Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
dTub
Скачать

BSides DC 2016 - PowerShell Security: Defending the Enterprise from the Latest Attack Platform

Автор: BSides DC

Загружено: 2016-10-30

Просмотров: 3319

Описание:

PowerShell is a boon to administrators, providing command consistency and the ability to quickly gather system data and set configuration settings. However, what can be used to help, can also be used for less altruistic activities. Attackers have recently learned that leveraging PowerShell provides simple bypass methods for most defenses and a platform for initial compromise, recon, exploitation, privilege escalation, data exfiltration, and persistence.

With the industry shift to an "Assume Breach" mentality, it's important to understand the impact of defending against an attacker on the internal network since this is a major shift from the traditional defensive paradigm. In its default configuration, there's minimal PowerShell logging and nothing to slow an attacker's activities. Many organizations seek to block the PowerShell executable to stop attacks. However, blocking PowerShell.exe does not stop PowerShell execution and can provide a false sense of security. Simply put, don't block PowerShell, embrace it. The key is monitoring PowerShell usage to enable detection of recon and attack activity. As attack tools like PowerSploit (Invoke-Mimikatz) and the recently released PowerShell Empire become more prevalent (and more commonly used), it's more important than ever to understand the full capabilities of PowerShell as an attack platform as well as how to effectively detect and mitigate a variety of PowerShell attack methods.

The presentation walks the audience through the evolution of PowerShell as an attack platform and shows why a new approach to PowerShell attack defense is required. PowerShell recon & attack techniques are shown as well as methods of detection & mitigation. Also covered are the latest methods to bypass and subvert PowerShell security measures including PowerShell v5 logging, constrained language mode, and Windows 10's AMSI anti-malware for scanning PowerShell code in memory.The final part of the presentation explains why PowerShell version 5 should be every organization's new baseline version of PowerShell due to new and enhanced defensive capability.

This talk is recommended for anyone tasked with defending and testing the defenses for an organization as well as system administrators/engineers.

Sean Metcalf (Founder at Trimarc)
Sean Metcalf is founder and principal security consultant at Trimarc (www.TrimarcSecurity.com), an information security consulting firm focused on improving enterprise security. He is one of about 100 people in the world who holds the Microsoft Certified Master Directory Services (MCM) certification, is a Microsoft MVP, and has presented on Active Directory attack and defense at BSides, Shakacon, Black Hat, DEF CON, and DerbyCon security conferences.

Sean has provided Active Directory and security expertise to government, corporate, and educational entities since Active Directory was released. He currently provides security consulting services to customers and regularly posts interesting Active Directory security information on his blog, ADSecurity.org. Follow him on Twitter @PyroTek3.

Thanks to our video sponsors
Antietam Technologies http://antietamtechnologies.com
ClearedJobs.Net http://www.clearedjobs.net
CyberSecJobs.Com http://www.cybersecjobs.com

BSides DC 2016 - PowerShell Security: Defending the Enterprise from the Latest Attack Platform

Поделиться в:

Доступные форматы для скачивания:

Скачать видео mp4

  • Информация по загрузке:

Скачать аудио mp3

Похожие видео

BSides DC 2016 - Beyond Automated Testing

BSides DC 2016 - Beyond Automated Testing

BSides DC 2018 - Lightning fast CTF solving - Automatic Exploit Generation & Side Channel Analysis

BSides DC 2018 - Lightning fast CTF solving - Automatic Exploit Generation & Side Channel Analysis

The Detection Series: Powershell

The Detection Series: Powershell

BSides DC 2019 - Hands-on Writing Malware in Go

BSides DC 2019 - Hands-on Writing Malware in Go

Музыка для работы за компьютером | Фоновая музыка для концентрации и продуктивности

Музыка для работы за компьютером | Фоновая музыка для концентрации и продуктивности

Kubernetes — Простым Языком на Понятном Примере

Kubernetes — Простым Языком на Понятном Примере

Как устроена База Данных? Кластеры, индексы, схемы, ограничения

Как устроена База Данных? Кластеры, индексы, схемы, ограничения

BSides DC 2016 - Keynote by Marcia Hoffman

BSides DC 2016 - Keynote by Marcia Hoffman

Bitcoin: Disrupting Cross Border Payments - IMF Fintech Seminar

Bitcoin: Disrupting Cross Border Payments - IMF Fintech Seminar

Top 10 Ways to Improve Active Directory Security Quickly

Top 10 Ways to Improve Active Directory Security Quickly

4 Hours Chopin for Studying, Concentration & Relaxation

4 Hours Chopin for Studying, Concentration & Relaxation

Музыка для работы - Deep Focus Mix для программирования, кодирования

Музыка для работы - Deep Focus Mix для программирования, кодирования

BSides DC 2019 - Using JA3. Asking for a friend?

BSides DC 2019 - Using JA3. Asking for a friend?

BSides DC 2016 - Detecting Malicious websites using Machine Learning

BSides DC 2016 - Detecting Malicious websites using Machine Learning

BSides DC 2015 - Bridging the Gap: Lessons in Adversarial Tradecraft

BSides DC 2015 - Bridging the Gap: Lessons in Adversarial Tradecraft

MLA Mini - Martin Audio at InfoComm 2014

MLA Mini - Martin Audio at InfoComm 2014

BSides DC 2019 - Signing your code the easy way

BSides DC 2019 - Signing your code the easy way

4 часа Шопена для обучения, концентрации и релаксации

4 часа Шопена для обучения, концентрации и релаксации

BSides DC 2019 - Keeping CTI on Track: An Easier Way to Map to MITRE ATT&CK

BSides DC 2019 - Keeping CTI on Track: An Easier Way to Map to MITRE ATT&CK

Jazz & Soulful R&B  smooth Grooves  Relaxing instrumental Playlist /Focus/study

Jazz & Soulful R&B smooth Grooves Relaxing instrumental Playlist /Focus/study

© 2025 dtub. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]