Overview
Explore rapid incident response techniques using PowerShell in this 51-minute conference talk from Derbycon 7. Dive into the NotPetia attack as a case study, and learn essential PowerShell concepts for effective incident handling. Discover preparation strategies, identification methods, and containment procedures. Examine tools like WillBam and Sideswipe, and understand the role of vendors in the response process. Gain insights into quick fixes and practical approaches for managing cybersecurity incidents efficiently.
Syllabus
Introduction
The NotPetia attack
What is PowerShell
Preparation Identification Containment
WillBam
Identification
Sideswipe
Vendors
Suspect
Getting to Work
Fast Fix
Wrap Up