Тёмный

Finding and Decoding Malicious Powershell Scripts - SANS DFIR Summit 2018 

SANS Digital Forensics and Incident Response
Подписаться 72 тыс.
Просмотров 37 тыс.
50% 1

Опубликовано:

 

3 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 21   
@TjSpoonManJacques
@TjSpoonManJacques 2 года назад
My personal experience with Base64 came in the form of a Rootkit - that slithered through on of those Window 10 open windows (port 445). Since Dec 2021 I have submerged in cybersecurity out of rage and unquenchable craze revenge. Even I am amazed how much I learned in 30 minutes!!! I would work with your team an entire year for FREE just to be room with super talent like this beautiful young lady! JOB WEL DONE - Much love from New Orleans
@paulosilva-dm1qb
@paulosilva-dm1qb 2 года назад
Excellent!!!!
@orca2162
@orca2162 2 года назад
Clever cookie! I was waiting to see Wonder Woman but she was probably base encoded in the invisible plane so I missed it! Are the tools limited to base 64 encoding?
@alifayyaz851
@alifayyaz851 2 года назад
Excellent
@paulosilva-dm1qb
@paulosilva-dm1qb 2 года назад
How do we add powershell log to the eventlog
@ravisuj
@ravisuj 2 года назад
the demonstration has been done on windows server 2008 r2. On windows server 2012 and above the event logs generated are readable in plain english. Also if the service doesn't starts how will it connect back to the meterpreter?
@boratsagdiyev1586
@boratsagdiyev1586 4 года назад
What to do about runtime detection. I have several backdoors wich can be scanned without going detected. As soon i execute them, i get an alert indicating a malicious file in my temp folder. ( I assume its detected from memory). Any tips to combat this?
@Blackrose-or7fy
@Blackrose-or7fy 3 года назад
Use off the land techniques
@boratsagdiyev1586
@boratsagdiyev1586 3 года назад
@@Blackrose-or7fy i prefer urban techniques
@tenzo42o
@tenzo42o 3 года назад
I just need to know, do you like python?
@peacefultube45
@peacefultube45 5 лет назад
Can we use cyberchef 🕵️
@DaNerd01
@DaNerd01 5 лет назад
Exactly, cyberchef is a great tool. Her entire presentation can be done in less than 30 seconds with a cyberchef cookbook.
@zvjer2
@zvjer2 5 лет назад
you are using windows and looking at a piece of code compressed with powershell so you go and try as hard as you can to decode it with.... python??
@ItsMeooooooo
@ItsMeooooooo 4 года назад
Whats your point?
@adekeyetemitope2301
@adekeyetemitope2301 4 года назад
@@ItsMeooooooo powershell could have just been used ... @least thats what i think hes trying to say
@amrkhled3598
@amrkhled3598 2 года назад
mistress at 2:20
@Robalo450
@Robalo450 2 года назад
Shes so hot.
@logicfirst7959
@logicfirst7959 6 лет назад
Damn, you are gonna make me hate python if you say it one more time.
@b3twiise853
@b3twiise853 4 года назад
ssssss
@simplelife5600
@simplelife5600 5 лет назад
How old is this woman??42?Doesn't look it tho.
@orca2162
@orca2162 2 года назад
17, from the superhero intro ;)
Далее
Keynote: Cobalt Strike Threat Hunting | Chad Tilbury
45:45
МАЛОЙ ГАИШНИК
00:35
Просмотров 495 тыс.
Fileless Malware Analysis & PowerShell Deobfuscation
26:42
DFIR 101: Digital Forensics Essentials | Kathryn Hedley
1:16:05
When you Accidentally Compromise every CPU on Earth
15:59
Will YouTube Ever Run Out Of Video IDs?
5:10
Просмотров 9 млн
The Art of Code - Dylan Beattie
1:00:49
Просмотров 4,7 млн
Investigating WMI Attacks
1:00:43
Просмотров 26 тыс.