Living Off the Land 2 - A Minimalist's Guide to Windows Defense

Living Off the Land 2 - A Minimalist's Guide to Windows Defense

via YouTube Direct link

Intro

1 of 23

1 of 23

Intro

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

Living Off the Land 2 - A Minimalist's Guide to Windows Defense

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Intro
  2. 2 Motivations for "Living off the Land"
  3. 3 Case for PS Remoting (WinRM)
  4. 4 PowerShell Remoting
  5. 5 WMI-based Data Collection
  6. 6 CimSweep - Introduction
  7. 7 Intrusion Detection
  8. 8 WMI Event Basics - Events
  9. 9 WMI Query Language via PowerShell
  10. 10 Uproot - Introduction
  11. 11 ETW Introduction
  12. 12 ETW Terminology
  13. 13 Common ETW Usage
  14. 14 ETW for Incident Response
  15. 15 ETW Capture Scenario
  16. 16 Investigation
  17. 17 PowerForensics - Introduction
  18. 18 Taking Ideas from the Bad Guys
  19. 19 Device Guard - Introduction
  20. 20 Device Guard vs. AppLocker
  21. 21 Device Guard Monitoring
  22. 22 Device Guard Bypass Strategies
  23. 23 Device Guard Bypass Mitigations

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.