Conference Video – Invoke-Obfuscation: PowerShell obFUsk8tion

Power Shell has increasingly become the de facto standard for penetration testers and hackers alike. It enables attackers to “live off the land” by using a Microsoft-signed binary that can execute remote code entirely in memory while bypassing both A/V and application whitelisting solutions. Today’s detection techniques monitor for certain strings in powershell.exe’s command-line arguments. Read More …

Conference Video – Dirty Red Team tricks

Let’s time travel to 2003 with today’s tools and own everything. This talk takes you inside the red teams at the North East and Mid Atlantic Collegiate Cyber Defense competition events. Raphael Mudge, the developer of the Armitage Metasploit GUI, will guide you on this journey. You will learn how to automate Metasploit, nmap, and Read More …

Cleaning a Backyard Chicken Coop

It really doesn’t take much to clean a small coop like this when you want to keep a small number of backyard chickens.  You have to pay attention to a few specific things, but other than that it only takes an hour or so, once a month to keep things clean, and the smell away.

Conference Video – Offensive Countermeasures: Still trying to bring sexy back

Why is it that the Hackers and Penetration Testers get to have all of the “sexy” fun? In this presentation we will cover some cool tricks to confuse, block or mislead attackers. Penetration testers may be angered during this presentation as we will describe how to make their lives difficult. The term “hacking back” will Read More …

Conference Video – Fantastic OSINT and where to find it

Open-Source security intelligence is bountiful if you know where to look. The goal of my talk is show you where to find this data, how to utilize it, and how the data you find can be enriched through free and/or commercial tools.

Conference Video – OSINT: Oh the places you’ll go

Justin Brown (Spridel) Open Source Intelligence (OSINT) is what many of us do on a daily basis. We may not acknowledge it. We perform research, digital foot printing, competitive intelligence, and reconnaissance, just to name a few. Come find some additional resources for your efforts, listen to what should be collected, how to perform collection, Read More …