Pausing the attack: deep dive on Pause-Process. A PowerShell script that allows you to pause and unpause potentially malicious attacks

  • Thursday, 05 Apr 2018 10:30AM EDT (05 Apr 2018 14:30 UTC)
  • Speaker: Mick Douglas

Once you find a potentially malicious executable, things become tough. 'Not technically... but rather politically... 'Are you allowed to halt it? 'If so, are you prepared for the political fallout if you're wrong? 'All too often, fear of stopping a business critical application has prevented incident response teams from taking timely actions.'this has got to stop. 'Pause-Process allows you to pause running programs giving defenders the time they so desperately need. 'What's even better is that any i/o for the paused application is placed on a FIFO buffer, meaning if you resume the running application, all transactions should flow as expected! 'Attendees will walk away with a deep understanding of this free tool.