PowerShell+ 2019 - Malicious Payloads vs Deep Visibility: A PowerShell Story by Daniel Bohannon

Channel:
Subscribers:
42,400
Published on ● Video Link: https://www.youtube.com/watch?v=OatLgndWPuA



Duration: 43:22
12 views
0


For over a decade PowerShell has empowered administrators, DevOps practitioners and automation enthusiasts to accomplish significant tasks with relative ease. However, malicious threat actors have also harnessed PowerShell’s capabilities by writing extensive offensive tools and frameworks in PowerShell.
The PowerShell team has countered these malicious trends with adding numerous defensive enhancements to PowerShell including extremely deep logging visibility (like ScriptBlock, Module and Transcription logging) as well as blocking capabilities and interfaces like the AntiMalware Scan Interface (AMSI).
This talk draws from over four years of Incident Response experience to lay out a technical buffet of in-the-wild malicious PowerShell payloads and techniques. In addition to diving deep into the mechanics of each malicious example, this presentation will highlight forensic artifacts, detection approaches and the deep visibility that the latest versions of PowerShell provides security practitioners to defend their organizations against the latest attacks that utilize PowerShell.
So if you are new to security or just want to learn about how attackers have used PowerShell in their attacks, then this talk is for you. If you want to see what obfuscated and multi-stage, evasive PowerShell-based attacks look like under the microscope of PowerShell deep inspection capabilities, this talk is for you. And if you want to see why these security advancements to PowerShell are causing many attackers to shift their tradecraft development away from PowerShell, this talk is for you.

PowerShell Summit videos are recorded on a "best effort" basis. We use a room mic to capture as much room audio as possible, with an emphasis on capturing the speaker. Our recordings are made in a way that minimizes overhead for our speakers and interruptions to our live audience. These recordings are meant to preserve the presentations' information for posterity, and are not intended to be a substitute for attending the Summit in person. These recordings are not intended as professional video training products. We hope you find these videos useful - the equipment used to record these was purchased using generous donations from members of the PowerShell community.




Other Videos By Confreaks


2022-09-12DevOpsDays Boston
2022-09-06PowerShell+ 2019 - Wardley Maps Saved The Day - How Stack Overflow Enterprise... by Chris Hunt
2022-09-06PowerShell+ 2019 - Continuously deploying SQL code using Powershell by Kirill Kravtsov
2022-09-06PowerShell+ 2019 - It’s PowerShell In the Cloud – Welcome to Azure Cloud Shell by Michael Bender
2022-09-06PowerShell+ 2019 - Demystifying Microsoft's Cloud Automation products by Jaap Brasser
2022-09-06PowerShell+ 2019 - Introduction to Serverless Functions by Kirk Munro
2022-09-06PowerShell+ 2019 - Beyond Pester 102: Acceptance testing with PowerShell by Glenn Sarti
2022-09-06PowerShell+ 2019 - Moving Up the Monitoring Stack by Steven Murawski
2022-09-06PowerShell+ 2019 - Sipping psake: Creating a Build and Release Pipeline for ... by Brandon Olin
2022-09-06PowerShell+ 2019 - Basic To Boss: Customizing Your PowerShell Prompt by Thomas Rayner
2022-09-06PowerShell+ 2019 - Malicious Payloads vs Deep Visibility: A PowerShell Story by Daniel Bohannon
2022-09-06PowerShell+ 2019 - Completely Automate Managing Windows Software...Forever by Daniel Franciscus
2022-09-06PowerShell+ 2019 - Look smarter: deliver your work in Excel by James O'Neill
2022-09-06PowerShell+ 2019 - Turn your logs into actionable data at any scale with AWS by Andrew Pearce
2022-09-06PowerShell+ 2019 - Writing Clustered Applications with Windows PowerShell and... by Tome Tanasovski
2022-09-06PowerShell+ 2019 - PSCache: simple strategies for magnificent performance by Mathias Jessen
2022-09-06PowerShell+ 2019 - "Piping" data between packaged scripts by Paul DeArment Jr
2022-09-06PowerShell+ 2019 - Jenkins - User Interface for your Powershell tasks by Kirill Kravtsov
2022-09-06PowerShell+ 2019 - Finding Performance Bottlenecks with PowerShell by Mike F. Robbins
2022-09-06PowerShell+ 2019 - F5 Declarative Configuration by James Arruda
2022-09-06PowerShell+ 2019 - Monitoring Out, Observability In by Ebru Cucen