
Workshop materials for “Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel” presented at DEF CON 34 and BSidesLV 2026. Covers malware development, EDR Architecture, EDR evasion, C2 customization, and kernel-level techniques.
Workshop materials for “Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel”, presented at DEF CON 34 and BSidesLV 2026.
This workshop explores custom malware development, EDR Architecture & Evasion, C2 customization, and kernel-level techniques using Elastic Defend as the target EDR.
Workshop materials from DEF CON 34 and BSidesLV 2026.
The materials cover topics including:
The workshop focuses on understanding how EDR detects malicious behavior and how attackers can modify their techniques to evade detection.
The Reference directory contains Markdown versions of the workshop materials. These files are provided for reference only and have not been thoroughly reviewed or updated.
During the actual workshops, we used slide-based presentation materials.
The source code used in the workshops was shared with workshop participants. I may make the source code publicly available if there is sufficient interest.
The techniques and concepts presented in these materials are intended for educational and security research purposes only.
Please do not use these techniques for malicious or unauthorized activities.
We hope these materials help you better understand EDR detection and evasion techniques and, ultimately, improve your security and build stronger defenses.