iPad Air 2, Samsung Galaxy Tab A, or $350 Off with SANS Online Training Right Now!

Brussels 2015

Brussels, Belgium | Mon, Jan 26 - Sat, Jan 31, 2015
This event is over,
but there are more training opportunities.

What Malware? Hunting Command Line Activity

  • Chad Tilbury
  • Tuesday, January 27th, 7:00pm - 8:00pm

There is a reason hackers use the command line, and it isn't to impress you with their prowess. Throughout the history of Windows, the command line has left far fewer forensic artifacts than equivalent operations via the GUI. To make matters worse, the transition to Windows 7 and 8 has spread PowerShell throughout the enterprise. While it makes our lives easier as defenders, it does the same for our adversaries. Every time you marvel at the capabilities of PowerShell, you should fear how your adversaries may use that power against you.

We will show how incident responders are countering the command line threat via real-world examples. Learn to identify when it is in play, extract commands from memory, and see what is new on the horizon from Microsoft to make tracking command line activity easier.


Bonus Sessions

The following bonus sessions are open to all paid attendees at no additional cost. There are many different types of events that fall into these categories:

  • SANS@Night: Evening presentations given after day courses have ended. This category includes Keynotes.
  • Special Events: SANS-hosted events and other non-technical recreational offerings. This category includes, but is not limited to, Receptions and Information Tables.
Tuesday, January 27
Session Speaker Time Type
Incident Handling in the Enterprise Steve Armstrong Tuesday, January 27th, 6:00pm - 7:00pm SANS@Night
What Malware? Hunting Command Line Activity Chad Tilbury Tuesday, January 27th, 7:00pm - 8:00pm SANS@Night
Wednesday, January 28
Session Speaker Time Type
SANS Brussels Social Night Wednesday, January 28th, 6:00pm - 8:00pm Special Events
Thursday, January 29
Session Speaker Time Type
Brussels Community Night Sponsored by NVISO Erik Van Buggenhout & Arne Swinnen Thursday, January 29th, 6:00pm - 9:30pm Special Events