Главная
Study mode:
on
1
Intro
2
Welcome
3
WhyMI
4
PowerShell
5
WMI Query
6
WMI Events
7
WMI Attacks
8
Providers
9
Motivation
10
Advanced forensics
11
Reverse engineering
12
Forensic parsers
13
Demo
14
WMI tool
Description:
Explore Windows Management Instrumentation (WMI) attacks, real-time defense strategies, and advanced forensic analysis techniques in this comprehensive conference talk from BSidesLV 2015. Delve into the intricacies of WMI, including PowerShell integration, WMI queries, and event handling. Examine various WMI attack vectors and understand the motivations behind their use. Learn about advanced forensic methodologies, reverse engineering techniques, and forensic parsing tools specifically designed for WMI analysis. Witness a live demonstration of WMI tools and gain practical insights into defending against and investigating WMI-based threats. This 53-minute presentation equips security professionals with essential knowledge to enhance their understanding of WMI security implications and forensic capabilities.

WhyMI So Sexy? WMI Attacks, Realtime Defense & Advanced Forensic Analysis

BSidesLV
Add to list
0:00 / 0:00