Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore a 39-minute conference talk from the 44CON Information Security Conference that delves into the use of PowerShell for digital forensics and incident response. Learn how the PowerForensics project provides an all-in-one toolset for attack response and investigation, leveraging PowerShell's access to the Windows API and .NET framework. Discover how this forensically sound "live" investigation platform eliminates the need for hard drive imaging, enabling rapid response to network intrusions. Gain insights into the project's background, capabilities, and its potential to facilitate investigations of advanced actors at scale. Witness a complex demonstration showcasing how PowerForensics can assist blue teams in investigating real-world attacks, proving that PowerShell is no longer exclusive to red team operations.