SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsPowerShell is a Windows scripting language that can be leveraged to deliver enterprise-wide incident response. Although PowerShell's remoting technology offers a secure, flexible, and scalable solution, there are implications that need to be considered. This paper will address authentication, performance, and the integrity of data as it relates to incident response. A virtualized lab environment will be used to illustrate key research findings, with the ultimate goal of addressing both the appropriate and inappropriate uses of PowerShell remoting. This will enhance the security practitioner's ability to perform incident response, while understanding the most suitable use-cases for using PowerShell.