nullcon 2017 - Invoke Obfuscation: Powershell Obfuscation Techniques n How To Try To Detect Them
About this talk
This talk explores advanced techniques for obfuscating PowerShell command line arguments to evade detection by application whitelisting and antivirus technologies. The speaker, Daniel Bohannon, reveals twelve unique methods that have been observed in the wild, along with three new layers of obfuscation that can be implemented independently or in combination. Each layer manipulates PowerShell and .NET cmdlets, applies string manipulation, and utilizes command input parameters to conceal command line arguments from powershell.exe. The session highlights the limitations of traditional detection methods and demonstrates the use of Invoke-Obfuscation, an open-source tool designed to apply these obfuscation techniques effectively. Daniel Bohannon, an experienced Incident Response Consultant at Mandiant, brings a wealth of knowledge in PowerShell-based attack research and detection techniques.
More from this event
See all 33 talks →
nullcon Goa 2017 - Antivirus Evasion Reconstructed Veil 3 0 by Chris Truncer
59:38
nullcon Goa 2017 - Barbarians At The Gateway by Dave Lewis
42:56
nullcon Goa 2017 - Drone Hijacking And Other IoT Hacking With GNU Radio And SDR by Arthur Garipov
46:02
nullcon Goa 2017 - Nearly Generic Fuzzing Of XML Based Formats by Nicholas Gregoire
46:04