hosted by VirusTotal
In brief:
This workshop - hosted by VirusTotal - will take participants through the process of threat hunting and showcase how to leverage new techniques available for analysts to step our research up to the next level.
Duration: 45 minutes.
When:
Thursday 7 Oct 17:00 UTC
How to join:
This workshop is now over.
Threat Hunting is one of the most popular techniques used by security analysts for all kinds of investigations. It is both science and, to some degree, inspiration. However, in recent years the security industry has developed new tools and techniques that can dramatically improve the effectiveness and efficiency of our threat hunting. In particular, similarity and automatic Yara generation are key when dealing with large amounts of data.

Join this workshop with VirusTotal to go through the process of threat hunting and explore new techniques available for analysts to step-up to the next level.

Vicente Diaz
VirusTotal

Vicente holds a degree in computer science and an M.Sc. in artificial intelligence. He was e-Crime Manager at S21sec for five years and Deputy Director for EU in Kaspersky's Global Research and Analysis team for almost 10 years, where he was co-creator and responsible for the APT Intelligence Reporting service. Since joining VirusTotal, Vicente helps businesses to get more from their threat intelligence, which without context is just noise.