Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

My Adversary Emulation Goes to the Moon… Until False Flag

Recon Conference via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Learn to replicate advanced threat actor obfuscation techniques through a detailed conference talk examining the re-implementation of APT41's Scatterbrain obfuscator. Explore the challenges of creating accurate adversary emulation tools that mirror both the functionality and sophisticated evasion methods of real-world malware. Discover how instruction dispatchers disrupt control flow analysis and understand import protection mechanisms that utilize Linear Congruential Generator (LCG)-based encryption. Examine the validation process used to test custom implementations against existing deobfuscation tools, including Mandiant's specialized toolset for the original Scatterbrain malware. Analyze how subtle modifications to obfuscation techniques can effectively bypass established heuristics while maintaining structural similarity to the original threat, demonstrating the ongoing cat-and-mouse game between malware authors and security researchers. Gain insights into the practical aspects of developing custom implants for red team exercises and security assessments that accurately represent advanced persistent threat capabilities.

Syllabus

Recon 2025 - My Adversary Emulation Goes to the Moon… Until False Flag

Taught by

Recon Conference

Reviews

Start your review of My Adversary Emulation Goes to the Moon… Until False Flag

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.