Overview
Syllabus
Introduction
Who am I
Audience
Agenda
What is PowerShell
Why is PowerShell important
Exploit frameworks
PowerShell is extremely flexible
PowerShell is important to miner
Querying PowerShell logs
PowerShell logs
References
Analyzing PowerShell Data
Evasion Tactics
Special Characters
Cosine Similarity
HighLevel Features
Machine Learning
Documentation
Raw Events
Transformation
Sample Event
Algorithm Evaluation
Results
Accuracy
Precision
Random Force
Lessons Learned
Overfitting
Normalized Data
Get More Data
Measure Your Performance
Code Names Stick Around
Detection Efficacy
RealTime Pipeline
Merging work
Data set
Questions
Taught by
BSidesLV