Feb. 8, 2024, 5:49 p.m. | Black Hat

Black Hat www.youtube.com

...This talk will take you on a journey on how to reverse the underlying API, understand the core components of the undocumented internals of Fibers, and then use this knowledge to create granular detection telemetry from process memory. It will conclude by demonstrating and then open-sourcing a novel tool called Weetabix that automates this whole process for the benefit of threat hunting teams or EDR developers....

By: Daniel Jary

Full Abstract and Presentation Materials: https://www.blackhat.com/us-23/briefings/schedule/#from-dead-data-to-digestion-extracting-windows-fibers-for-your-digital-forensics-diet-32832

api components data dead detection digital digital forensics forensics journey knowledge memory process reverse telemetry understand undocumented windows

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Security Officer Hospital Laguna Beach

@ Allied Universal | Laguna Beach, CA, United States

Sr. Cloud DevSecOps Engineer

@ Oracle | NOIDA, UTTAR PRADESH, India

Cloud Operations Security Engineer

@ Elekta | Crawley - Cornerstone

Cybersecurity – Senior Information System Security Manager (ISSM)

@ Boeing | USA - Seal Beach, CA

Engineering -- Tech Risk -- Security Architecture -- VP -- Dallas

@ Goldman Sachs | Dallas, Texas, United States