Главная
Study mode:
on
1
Intro
2
Demo
3
Process Thread
4
PowerShell Commands
5
Capturing Script Blocks
6
Domain Lookup
7
Child Processes
8
File IO
9
Thread Tracking
Description:
Explore advanced techniques for detecting and tracing adversarial activities using Event Tracing for Windows (ETW) in this informative conference talk from Derbycon 7. Delve into practical demonstrations covering process and thread monitoring, PowerShell command tracking, script block capturing, domain lookup analysis, child process detection, file I/O monitoring, and thread tracking. Gain valuable insights into enhancing your cybersecurity defenses and improving your ability to identify and respond to potential threats in Windows environments.

Tracing Adversaries - Detecting Attacks with ETW

Add to list
0:00 / 0:00