DEF CON 27 - Zombie Ant Farm Practical Tips for Playing Hide and Seek with Linux EDRs @HackersOnBoard
DEF CON 27 - Zombie Ant Farm Practical Tips for Playing Hide and Seek with Linux EDRs  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 3 hours ago
Talk by Dimitry Snezhkov

EDR solutions have landed in Linux. With the ever increasing footprint of Linux machines deployed in data centers, offensive operators have to answer the call.

In the first part of the talk we will share practical tips and techniques hackers can use to slide under the EDR radar, and expand post-exploitation capabilities.

We will see how approved executables could be used as decoys to execute foreign functionality. We will walk through the process of using well known capabilities of the dynamic loader. We will take lessons from user-land root-kits in evasion choices.

Part two will focus on weaponizing the capabilities. We will show how to create custom preloaders, and use mimicry to hide modular malware in memory. We will create a "Preloader-as-a-Service" capability of sorts by abstracting storage of modular malware from its executing cradles. This PaaS is free to you though!

We fully believe the ability to retool in the field matters, so we have packaged the techniques into reusable code patterns in a toolkit you will be able to use (or base your own code on) after it is released.

This talk is for hackers, offensive operators, malware analysts and system defenders. We sincerely hope defensive hackers can attend and also have fun.
DEF CON 27 - Zombie Ant Farm Practical Tips for Playing Hide and Seek with Linux EDRsDEF CON 27 - State of DNS Rebinding Attack & Prevention Techniques and the Singularity of OriginDEF CON 27 - droogie - Go NULL Yourself or How I Learned to Start Worrying While Getting FinedDEF CON 27 - XiaoHuiHui - All the 4G Modules Could Be HackedDEF CON 27 - Leon Jacobs - Meticulously Modern Mobile ManipulationsDEF CON 27 - Backdooring Hardware Devices By Injecting Malicious Payloads On MicrocontrollersDEF CON 27 - Patrick Wardle - Harnessing Weapons of Mac DestructionDEF CON 27 - How You Can Buy ATandT T-Mobile and Sprint Real-Time Location Data on the Black MarketDEF CON 27 - Pedro Cabrera Camara - SDR Against Smart TVs URL and Channel Injection AttacksBlack Hat USA 2018 - Pestilential Protocol How Unsecure HL7 Messages Threaten Patient LivesEdge Side Include Injection Abusing Caching Servers into SSRF and Transparent Session HijackingEfail Breaking S MIME and OpenPGP Email Encryption using Exfiltration Channels
HackersOnBoard |

DEF CON 27 - Zombie Ant Farm Practical Tips for Playing Hide and Seek with Linux EDRs

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER