
Pen Testing & Adversary Emulation - Carlos Perez - PSW #789
About this episode
In this segment we welcome Carlos Perez back to the show! Carlos will discuss methods we can use to hide one systems and cover our tracks.
We'll cover how on a system (as administrator) the blue team's struggle using default logs or even on a default install of Sysmon to detect an attacker. Attackers can selectively disable modern event log providers, take action and then re-enable. We will demo this and how to best monitor for this technique.
Visit https://www.securityweekly.com/psw for all the latest episodes!
Show Notes: https://securityweekly.com/psw-789
Get every episode summarized
Each time Paul's Security Weekly (Video) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Paul's Security Weekly (Video)
The AI "Vulnpocolypse" Is Real? - PSW #922
Paul's Security Weekly (Video)
AI Makes All Bug Shallow? - PSW #921
Paul's Security Weekly (Video)
What Is A Router? (And all things AI) - PSW #920
Paul's Security Weekly (Video)
Scanning The Internet with Linux Tools - PSW #919
Paul's Security Weekly (Video)