Beware of the Shadowbunny - Using virtual machines to persist and evade detections
This was also presented at BSides Singapore 2020. The slides are here and YouTube link is here.
The origins of the Shadowbunny A few years ago, around 2016, I went on a relaxing two weeklong vacation. It was great to disconnect from work. I traveled to Austria, enjoying hiking in the mountains, and exploring Vienna.
When I came back to the office, the team had placed a giant bunny teddy into my chair.