How To Bypass AM-PPL & Disable EDRs - A Red Teamer's Story-Stephen Kho & Juan Sacco | Nullcon Berlin
About this talk
This talk introduces the Antimalware Protected Process Light (AM-PPL) technology implemented in Windows 8.1, which aims to ensure that only trusted services and processes are loaded by the operating system. The speakers explore the effectiveness of AM-PPL and investigate potential abuse scenarios that may allow bypassing antivirus and endpoint detection and response (EDR) products. Stephen, the Red Team lead at Avast, and Juan Sacco, co-team lead, leverage their extensive backgrounds in security and exploitation to share insights and findings from their research on this critical security technology.
More from this event
See all 19 talks →
Keynote | High-assurance Code Reviews: How Consulting Works When The Risks Are High by Dan Guido
49:15
Night Track | GNU Anastasis: Privacy-Preserving Key Backup And Recovery by Christian Grothoff
28:47
Fuzzware: Automating & Scaling Fuzzing For Firmware by Tobias Scharnowski & Marius Muench | Nullcon
39:10
CXO Panel | Digital Identity In The Age Of Fintech | Nullcon Berlin 2022
56:07