This practical and technical session is designed to equip IT professionals and security technicians with a free, accessible toolkit and accompanying methodology to safely identify, triage, and analyze suspected malicious PDFs. Using a real-world hypothetical scenario involving a compromised corporate account, attendees will learn how to safely dissect a PDF's anatomy and uncover hidden threats without risking organizational data privacy.
The Toolkit: Discover how to leverage free analysis tools for initial triage, mapping object logic trees, and extracting and deobfuscating embedded JavaScript payloads.
Safe Handling & OPSEC: Learn industry-standard safe-handling techniques coupled with important data-privacy strategies to avoid accidental detonation, alerting threat actors and inadvertent data leaks.
Analysis Methodologies: Explore both traditional code-to-behavior analysis workflows and unconventional "lazy-analyst" approaches to efficiently pivot from static observations to dynamic detonation.
Unmasking Anti-Analysis Tactics: Learn how malware authors hide their payloads to evade analysts.
Enterprise Mitigations: Walk away with actionable strategies to harden your infrastructure.
Target audience identified by presenter: Cybersecurity