Toilet Duck

Everything Stays Local

Document malware, and sanitising it without uploading anything.

Slides

Both present in the browser — arrow keys, space or click to advance, f for full screen. Same 36 slides, two house styles.

Present → with demonstrations 64 slides · the Accenture deck with 28 worked demonstrations interleaved — the artifacts and the disarm shown against real files rather than described Present → SOC analyst, Accenture style 31 slides · the artifacts to pivot on, why each technique evades the control you already have, and where this fits next to a sandbox you are not always allowed to use Present → project style, technical 36 slides · the five families of document-borne execution, why the usual defences fit badly, and how the sanitiser is built Present → Accenture house style the same 36 technical slides, set in Accenture’s house style

Or take the PDF: with demonstrations · SOC analyst · project style · Accenture

Paper

Read → companion paper 9 pages · the same material argued rather than asserted — the full PDF action table, where the tool deliberately disagrees with the sanitiser it was ported from, and the implementation mistakes with enough context to be useful

Tools used in the demonstrations

Linked rather than bundled. These are other people’s tools, and you want the current version from the author, not a copy frozen inside a talk.


What the talk covers

The tool

Toilet Duck Web is a single index.html. It opens from disk, has no dependencies, and makes no network requests — the files you scan never leave the machine. toiletduck.cleaning