Olivier Bilodeau, <obilodeau@gosecure.net>
Our Vision
Malware Analysis with Malboxes
Code Hardening with Find Security Bugs
RDP Snooping with PyRDP
Future Work
Cybersecurity Research Director
Reverse-Engineering and Tools Enthusiast
International Speaker
DefCon, BlackHat, RSAC, DerbyCon, 44CON, etc.
Co-founder Montrehack (hands-on security workshops)
VP Training and Hacker Jeopardy at NorthSec
Easy to Use
Paid For
Supported
Proven
DIY
Free, Adaptable
You Are on Your Own
Proof of Concept
Making Malware Analysis More Accessible
Malware analysis is not accessible to newcomers
Easy to mess things up (get infected)
Building an environment with all the tools installed takes time
Team work is hard (tools don’t encourage it)
Core Principle: Infrastructure as Code
Reproducible
Throw-away
Efficient
FRONT-END BACK-END +---------------+ +---------------+ +-------------------+ | | | +---> | Autounattend.xml | | +-> | packer | +-------------------+ | | | +-+ | | +---------------+ | +--------------------+ | malboxes.py | +-> | | | | +---------------+ | PowerShell| | | | | | WinRM winrmcp | | +-> | vagrant +---> | Shell | | | | | | Chocolatey| +---------------+ +---------------+ +--------------------+ +------------------------------------------+ | | | VirtualBox / vSphere (ESXi) / KVM / AWS* | | | +------------------------------------------+ *: NEW!
Detectors built around the SpotBugs engine with a focus on security issues
Open-source
OWASP project since 2019
131 bug patterns
Works great with Java, Kotlin and JSP
SQL/HQL Injection
Command Injection
Cryptographic Weaknesses
Cross-Site Scripting
Path Traversal
Template Injection
Hard-Coded Password
Insecure Configuration
XML External Entity
Predictable Random Number Generator
SonarQube (with Sonar-FindBugs)
Jenkins (with Warnings-NG)
Gitlab
CodeDX
Remote Desktop Protocol MITM
Active Clipboard Stealer
PowerShell / cmd Injection on Login
Take Control of the Remote Session
Client-Side File Browsing
NLA Downgrade Attack
Heuristic-based Credential Harvester
Integration with Bettercap
Active File Crawler / Downloader
Honeypots
Config Rework
More Detectors
More OWASP Visibility
Support GDI+ Passthrough
Honeypots
Hugo Genesse, Gregory Leblanc, @snakems, @pix, Camille Moncelier, @xambroz, @malwarenights, Mathieu Tarral, Maxime Carbonneau, Etienne Lacroix, Emilio Gonzalez, Francis Labelle, Humoud, Ondrej Gersl, @tothi, François Labrèche, Sanket Shah
Corporate @GoSecure_Inc
Personal @obilodeau
Email: obilodeau@gosecure.net
Send me malware samples!