Talk With an Expert

Emulating, Detecting, and Responding to LOLBAS Attacks – A SEC699 Update Preview

  • Tue, Sep 20, 2022
  • 2:00PM - 3:00PM UTC
  • English
  • Jean-François Maes
  • Technical Presentation
Webcast Hero

Join SANS Certified Instructor Jean-François Maes as he previews new material directly from the updated SANS SEC699: Purple Team Tactics - Adversary Emulation for Breach Prevention & Detection. Once attackers have gained initial access, they do not want to get caught by the suite of security tools on modern Windows systems. To stay under the radar, attackers leverage Living Off the Land Binaries and Scripts (LOLBAS). These are signed, allowed, and often built-in binaries, scripts, and libraries that have additional functionality attackers can abuse. In this webcast, Jean will introduce various LOLBAS, how to emulate them, detect, and respond to them in a true purple team fashion. As usual, expect demos and dad jokes.

Meet the speaker

Jean-François Maes
Jean-François Maes

Jean-François Maes

Director of Offensive Security

European director of advanced assessment at Neuvik, specializing in penetration testing, red teaming, and adversary emulation. Passionate open-source contributor with extensive experience in offensive security technologies.

Read more about Jean-François Maes