Revoke-Obfuscation - PowerShell Obfuscation Detection and Evasion Using Science
Offered By: Black Hat via YouTube
Course Description
Overview
Syllabus
Introduction
Remote Download Cradle
Get Command
More Options
Alias
Invoke Expression
Fun Fact
Invoke Expressions
Invoke Command
Invoke Script
Convert Expression to Script Block
InvokeCradleCrafter
Just Breathe
Reverse
InvokeOffEustachian
CradleCrate
Muto Gucci
Whitespace tab encoding
Im starting to feel guilty
The big thing to realize
Look at this
Character Frequency
Cosine Similarity
Character Similarity
Underhanded PowerShell Contest
Building a PowerShell Corpus
Lee is so polite
GitHub
Thank You
Remove Games at PS1
Stop Online Piracy Act
More Data
How Many Scripts
Similarity Metrics
Precision and Recall
Powershell
AST Explorer
AST Type
Linear Regression
Logistic Regression
Gradient Descent
Results
Deep Analysis
Fun Facts
Script Block Logging
Upgrade to PowerShell 5
Enable Script Block Logging
Whitelisting
References
Questions
Taught by
Black Hat
Related Courses
Computer SecurityStanford University via Coursera Cryptography II
Stanford University via Coursera Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera Building an Information Risk Management Toolkit
University of Washington via Coursera Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network