Главная
Study mode:
on
1
Intro
2
Welcome
3
Introduction
4
Jorge
5
Bug bounties
6
First challenge
7
Two axes
8
Cyber defense matrix
9
Lowbass
10
Run dll32
11
Site Intro
12
Marketplace
13
Vulnerability is a feature
14
Demo
15
Building Community
16
Outro
Description:
Explore the evolution of offensive security from CVEs to TTPs in this 53-minute conference talk. Delve into the concept of "it's not a vulnerability, it's a feature" and how attackers leverage built-in functionalities for malicious purposes. Learn about the Living off the Land Binaries and Scripts (LOLBAS) project and its focus on Microsoft-signed binaries. Discover how creating, sharing, and selling TTPs can benefit the cybersecurity community when vendors don't acknowledge certain functionalities as vulnerabilities. Gain insights from industry experts Bryson and Jorge as they discuss the maturation of offensive security techniques and the potential for monetizing feature-based exploits.

It's Not a Vulnerability, It's a Feature - Exploiting Built-in Functionality

Bugcrowd
Add to list
0:00 / 0:00