Главная
Study mode:
on
1
Intro
2
Motivations for "Living off the Land"
3
Case for PS Remoting (WinRM)
4
PowerShell Remoting
5
WMI-based Data Collection
6
CimSweep - Introduction
7
Intrusion Detection
8
WMI Event Basics - Events
9
WMI Query Language via PowerShell
10
Uproot - Introduction
11
ETW Introduction
12
ETW Terminology
13
Common ETW Usage
14
ETW for Incident Response
15
ETW Capture Scenario
16
Investigation
17
PowerForensics - Introduction
18
Taking Ideas from the Bad Guys
19
Device Guard - Introduction
20
Device Guard vs. AppLocker
21
Device Guard Monitoring
22
Device Guard Bypass Strategies
23
Device Guard Bypass Mitigations
Description:
Explore a comprehensive conference talk on minimalist Windows defense strategies and "Living off the Land" techniques. Delve into PowerShell Remoting, WMI-based data collection, and intrusion detection using WMI events. Learn about ETW (Event Tracing for Windows) for incident response, and discover PowerForensics for digital investigations. Examine Device Guard, comparing it to AppLocker, and understand potential bypass strategies and mitigations. Gain insights from both defensive and offensive perspectives to enhance your Windows security knowledge.

Living Off the Land 2 - A Minimalist's Guide to Windows Defense

Add to list
0:00 / 0:00