Talk With an Expert

Emulating, Detecting, and Responding to LOLBAS Attacks – A SEC699 Update Preview

  • Tue, Sep 20, 2022
  • 2:00PM - 3:00PM UTC
  • English
  • Jean-François Maes
  • Technical Presentation
Webcast Hero

Join SANS Certified Instructor Jean-François Maes as he previews new material directly from the updated SANS SEC699: Purple Team Tactics - Adversary Emulation for Breach Prevention & Detection. Once attackers have gained initial access, they do not want to get caught by the suite of security tools on modern Windows systems. To stay under the radar, attackers leverage Living Off the Land Binaries and Scripts (LOLBAS). These are signed, allowed, and often built-in binaries, scripts, and libraries that have additional functionality attackers can abuse. In this webcast, Jean will introduce various LOLBAS, how to emulate them, detect, and respond to them in a true purple team fashion. As usual, expect demos and dad jokes.

Meet the speaker

Jean-François Maes
Jean-François Maes

Jean-François Maes

CEO

Jean-François is based in Portugal, where he is the CEO of Offensive Guardian, a boutique red and purple teaming shop providing freelance services to various organizations. He has worked for other noteworthy firms, including, but not limited to: Neuvik, TrustedSec, Fortra's Cobalt-Strike team, and NVISO.

Read more about Jean-François Maes