BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//talks.toorcon.net//toorcamp-2020-2019//talk//PX3N3H
BEGIN:VTIMEZONE
TZID:PST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T100000Z
TZNAME:PST
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:PST
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T110000Z
TZNAME:PDT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:PDT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-toorcamp-2020-2019-PX3N3H@talks.toorcon.net
DTSTART;TZID=PST:20220714T140000
DTEND;TZID=PST:20220714T145000
DESCRIPTION:Program instrumentation and tracing is a key component of any o
 ffensive persistence framework or defensive endpoint detection and respons
 e (EDR) technology. This talk will focus on the latest tracing infrastruct
 ure known as Extended Berkeley Packet Filters (eBPF) which is currently su
 pported on Linux and is coming to Windows as well. eBPF is complex with se
 veral front end languages and backend hooking engines. This talk will expl
 ain how eBPF works\, what it takes to write eBPF based hooks\, and demonst
 rate two simple tools for verfiying or infecting ELF binaries on the fly.
DTSTAMP:20260819T200541Z
LOCATION:Prime Dome
SUMMARY:Extra Better Program Finagling (eBPF) for Attack and Defense - Rich
 ard Johnson
URL:https://talks.toorcon.net/toorcamp-2020-2019/talk/PX3N3H/
END:VEVENT
END:VCALENDAR
