Тёмный

Revoke-Obfuscation: PowerShell Obfuscation Detection (And Evasion) Using Science 

Black Hat
Подписаться 229 тыс.
Просмотров 24 тыс.
0% 0

Опубликовано:

 

4 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 18   
@anonamous9945
@anonamous9945 6 лет назад
That is some really excellent insight into observing these activities and parsing the wheat from the chaff. Great work Gents. Even the Audio was much better this year!
@TurboWindex
@TurboWindex 3 года назад
Very good presentation, keep it up.
@Asdayasman
@Asdayasman 6 лет назад
<a href="#" class="seekto" data-time="40">0:40</a> LMAO THAT DRAMATIC PAN TO HIS BEARD
@TimLF
@TimLF 7 лет назад
Seems like AppArmor or android permissions (issues aside) are the more elegant approaches, as fun as building classifiers is... to bad that after 19 years the powershell install options are nowhere close the bounty of trusted code in apt.
@LeeHolmes
@LeeHolmes 7 лет назад
A whitelisting approach is absolutely the right way to go, and PowerShell is great at this (see watch?v=ZkJ64_tQxPU). This is for people that don't.
@broderalias
@broderalias 4 года назад
Its Elliot Anderson!
@DustinRodriguez1_0
@DustinRodriguez1_0 7 лет назад
I really don't understand why they focus on false positives so much. A false positive means a safe script was called out as potentially dangerous, so it gets reviewed. Big whoop. Their false negative rates were higher - that are actually dangerous scripts which they deemed to be safe. It only takes 1 of those and the game is over.
@LeeHolmes
@LeeHolmes 7 лет назад
False positives are deadly to anything at scale. The reality is that clean scripts outnumber obfuscated ones by many orders of magnitude. If an ops team has to look at 100 scripts per day that are false positives, they will become blind when real obfuscated stuff comes up (if they are even still looking at the reports any longer).
@aboodtube2577
@aboodtube2577 2 года назад
Moral of the story Delete powershell
@hacker-isback903
@hacker-isback903 3 года назад
im a practicing
@StephenChapman
@StephenChapman 7 лет назад
It drives me absolutely bonkers when people say ob-FEW-scate / ob-FEW-scation. Throw a define:obfuscate into Google and click the speaker icon in the result up top. And now back to the video which, sans all the ob-FEW-scates I'm sure are in store for me, I feel quite certain is going to be rather awesome. =)
@endofthelinejoel
@endofthelinejoel 7 лет назад
This presenter is NOT DIVERSE ENOUGH. Too white, too straight, too male. By comparison, I don't flinch when I get ransomware... but this level of cisgender privilege has me LITERALLY shaking. OMG, I can't even...
@codex3191
@codex3191 7 лет назад
Please tell me this is a joke.... (I know it is - nice try bud)
@p00ky76
@p00ky76 7 лет назад
Obfuscation Detected! Analysis..... High frequency of "white space encoding". Weighing script elements before Eval.......... Revoke.method............ delete.user
@YumzHD
@YumzHD 7 лет назад
And in the end its best this way, fuck those SJWs trying to ruin our field and attempting to instill affirmative action. All it'd do is cause more work and load for us as we need to pick up the extra slack, fix more mistakes, do extra training, deal with more stress - fuck that
@wtfgeis
@wtfgeis 6 лет назад
...what?
@Stopinvadingmyhardware
@Stopinvadingmyhardware 2 года назад
That’s dumb as hell.
Далее
How Many Twins Can You Spot?
00:17
Просмотров 23 млн
Ichthyology: Phishing as a Science
24:28
Просмотров 36 тыс.
Breaking the x86 Instruction Set
44:29
Просмотров 360 тыс.
Exploiting Network Printers
45:09
Просмотров 45 тыс.
Hacking Windows TrustedInstaller (GOD MODE)
31:07
Просмотров 659 тыс.