SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) cover image

ISC StormCast for Thursday, October 20th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

00:00

How to Detect an Undetectable PowerShell Command Control Channel

Safe breach published blog post with details regarding what they call an undetectable PowerShell a backdoor. The payload itself is encrypted uses as for its encryption the keys should be retrievable from the packet data if I saw this correctly one thing that sort of helped them actually figure out how many people were infected by this was that the victim ID that you're being assigned appears to be sequential.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app