Invoke Obfuscation - PowerShell Obfuscation Techniques and How To Try To Detect Them
Offered By: nullcon via YouTube
Course Description
Overview
Explore advanced PowerShell obfuscation techniques and detection methods in this 55-minute conference talk from nullcon 2017. Delve into a dozen never-before-seen obfuscation methods used by sophisticated attackers to evade detection by antivirus and application whitelisting technologies. Learn about three new layers of obfuscation that can be applied to PowerShell commands and scripts, including direct manipulation of cmdlets and functions, string manipulation, and content execution techniques. Discover how these methods can be stacked to create highly evasive payloads. Gain insights into the challenges of detecting obfuscated commands and the importance of PowerShell event logging. Witness a demonstration of Invoke-Obfuscation, an open-source tool for applying these techniques. Presented by Daniel Bohannon, an Incident Response Consultant at MANDIANT with expertise in PowerShell-based attack research and detection techniques.
Syllabus
nullcon 2017 - Invoke Obfuscation: Powershell Obfuscation Techniques n How To Try To Detect Them
Taught by
nullcon
Related Courses
Computer SecurityStanford University via Coursera Cryptography II
Stanford University via Coursera Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera Building an Information Risk Management Toolkit
University of Washington via Coursera Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network