SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsAuditing with PowerShell is a major component to the future on Windows Security. As part of the Open Source Security Assessment Management System (OSSAMS) project, this paper analyzes the initial development of the PowerShell framework used to collect DACL's from AD objects. The objective for OSSAMS is normalizing data for a streamlined analysis. The data will be collected from routers, switches, firewall, security tools, directory services, and other information systems. This paper outlines the initial framework used within PowerShell to audit MS AD and other MS systems. The restrictions on the framework are the customer, or organization being assessed, would only need to create a user account for the assessor. The computer doing the assessment cannot join the domain. The paper discusses the SID, .Net Classes, and the codingprocess in-depth.