<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Kyle Avery: Evading Memory Scanners — Bypassing YARA and PE-sieve</title>
        <link>https://peertube.eqver.se/videos/watch/99b46866-7de9-46a0-97bd-aaeaf24ccd76</link>
        <description>A DEF CON 30 talk about techniques for evading memory analysis tools used by antivirus products and researchers to detect malware in Windows. The presentation explains how popular scanners such as PE-sieve, Moneta, MalMemDetect, Volatility malfind, and YARA rules detect indicators of compromise in memory. It demonstrates how malware implants and shellcode can be modified to evade these detection methods. The talk also introduces a new position-independent reflective DLL loader called AceLdr, designed for stealthy loading and successful evasion of memory scanners.</description>
        <lastBuildDate>Fri, 24 Jul 2026 11:29:43 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>PeerTube - https://peertube.eqver.se</generator>
        <image>
            <title>Kyle Avery: Evading Memory Scanners — Bypassing YARA and PE-sieve</title>
            <url>https://peertube.eqver.se/client/assets/images/icons/icon-512x512.png</url>
            <link>https://peertube.eqver.se/videos/watch/99b46866-7de9-46a0-97bd-aaeaf24ccd76</link>
        </image>
        <copyright>All rights reserved, unless otherwise specified in the terms specified at https://peertube.eqver.se/about and potential licenses granted by each content's rightholder.</copyright>
        <atom:link href="https://peertube.eqver.se/feeds/video-comments.xml?videoId=99b46866-7de9-46a0-97bd-aaeaf24ccd76" rel="self" type="application/rss+xml"/>
    </channel>
</rss>