The Best Online Cybersecurity Training in the World - SANS OnDemand


To attend this webcast, login to your SANS Account or create your Account.

Pausing the attack: deep dive on Pause-Process. A PowerShell script that allows you to pause and unpause potentially malicious attacks

  • Thursday, April 5th, 2018 at 10:30 AM EDT (14:30:00 UTC)
  • Mick Douglas
This webcast has been archived. You can view the webcast presentation and download the slides by logging into your SANS Portal Account or creating an Account. Click the Register Now button after you have logged in to view the Webcast.

You can now attend the webcast using your mobile device!


Once you find a potentially malicious executable, things become tough. Not technically... but rather politically... Are you allowed to halt it? If so, are you prepared for the political fallout if you're wrong? All too often, fear of stopping a business critical application has prevented incident response teams from taking timely actions. This has got to stop. Pause-Process allows you to pause running programs giving defenders the time they so desperately need. What's even better is that any i/o for the paused application is placed on a FIFO buffer, meaning if you resume the running application, all transactions should flow as expected! Attendees will walk away with a deep understanding of this free tool.

Speaker Bio

Mick Douglas

Even when his job title has indicated otherwise, Mick Douglas has been doing information security work for over 10 years. He received a bachelor's degree in communications from Ohio State University and holds the CISSP, GCIH, GPEN, GCUX, GWEB, and GSNA certifications. He currently works at Binary Defense Systems as the DFIR Practice Lead. He is always excited for the opportunity to share with others so they do not have to learn the hard way! By studying with Mick, security professionals of all abilities will gain useful tools and skills that should make their jobs easier. When he's not "geeking out" you'll likely find Mick indulging in one of his numerous hobbies; photography, scuba diving, or hanging around in the great outdoors.

Need Help? Visit our FAQ page or email

Not able to attend a SANS webcast? All Webcasts are archived so you may view and listen at a time convenient to your schedule. View our webcast archive and access webcast recordings/PDF slides.