Jie

Palo Alto Networks / Security Architect, Cortex Japac

Cybersecurity enthusiast, who has more than 17 years working experience on IT field and now is holding CCIE, OSCP and CEH certification. Was network engineer at NCHC and Qualcomm. Also worked for IBM on developing and testing network security product (XGS, Guardium, SysFlow and CP4S) for 7 years. Now is working for Palo Alto Networks.

SPEECH
演講議程
4/17 (四) 14:45 - 15:15 7F 701B SecOps 論壇
Hide Your Invocation of PowerShell Execution

PowerShell is a good tool to administrate your Windows machine and it's good for malicious actors as well. Malicious actors often use PowerShell to launch both local and remote payloads and usually want their code to be executed without detection and obfuscation. In this session, I will discuss how to use the invocation expression to launch the malicious payload and how to obfuscate your invocation.