Head of Technical Advocacy at SCYTHE | CEO CROSS-INTEL
I’ve been working as Head of Technical Advocacy at SCYTHE, CEO at CROSS-INTEL, BSides Porto Organizer, Red Team Village Director (DEF CON), Senior Advisor Raices Cyber Academy, Founder of Red Team Community (Brazil and LATAM), AWS Community Builder, Snyk Ambassador, Application Security Specialist and Hacking is NOT a crime Advocate. International Speaker at Security and New technologies events in many countries such as US (Black Hat & Defcon), Canada, France, Spain, Germany, Poland, Black Hat MEA - Middle-East - and others, I’ve served as University Professor in Master Degree in Portugal, Graduation and MBA courses at Brazilian colleges, in addition, I'm Creator and Instructor of the Course - Malware Attack Types with Kill Chain Methodology (PentestMagazine), PowerShell and Windows for Red Teamers(PentestMagazine) and Malware Analysis - Fundamentals (HackerSec).
Black Hat US 2025 - https://blackhat.com/us-25/arsenal/schedule/presenters.html#filipi-pires-46329
Black Hat US 2024 - https://blackhat.com/us-24/arsenal/schedule/presenters.html#filipi-pires-46329
Black Hat MEA 2025 - https://blackhatmea.com/speaker/filipi-pires-0
Black Hat MEA 2024 - https://blackhatmea.com/speaker/filipi-pires
DEF CON 33 / 32 - https://sessionize.com/filipi-pires/
DEF CON - Adversary Village - https://adversaryvillage.org/adversary-events/DEFCON-33/Filipi-Pires/
13:00-14:55 PDT | Saturday, Aug 8th 2026 | Adversary Village Workshop Stage, Las Vegas Convention Center Hands-on Workshop
Commodity infostealers account for a significant share of initial access in enterprise breaches. Their TTPs are documented, their tooling is public, and most detection stacks still miss them. This workshop emulates the full infostealer playbook against a live target and measures exactly where the gaps are.
Attendees execute an eight-stage adversary emulation scenario replicating documented commodity threat actor TTPs: HTA phishing delivery, in-memory C2 via Meterpreter, browser credential theft from Chrome and Edge using DPAPI and the SQLite Login Data file, in-memory keylogging via process migration to explorer.exe, UAC bypass using the fodhelper registry hijack documented across multiple threat actor profiles, and LSASS credential dumping via Kiwi/Mimikatz recovering NTLM hashes, SAM contents, and the DPAPI_SYSTEM master key. Every technique is drawn from documented threat actor behavior and mapped to MITRE ATT&CK before execution begins.
The second half of the workshop shifts to validation. Attendees enable Sysmon64 telemetry and replay the emulation, stage by stage, identifying which techniques generated detectable events and which did not. Each gap maps to a concrete control recommendation. The keylogging stage writes nothing to disk. The Meterpreter session exists only in memory. The DPAPI_SYSTEM extraction is not anomalous to most SIEMs by default. Attendees document all three as validated findings, not assumptions.
Key Takeaways
1. Adversary emulation with real TTPs produces validated detection gaps, not theoretical ones. Running the actual technique against your stack tells you whether the control works. Running it in this workshop tells you before an attacker does.
2. In-memory execution breaks file-based detection entirely. Meterpreter leaves no binary on disk. The only detection path is behavioral: process injection signals, memory scanning, or network correlation between a user-context process and an external C2 session.
3. DPAPI_SYSTEM recovery after LSASS access retroactively compromises all protected data on the machine. Most SIEMs do not alert on this extraction by default. Attendees leave with the specific Event IDs and Sysmon rule configuration that catch it.
Outline
Adversary emulation framing: commodity infostealer TTP landscape, ATT&CK coverage planning, emulation scenario overview
Stage 1 to 2: emulating HTA phishing delivery, in-memory C2 establishment, session confirmed, T1566.001, T1204.002, T1571
Stage 3: browser credential theft emulation, DPAPI architecture, Chrome and Edge Login Data extracted, T1555.003
Stage 4: keylogging emulation via process migration to explorer.exe, zero disk artifacts confirmed, T1056.001
Stage 5 to 6: privilege escalation emulation, fodhelper UAC bypass, SYSTEM access, Kiwi loaded, T1548.002
Stage 7 to 8: credential dump emulation, NTLM hashes, SAM, DPAPI_SYSTEM master key recovered, T1003.001, T1003.002
Detection validation: Sysmon64 telemetry review, gap analysis per stage, control recommendations, ATT&CK mapping finalized
Agency.
Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!