1st 3 Windows IR Commands - BHIS Nuggets | John Strand

Поделиться
HTML-код
  • Опубликовано: 23 авг 2024
  • Join us in the Black Hills InfoSec Discord server here: / discord to keep the security conversation going!
    📄 Learn cloud security and penetration testing from John www.antisyphon...
    📄 View our Pay-What-You-Can Courseswww.antisyphon...
    📄 View the Antisyphon Course Catalog
    www.antisyphon...
    📄 View Our Live Training Course Calendarwww.antisyphon...
    John Strand's favorite 3 Windows IR (Incident Response) commands.
    Black Hills Infosec Socials
    Twitter: / bhinfosecurity
    Mastodon: infosec.exchan...
    LinkedIn: / antisyphon-training
    Discord: / discord
    Black Hills Infosec Shirts & Hoodies
    spearphish-gen...
    Black Hills Infosec Services
    Active SOC: www.blackhills...
    Penetration Testing: www.blackhills...
    Incident Response: www.blackhills...
    Backdoors & Breaches - Incident Response Card Game
    Backdoors & Breaches: www.backdoorsa...
    Play B&B Online: play.backdoors...
    Antisyphon Training
    Pay What You Can: www.antisyphon...
    Live Training: www.antisyphon...
    On Demand Training: www.antisyphon...
    Educational Infosec Content
    Black Hills Infosec Blogs: www.blackhills...
    Wild West Hackin' Fest RUclips: / wildwesthackinfest
    Active Countermeasures RUclips: / activecountermeasures
    Antisyphon Training RUclips: / antisyphontraining
    Join us at the annual information security conference in Deadwood, SD (in-person and virtually) - Wild West Hackin' Fest: wildwesthackin...

Комментарии • 11

  • @GadgetMick
    @GadgetMick Год назад +1

    Great video. I'm glad that all those hours spent looking at the output of netstat haven't been wasted 😂
    I would love a bit more of an explanation as to why you'd see those 4 DLLs in a lot of application level backdoor 😊

  • @sjporter1254
    @sjporter1254 Год назад +1

    Your impression of the RUclips troll was perfect 😂

  • @joepangit6938
    @joepangit6938 Год назад +1

    You taught us this a long time ago in a GCIH class in Vegas. It looks like a lot of the basics don't change so much. Almost every time I teach someone netstat -anob they think I'm some type of wizard :)

  • @thedevinmccarthy
    @thedevinmccarthy Год назад +3

    "hot state on state actor action" 😂

  • @phoneaccount6942
    @phoneaccount6942 Год назад

    These nuggets are gold

  • @khayla_matthews
    @khayla_matthews Год назад

    Very informative 👍🏾

  • @abefroeman100
    @abefroeman100 Год назад

    Nailed it

  • @anthonynowlan9765
    @anthonynowlan9765 Год назад

    Why is svchost a thing?

  • @baconblaster6422
    @baconblaster6422 Год назад +1

    wHaT iF tHe MaLwArE iS uSinG rAw SoCkEtZ

  • @alexmags
    @alexmags Год назад

    I like Resource Monitor GUI to see network connections and file access by processes. Perfmon.exe /res