Detecting PowerShell - Empire Using the NetWitness Platform

Описание к видео Detecting PowerShell - Empire Using the NetWitness Platform

PowerShell - Empire is a post-exploitation framework used by red teams and advanced persistent threat actors for gaining and maintaining a foothold on computers and servers running Microsoft Windows Server operating systems. Empire implements the ability to run PowerShell agents without needing powershell.exe, modules ranging from keyloggers to Mimikatz, and adaptable communications to evade network detection.

This demo covers the detection of PowerShell - Empire using NetWitness Endpoint Tracking Data as well as Network/Packet Data.

Комментарии

Информация по комментариям в разработке