
DEF CON 33 - Kill Chain Reloaded: Abuse legacy paths fr stealth persistence - A Hernando, B Martinez
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 43:05
The talk demonstrates how attackers can abuse legitimate signed but vulnerable software components to achieve stealth persistence on systems, bypassing security measures like Secure Boot 1:16. The researchers present techniques for exploiting UEFI vulnerabilities and signed drivers to maintain persistent access while evading detection.
Key Takeaways:
• Secure Boot has significant limitations as it will load vulnerable binaries even if they're compromised, especially if not properly updated in the DBX revocation list 2:16
• The researchers found vulnerable UEFI components like shield loader that allow loading unsigned EFI binaries, enabling pre-boot attacks 9:23
• They demonstrate bypassing both Secure Boot and BitLocker by exploiting a vulnerable signed UEFI application and manipulating the Windows Platform Binary Table 18:02
• Signed vulnerable drivers from major vendors can be exploited to gain kernel-level access and protect malicious processes from termination 35:24
• These techniques enable complete system compromise with stealth persistence while evading EDR solutions 41:35
The research highlights how the most effective offensive techniques don't rely on traditional malware but instead re-purpose legitimate signed components, making detection and removal significantly more challenging 42:25.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
It is my absolute pleasure to introduce these two firsttime Defcon speakers, Alejandro and Buya. Um, the title of their talk is KillChain Reloaded: Abusing Legacy Pass for stealth persistence. With that, take it away, guys. >> Thank you. [Applause] >> Hello everyone. First of all, thank you to organizer for inviting us to Defcon. It's an honor to for us to be here. Our English is not perfect, but we will try to explain everything as clear as possible. We ask for your patent and please do not be too hard with us. This is my colleague Alejandro Nando. We both work in the hacking department at a central Spain in red team and research. Uh we love breaking things and find out more abilities. Here are your social media just in case you want contact us or ask anything about this talk. I am Bora M…