Главная
Study mode:
on
1
Introduction
2
What is this about
3
Why should you be here
4
This is a new technique
5
Not a perfect replacement
6
Current state of the art VBA macros
7
Whats another diagnostic tool
8
PowerShell 20 in RM
9
Microsoft Code Signing
10
PowerShell
11
Windows Diagnostics
12
Output
13
TerraDoe
14
Disable TerraDoe
15
Whats next
16
References
17
Thank you
Description:
Learn to leverage Windows diagnostics for detecting system compromises in this 35-minute conference talk from Derbycon 2015. Explore a novel technique that complements existing methods like VBA macros. Discover the potential of PowerShell 2.0 in RMM and Microsoft Code Signing. Gain insights into Windows Diagnostics output and the TerraDoe tool. Understand how to disable TerraDoe and explore future developments in this field. Acquire valuable references for further study on system compromise detection techniques.

Using Windows Diagnostics for System Compromise

Add to list