BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.balccon.org//balccon2k26-2026//talk//QSSAXP
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-balccon2k26-2026-QSSAXP@cfp.balccon.org
DTSTART;TZID=CET:20260920T153000
DTEND;TZID=CET:20260920T183000
DESCRIPTION:Shellcode is often treated as a dark art: small\, opaque\, and 
 inseparable from exploit folklore. This workshop takes the opposite approa
 ch. It breaks shellcode down as a disciplined form of constrained systems 
 programming\, where every byte\, register\, calling convention\, memory re
 ference\, and control-flow decision matters.\n\nParticipants will learn ho
 w shellcode is structured\, how position-independent code works\, and why 
 common instruction patterns such as call/pop\, base-register anchoring\, s
 tack construction\, and compact control-transfer sequences appear so frequ
 ently in real-world payloads. The workshop will also cover Windows interna
 ls relevant to shellcode\, including TEB and PEB access\, API discovery\, 
 API hashing\, syscall resolution\, and indirect syscall techniques. Finall
 y\, it will explore more advanced building blocks such as tiny disassemble
 rs\, trampolines\, and API interception hooks.\n\nThe goal is not to teach
  copy-paste payload development\, but to give reverse engineers\, malware 
 analysts\, exploit developers\, and detection engineers a clear mental mod
 el for how shellcode actually works.
DTSTAMP:20260901T064414Z
LOCATION:Pupin
SUMMARY:Shellcode: Learning to Write Position Independent Code - Malware Ut
 konos
URL:https://cfp.balccon.org/balccon2k26-2026/talk/QSSAXP/
END:VEVENT
END:VCALENDAR
