Payload Podcast 009 - Steven Flores

Payload Podcast 009 - Steven Flores

Source: YouTube · John Hammond · published Jul 16, 2026 · 1:01:47

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Steven Flores discusses the evolution of offensive engineering, focusing on payload development and WMI exploitation.

Key Takeaways:
• WMI (Windows Management Instrumentation) serves as a powerful remote execution platform, leveraging underlying technologies like DCOM and RPC 4:16.
• Modern EDRs utilize data-driven approaches and AI/ML, making evasion significantly harder than in the past 11:56.
• Effective payload development requires tailoring techniques to specific EDR behaviors, such as Elastic’s detection of unbacked memory execution 10:45.
• Offensive teams prioritize using high-reputation, signed code (like ClickOnce) to blend in and avoid close inspection 17:45.
• Flores introduces "WMI maxing," aiming to perform post-exploitation activities remotely via WMI without dropping new agents or files 26:23.
• The community needs a centralized repository for YARA rules to better understand defensive capabilities and improve offensive tradecraft 24:45.

The landscape of cybersecurity is shifting toward data-driven detection, requiring offensive engineers to be more nuanced in their approaches. Open-source collaboration remains vital for advancing both offensive and defensive capabilities.

Sources:

  • 4:16 Explanation of WMI and its underlying technologies.
  • 10:45 Elastic EDR's detection of unbacked memory execution.
  • 17:45 Using signed .NET assemblies and ClickOnce for evasion.
  • 26:23 Concept of "WMI maxing" for remote

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Yeah. It says live. >> It says live. Fingers crossed. >> Does that mean it's live? >> Usually, it takes like a couple seconds, you know, the thing's got to kick on, all the systems, all the like internet pipes and >> Dude, I'm telling you telling me in 2026 it doesn't just do it automatically for us? >> Yeah, it's AI. >> [laughter] >> AI's just talking to each other all over the place. >> It's agents that carry our packets now. >> Dude, I love that actually. I love that. >> Oh, how you been, man? Welcome to the Payload Podcast. >> Hello, hello everybody. Sorry, it's been a minute, you know, there was holidays. People were on vacation, but we are we're so back. We're back. How's the heat for you where you're at? I'm not going to I'm not going to say where you're at, John, but how's the heat…