Last Chance: MacBook Air, Dell XPS 13 or $600 off with SANS Online Training Ends December 7

DFIR Summit

Austin, TX | Tue, Jul 7 - Tue, Jul 14, 2015
This event is over,
but there are more training opportunities.

Preparing for PowerShellmageddon - Investigating Windows Command Line Activity

  • Chad Tilbury, Senior Instructor, SANS Institute
  • Thursday, July 9th, 7:00pm - 8:00pm

There is a reason hackers use the command line, and it isn't to impress you with their prowess. Throughout the history of Windows, the command line has left far fewer forensic artifacts than equivalent operations via the GUI. To make matters worse, the transition to Windows 7 and 8 has spread PowerShell throughout the enterprise. While it makes our lives easier as defenders, it does the same for our adversaries. Every time you marvel at the capabilities of PowerShell, you should fear how your adversaries may use that power against you.

This talk will demonstrate how incident responders are countering the command line threat with real-world examples. Learn to identify when it is in play, extract command history, and see what is new on the horizon from Microsoft to make tracking command line and PowerShell activity easier.


Bonus Sessions

The following bonus sessions are open to all paid attendees at no additional cost. There are many different types of events that fall into these categories:

  • SANS@Night: Evening presentations given after day courses have ended. This category includes Keynotes.
  • Special Events: SANS-hosted events and other non-technical recreational offerings. This category includes, but is not limited to, Receptions and Information Tables.
  • Vendor: Events hosted by external vendor exhibitors.
  • Lunch & Learn: Short presentations given during the lunch break.
Additional Sessions
Session Speaker Type
Live Broadcast Special Events
Tuesday, July 7
Session Speaker Time Type
Vendor Solutions Expo Tuesday, July 7th, 10:10am - 10:30am Vendor Event
Vendor Solutions Expo Tuesday, July 7th, 3:45pm - 4:05pm Vendor Event
DFIR Night in Austin Tuesday, July 7th, 7:00pm - 9:00pm Reception
Wednesday, July 8
Session Speaker Time Type
Vendor Solutions Expo Wednesday, July 8th, 9:45am - 10:15am Vendor Event
The Power of 3 Wednesday, July 8th, 12:00pm - 1:00pm Lunch and Learn
Vendor Solutions Expo Wednesday, July 8th, 3:00pm - 3:20pm Vendor Event
Thursday, July 9
Session Speaker Time Type
CSI and Blackhat Scorpions: From Hollywood to Keyboard Robert M. Lee, Instructor, SANS Institute Thursday, July 9th, 6:00pm - 7:00pm SANS@Night
Preparing for PowerShellmageddon - Investigating Windows Command Line Activity Chad Tilbury, Senior Instructor, SANS Institute Thursday, July 9th, 7:00pm - 8:00pm SANS@Night
Friday, July 10
Session Speaker Time Type
The Tap House Phil Hagen, Certified Instructor, SANS Institute Friday, July 10th, 6:00pm - 7:00pm SANS@Night
The Plinko Board of Modern Persistence Techniques Alissa Torres, Certified Instructor, SANS Institute Friday, July 10th, 7:00pm - 8:00pm SANS@Night