Finding and Decoding Malicious Powershell Scripts - SANS DFIR Summit 2018

แชร์
ฝัง
  • เผยแพร่เมื่อ 14 ธ.ค. 2024

ความคิดเห็น • 21

  • @TjSpoonManJacques
    @TjSpoonManJacques 2 ปีที่แล้ว

    My personal experience with Base64 came in the form of a Rootkit - that slithered through on of those Window 10 open windows (port 445). Since Dec 2021 I have submerged in cybersecurity out of rage and unquenchable craze revenge. Even I am amazed how much I learned in 30 minutes!!! I would work with your team an entire year for FREE just to be room with super talent like this beautiful young lady! JOB WEL DONE - Much love from New Orleans

  • @paulosilva-dm1qb
    @paulosilva-dm1qb 2 ปีที่แล้ว +1

    How do we add powershell log to the eventlog

  • @ravisuj
    @ravisuj 2 ปีที่แล้ว

    the demonstration has been done on windows server 2008 r2. On windows server 2012 and above the event logs generated are readable in plain english. Also if the service doesn't starts how will it connect back to the meterpreter?

  • @orca2162
    @orca2162 2 ปีที่แล้ว

    Clever cookie! I was waiting to see Wonder Woman but she was probably base encoded in the invisible plane so I missed it! Are the tools limited to base 64 encoding?

  • @boratsagdiyev1586
    @boratsagdiyev1586 4 ปีที่แล้ว +1

    What to do about runtime detection. I have several backdoors wich can be scanned without going detected.
    As soon i execute them, i get an alert indicating a malicious file in my temp folder. ( I assume its detected from memory).
    Any tips to combat this?

  • @peacefultube45
    @peacefultube45 5 ปีที่แล้ว +6

    Can we use cyberchef 🕵️

    • @DaNerd01
      @DaNerd01 5 ปีที่แล้ว +4

      Exactly, cyberchef is a great tool. Her entire presentation can be done in less than 30 seconds with a cyberchef cookbook.

  • @alifayyaz851
    @alifayyaz851 2 ปีที่แล้ว

    Excellent

  • @tenzo42o
    @tenzo42o 3 ปีที่แล้ว

    I just need to know, do you like python?

  • @paulosilva-dm1qb
    @paulosilva-dm1qb 2 ปีที่แล้ว

    Excellent!!!!

  • @zvjer2
    @zvjer2 5 ปีที่แล้ว +1

    you are using windows and looking at a piece of code compressed with powershell so you go and try as hard as you can to decode it with.... python??

    • @ItsMeooooooo
      @ItsMeooooooo 4 ปีที่แล้ว

      Whats your point?

    • @adekeyetemitope2301
      @adekeyetemitope2301 4 ปีที่แล้ว

      @@ItsMeooooooo powershell could have just been used ... @least thats what i think hes trying to say

  • @amrkhled3598
    @amrkhled3598 2 ปีที่แล้ว

    mistress at 2:20

  • @logicfirst7959
    @logicfirst7959 6 ปีที่แล้ว +5

    Damn, you are gonna make me hate python if you say it one more time.

  • @Robalo450
    @Robalo450 2 ปีที่แล้ว

    Shes so hot.

  • @simplelife5600
    @simplelife5600 6 ปีที่แล้ว

    How old is this woman??42?Doesn't look it tho.

    • @orca2162
      @orca2162 2 ปีที่แล้ว

      17, from the superhero intro ;)