Overview
Syllabus
Introduction
How to download the talk
Whats on my website
Oregon Trail Expert
PreReq
Sunlight is the best disinfectant
The evolution of Windows malware
File list malware
Hidden PowerShell window
Manual gzip
The advantages of manual gzip
DeepBlueCLI v2 update
Perfect is the enemy of good
New features
Regex
Giant command lines
Perfect attacker fallacy
Im gonna fail
Lost in the wilderness
Peta gets smart
PowerShell
Event Log View
Wmake
PowerShell launch
Older examples
New object output mode
Metasploit
Pipe
PSExec
PSAttack
Daniel Bohannon
Dan Daniel
Multiple rounds
Alpha count
Binary encoding
Global variable
Object output
Automatic detective whitelisting
CSV deepwhitelist
Automate deepwhitelist
Is PowerShellExec evil
A revolution happening in Sims Elastic Stack
Why Python
Security Onion
How to get event logs
Python EBTX
BBBTX
Demo
Lobby Con